My wife has a Windows 8.1 Dell laptop running Avast Free AntiVirus 2015 which is up to date, and she just started getting something called an “afirst” or “afirst.exe” type virus. Any tips on the EASIEST way to get rid of this virus and to also completely BLOCK this type of virus from coming back?
Lets have a look see
Please download Farbar Recovery Scan Tool and save it to your Desktop.
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
[*]Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
[*]Select additions at the bottom
[*]Press Scan button.
https://dl.dropboxusercontent.com/u/73555776/frst.JPG
[*]It will produce a log called FRST.txt in the same directory the tool is run from.
[*]Please attach both logs generated.
Thanks. I have ran the Farbar Recovery Tools Scan and am attaching the 2 Log files in this reply as you requested. I look forward to your response.
I can see a little adware but that is all, is Avast alerting ?
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: 2015-07-30 12:29 - 2015-07-30 13:29 - 00000000 ____D C:\ProgramData\Browser 2015-07-30 05:04 - 2015-07-30 05:04 - 00000000 ____D C:\Program Files (x86)\Exploremedia 2015-07-30 05:00 - 2015-07-30 09:32 - 00000112 _____ C:\ProgramData\Y11yUB.dat 2015-07-30 04:55 - 2015-07-30 04:55 - 00000000 ____D C:\Program Files (x86)\predm 2015-07-30 04:36 - 2015-07-30 13:30 - 00000000 ____D C:\Program Files\015 2015-07-30 04:36 - 2015-07-30 05:01 - 00000008 _____ C:\END 2015-07-30 04:36 - 2015-07-30 04:50 - 00000000 ____D C:\Program Files\13 2015-07-30 05:00 - 2015-07-30 09:32 - 0000112 _____ () C:\ProgramData\Y11yUB.dat RemoveProxy: EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.