This thread's last reply is from January 18, 2015, 1:32 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Hi,
These are the copy and pasted results, it still can't find the log though.
C:\Users\C850-13D\AppData\Local\Temp\NODBB5B.tmp Win32/Adware.ObronaAds.B application
C:\Users\C850-13D\Downloads\ccsetup404.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application
C:\Users\C850-13D\Downloads\FreeSoundRecorder.exe Win32/OpenCandy potentially unsafe application
C:\Users\C850-13D\Downloads\stsetup.exe a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application
Hi,
We need to run another fix.
Once done please give me another update on how your computer is running.
If you're not having any problems i can give you final instructions.
Hi,
Computer is running well, no sign of ads or dubious links.
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 17-01-2015 01
Ran by [redacted] at 2015-01-17 22:40:04 Run:2
Running from C:\Users\[redacted]\Desktop
[redacted]
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
C:\Users\C850-13D\AppData\Local\Temp\NODBB5B.tmp
C:\Users\C850-13D\Downloads\ccsetup404.exe
C:\Users\C850-13D\Downloads\FreeSoundRecorder.exe
C:\Users\C850-13D\Downloads\stsetup.exe
EmptyTemp:
CMD: ipconfig /flushdns
*****************
C:\Users\C850-13D\AppData\Local\Temp\NODBB5B.tmp => Moved successfully.
C:\Users\C850-13D\Downloads\ccsetup404.exe => Moved successfully.
C:\Users\C850-13D\Downloads\FreeSoundRecorder.exe => Moved successfully.
C:\Users\C850-13D\Downloads\stsetup.exe => Moved successfully.
========= ipconfig /flushdns =========
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
========= End of CMD: =========
EmptyTemp: => Removed 31.3 MB temporary data.
The system needed a reboot.
==== End of Fixlog 22:40:22 ====
Hi,
Computer is running well, no sign of ads or dubious links.
Your latest logs appear to be clean so you should be good to go.
Lets tidy up and remove the tools we used to clean your computer.
Please download
delfix and save it to your
desktop.
- Right-click on delfix.exe and select " Run as administrator " to run it.
- Check the following boxes then click on Run.
- Activate UAC
- Remove disinfection tools
- Create registry backup
- Purge system restore
- Reset system settings
- All tools we used to clean your computer should be gone now.
- You can now delete any tools/logs we used if they remain on your computer.
Protection Programs
Don't forget to
re-enable any protection programs we disabled during your fix.
We removed outdated versions of
Adobe Reader and
Java, if you use them you can reinstall the latest versions.
Java SE Runtime Environment (JRE).
Please download from
HERE
- Find Java SE 8u25.
- Click the Download JRE button to the right.
- Choose the correct Platform and Multi-language. Next, check the box that says I agree to the Java SE Runtime Environment 6 License Agreement.
- Click the Continue button.
- Click on the filename under Windows Offline Installation and save it to your desktop.
- Close all active windows.
- Install the program.
Next.
Update Adobe Reader
- You should Download and Install the newest version of Adobe Reader for reading pdf files.
- Older versions may have vulnerabilities that malware can use to infect your system.
- Go Here to download and install Adobe Reader X (11.0.09).
- Note: Uncheck install McAfee Security Scan Plus
Please read the article below which will give you a few suggestions for how to minimise your chances of getting another infection.
I would be grateful if you could reply to this post so that I know you have read it and, if you've no other questions, the thread can be closed.
Safe surfing!
Hi Cypher,
Have removed all dowloads and fix logs and have re-installed Adobe reader and Java, everything is running smoothly.
Thankyou so much for your time and expertise.
Knoxy
Hi,
"Knoxy" wrote:Thankyou so much for your time and expertise.
You're most welcome, glad we could help
Good luck and stay safe.