t.j. 0 Posted May 30, 2014 Report Share Posted May 30, 2014 Emsisoft Emergency Kit log (C:\EEK\Run\Reports\) FRST.txt Addition.txt Emsisoft Emergency Kit - Version 4.0 Last update: 5/29/2014 8:55:08 PM User account: THAYJOHNSON\thay Scan settings: Scan type: Smart Scan Objects: Rootkits, Memory, Traces, C:\WINDOWS\, C:\Program Files\, C:\Program Files (x86)\ Detect PUPs: On Scan archives: Off ADS Scan: On File extension filter: Off Advanced caching: On Direct disk access: Off Scan start: 5/29/2014 8:56:59 PM C:\WINDOWS\System32\Drivers\lsnfd.sys detected: Adware.AdPage.A (B) Scanned 224468 Found 1 Scan end: 5/29/2014 9:55:36 PM Scan time: 0:58:37 Link to post Share on other sites
stapp 152 Posted May 30, 2014 Report Share Posted May 30, 2014 Before our experts can help, you need to follow this below and ATTACH the requested logs. http://support.emsisoft.com/forum-6/announcement-2-start-here-if-you-dont-we-are-just-going-to-send-you-back-to-this-thread/ Link to post Share on other sites
t.j. 0 Posted May 31, 2014 Author Report Share Posted May 31, 2014 (edited) <<< INLINE LOG REMOVED >> Edited May 31, 2014 by Kevin Zoll Link to post Share on other sites
Kevin Zoll 309 Posted May 31, 2014 Report Share Posted May 31, 2014 All logs are to be attached. Do not copy & paste logs to your threads, unless you are specifically asked to do so. There are 3 logs that are needed. Link to post Share on other sites
t.j. 0 Posted June 3, 2014 Author Report Share Posted June 3, 2014 I dont get three logs. Dont know what i am doing wrong. Link to post Share on other sites
t.j. 0 Posted June 3, 2014 Author Report Share Posted June 3, 2014 finally,.......here they are Link to post Share on other sites
Kevin Zoll 309 Posted June 3, 2014 Report Share Posted June 3, 2014 You attached 2 copies of the Addition.txt from FRST, I need the FRST.txt log file. Download AdwCleaner and save it on your desktop. Close all open programs and Internet browsers (you may want to print our or write down these instructions first). Double click on adwcleaner.exe to run the tool. Click on the Scan button. After the scan has finished, click on the Clean button. Confirm each time with OK. You will be prompted to restart your computer. A text file will open in Notepad after the restart (this is the log of what was removed), which you can save on your desktop. Attach that log file to your reply by clicking the More Reply Options button to the lower-right of where you type in your reply. If you lose that log file for any reason, you can find it at C:\AdwCleaner on your computer. Download Junkware Removal Tool and save it on your desktop.Shut down your anti-virus, anti-spyware, and firewall software now to avoid potential conflicts. Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click it and select Run as administrator. The tool will open and start scanning your system. Please be patient as this can take a while to complete depending on your system's specifications. On completion, a log is saved to your desktop and will automatically open. Attach the JRT log file to a reply by clicking the More Reply Options button to the lower-right of where you type in your reply. Link to post Share on other sites
t.j. 0 Posted June 4, 2014 Author Report Share Posted June 4, 2014 think this is the missing one Link to post Share on other sites
t.j. 0 Posted June 4, 2014 Author Report Share Posted June 4, 2014 here they are. I have no idea what these mean. Link to post Share on other sites
Kevin Zoll 309 Posted June 4, 2014 Report Share Posted June 4, 2014 Copy the below code to Notepad; Save As fixlist.txt to your Desktop. HKLM-x32\...\Run: [] => [X] HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKLM\...\Policies\Explorer: [NoFolderOptions] 0 Startup: C:\Users\thay\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (No File) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION 2014-05-29 12:52 - 2014-05-29 12:53 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 C:\Users\thay\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpurvakh.dll C:\Users\thay\AppData\Local\Temp\NSISUtils.dll C:\WINDOWS\System32\Drivers\lsnfd.sys Task: {52648100-CCEB-4219-9D44-E15941336B7C} - System32\Tasks\UpdaterEX => C:\Users\thay\AppData\Roaming\UpdaterEX\UpdateProc\UpdateTask.exe [2013-04-12] () <==== ATTENTION Task: {B3F9C2F1-D691-407A-BB6F-E06A4CBC993E} - System32\Tasks\LaunchApp => C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\UpdaterEX.job => C:\Users\thay\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE <==== ATTENTION AlternateDataStreams: C:\ProgramData\Temp:5C321E34Close Notepad.NOTE: It's important that both files, FRST64 and fixlist.txt are in the same location or the fix will not work. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system Run FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool complete its run after restart. The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply. Note: If the tool warns you about an outdated version please download and run the updated version. Link to post Share on other sites
t.j. 0 Posted June 5, 2014 Author Report Share Posted June 5, 2014 Fixlog.txt Link to post Share on other sites
Kevin Zoll 309 Posted June 6, 2014 Report Share Posted June 6, 2014 Let's take a fresh look. Run fresh scans with Emsisfot Emergency Kit (EEK) and FRST, attach the new EEK and FRST scan log to your reply. Link to post Share on other sites
t.j. 0 Posted June 6, 2014 Author Report Share Posted June 6, 2014 here they are Link to post Share on other sites
Kevin Zoll 309 Posted June 7, 2014 Report Share Posted June 7, 2014 Your logs look fine. How are things running? Link to post Share on other sites
Kevin Zoll 309 Posted June 11, 2014 Report Share Posted June 11, 2014 Thread Closed Reason: Lack of Response PM either ShadowPuterDude, Elise, or GT500 to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread. Link to post Share on other sites
Recommended Posts