Avast WEBforum

Other => Viruses and worms => Topic started by: REDACTED on July 30, 2015, 02:49:36 PM

Title: What to do with the afirst.exe Virus
Post by: REDACTED on July 30, 2015, 02:49:36 PM
My wife has a Windows 8.1 Dell laptop running Avast Free AntiVirus 2015 which is up to date, and she just started getting something called an "afirst" or "afirst.exe" type virus.  Any tips on the EASIEST way to get rid of this virus and to also completely BLOCK this type of virus from coming back?
Title: Re: What to do with the afirst.exe Virus
Post by: essexboy on July 30, 2015, 04:10:04 PM
Lets have a look see

Please download Farbar Recovery Scan Tool (http://www.geekstogo.com/forum/files/file/435-frst-farbars-recovery-scan-tool/) and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
Title: Re: What to do with the afirst.exe Virus
Post by: REDACTED on August 03, 2015, 06:53:05 AM
Thanks.  I have ran the Farbar Recovery Tools Scan and am attaching the 2 Log files in this reply as you requested.  I look forward to your response.
Title: Re: What to do with the afirst.exe Virus
Post by: essexboy on August 03, 2015, 03:45:53 PM
I can see a little adware but that is all, is Avast alerting ?

 

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
2015-07-30 12:29 - 2015-07-30 13:29 - 00000000 ____D C:\ProgramData\Browser
2015-07-30 05:04 - 2015-07-30 05:04 - 00000000 ____D C:\Program Files (x86)\Exploremedia
2015-07-30 05:00 - 2015-07-30 09:32 - 00000112 _____ C:\ProgramData\Y11yUB.dat
2015-07-30 04:55 - 2015-07-30 04:55 - 00000000 ____D C:\Program Files (x86)\predm
2015-07-30 04:36 - 2015-07-30 13:30 - 00000000 ____D C:\Program Files\015
2015-07-30 04:36 - 2015-07-30 05:01 - 00000008 _____ C:\END
2015-07-30 04:36 - 2015-07-30 04:50 - 00000000 ____D C:\Program Files\13
2015-07-30 05:00 - 2015-07-30 09:32 - 0000112 _____ () C:\ProgramData\Y11yUB.dat
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe
(https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG)
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner (http://www.bleepingcomputer.com/download/adwcleaner/) by Xplode onto your desktop.