Hello! I’ve been to this site once before and It really helped me out a lot, so I thought I would come here after trying to help fix my brothers pc.
He’s been having some problems for the last couple of months and he’s ran a couple of programs to try and figure out what the problem is; Such as malwarebytes and avast. But every time he thought he had it fixed, it would come back even worse. After looking over his pc, I’ve noticed that he has a lot of useless and unknown programs starting up and running at all times.
I’ve tried to turn them off and remove them, but it didn’t do any good. When he starts up his pc, it takes about 10-15 minutes before it’s finally finished booting up. Also, when you open up firefox, the pc shuts off. I’ve noticed that the pc is running very hot and if you try to do anything else other then turn it on, the temperature spikes and it shuts down.
Any help would be greatly appreciated! I will answer any question you might have to the best of my knowledge. Again, thank you for any and all help.
[]Shut down your protection software now to avoid potential conflicts.
[]Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select “Run as Administrator”.
[]The tool will open and start scanning your system.
[]Please be patient as this can take a while to complete depending on your system’s specifications.
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[]Post the contents of JRT.txt into your next message.
----- next -----
Please download ComboFixfrom here and save it to your Desktop. If you are unsure how ComboFix works please read this guide carefully. note: ComboFix must be downloaded to your Desktop.
Temporarily disable your AntiVirus program. If you are unsure how to do this please read this or this Instruction.
Instructions how to disable avast:
[*]Right-click on the avast! icon in the lower right corner of the screen and choose Open Avast! User Interface.
[*]In the window that opens on the top right corner, click Settings.
[*]In a new window that opens, choose the option Troubleshooting, Uncheck Enable avast! self-defense, and click OK.
[*]=> Again, right-click on the avast! icon in the lower right corner of the screen and select avast! shield controls .
[*]In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn on this option after the cleaning.
Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.
If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix’s window while it is running.
If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart computer once more.
When the tool is finished, it will produce a log report for you. (typical location: C:[b]ComboFix.txt[/b] )
Attach log reports ( ComboFix.txt) back to topic.
Running - more than one - antivirus program is not recommended because:
[*]They can conflict with each other.
[*]Report the other antivirus software as malicious.
[*]Antivirus programs use an enormous amount of computer’s resources… actively scanning your computer.
[*]Can cause your computer to become unstable…run slowly and even, in rare cases, BSOD crash…etc
I strongly suggest you uninstall one of them. Which one, is your decision.
Close all browser windows and refering to the picture above.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
OK, So I believe I removed the virus programs. I went ahead and removed both Norton and avg just to be sure. I was having a little bit of trouble trying to remove Norton, so that’s why i also removed avg.
I believe this is the log you are requesting and i hope it will help.
Close all browser windows and refering to the picture above.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.
[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
Open notepad and copy/paste the text present inside the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Save notepad as fixlist.txt NOTE. It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
[color=#008000]Note: If the tool warned you about the outdated version please download and run the updated version.
Ok, I feel Silly for asking this, but when you say they need to be in the same location, you just mean in the same folder right? Or do i have to drag the fixlist to the program like the combo fix?
I ran it when the fixlist was in the same folder and it said that there was no fixlist. I went to try again, but the frst program was gone, so i got it again and this time it did run. Only thing, the fixlist text document is now missing.
Feel free to download fresh FRST.exe to you Desktop and create new FixList.txt with above script. Just run FRST and hit Fix button.
FRST will search FixList.txt only at the location from where it was started.
Open notepad and copy/paste the text present inside the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Save notepad as fixlist.txt NOTE. It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.
----- next -----
Re-check:
Re-run FRST and attach here fresh created FRST.txt logreport.
Ok, I believe I have both of the files you requested. I ran it with the fix log and then i did a scan, because it wouldn’t let me run fix, with out a fixlist. So I assumed re-running it meant to scan it.
...and then i did a scan, because it wouldn't let me run fix, with out a fixlist. So I assumed re-running it meant to scan it.
That's right, you've done it right.
We shall re-run FRST with fresh FRST Script. Close Chrome browser and run FRST again via FixList.txt.
1. Open notepad and copy/paste the text present inside the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
2. Save notepad as fixlist.txt to your Desktop. NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply. Note: If the tool warned you about the outdated version please download and run the updated version.
ok, here is the new fixlog. Thank you for all of your help. The pc is ruining so much better now and isn’t shutting down every time i open up a program.
Now click on “Run” button. Wait for the programme completes his work.
All the tools we used should be gone.
Tool will create and open an log report (DelFix.txt) Note: The report will also be stored on C:\DelFix.txt
I don’t need DelFix log report.
------------------------------------------------
I recommended to use MCShield if you will.
You may download MCShield from one of the following links:
It will prevent infection by computer via USB flash drive, mobile phone or any other memory card.
And not only will prevent infection, but it will immediately clean flash drive, memory card or external HDD.