Pondus
September 12, 2017, 11:44am
21
I've sent a private/personal message to [b]Pondus[/b] and Sass Drake. But i cant still find it in profile > show posts. Its about the files and how it may affect me if I post it here.
I have not recived any PM from you?
Anyway Sass Drake is the one that analyze logs, not me
You can not see sendt PMs unless you check the box “Save a copy in my outbox”
You will then find them at My Messages > Messages > Sendt Items
system
September 12, 2017, 1:39pm
22
Did you received my message drake? I have already sent you the fixlog.
For now let’s do this:
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
Zip: H:\Drive.bat;H:\Battlefield.lnk;H:\Grand Theft Auto.lnk;H:\Movies.lnk;H:\Saints Row.lnk
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
Zip file will appear on your Desktop. Pleaseuplaod it on , for example, Google Drive, Onedrive, Dropbox, etc an d post link to it.
system
September 13, 2017, 3:47am
24
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
H:\Drive.bat
H:\Battlefield.lnk
H:\Grand Theft Auto.lnk
H:\Movies.lnk
H:\Saints Row.lnk
cmd: attrib -H -S "H:\Drive"
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
Please report if folders turn to shortcuts back.
system
September 13, 2017, 8:05am
26
The files on H is okay now i guess? but it is still on partition I and E. Anyway thanks. ;D
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
cmd: dir /S E:
cmd: dir /S I:
H:\Drive\461
E:\Drive\461
I:\Drive\461
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
system
September 15, 2017, 6:35am
28
File is too large? So am I just gonna copy it here or what?
Uplaod it it to OneDrive.
Open Notepad (click Start button → type notepad.exe → press Enter )
Copy text from code block below and paste it into Notepad
E:\drive.bat
I:\Drive.bat
I:\Games, installers, etc.lnk
I:\Movies.lnk
I:\Other Files.lnk
Go to File → Save As
Make sure that UTF-8 is selected as Encoding (left side of Save button)
Save it as fixlist.txt on Desktop
Open again FRST and click on button Fix
Wait until FRST finishes
fixlog.txt should be genereted and opened. Attach it your post and wait further instructions.
system
September 16, 2017, 5:05am
31
Woah. I try to run the FRST and it updates (like everyday) now my laptop can’t run it. Windows 10 pro x64
Did Windows Update worked last day/night?
Try with downloaded fresh copy.
https://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/
Now you should be able to restore original folder structure on your drives. Please tell if malware on drives reappears.
system
September 18, 2017, 10:57am
35
The malware has been removed now i think. Thanks for the help! Have a great day.
• The following will implement some post-cleanup procedures:
=> Please download DelFix by Xplode to your Desktop.]
Run the tool and check the following boxes below;
[i]
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Remove disinfection tools
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Create registry backup
http://www.mcshield.net/personal/magna86/Images/checkmark.png
Purge System Restore [/i]
Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:[b]DelFix.txt[/b])
The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.