Author Topic: Anythicago & Bestdriver  (Read 1832 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Anythicago & Bestdriver
« on: June 22, 2015, 05:28:04 AM »
Hello, new to the forums. I did all the diagnostics and attached them below. Someone please help me remove this malware from my system. Thank you.

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #1 on: June 22, 2015, 06:03:46 AM »
Hello


Always have one (and no more than one!) AntiVirus program! In this case having more of them will not provide you with better protection - instead they may cause slowness, lock-ups and even mark another ones as harmful, leading to leave your system unstable and even damaged. Please choose only one from the listed below to stay with and uninstall the others:
  • Ad-Aware Antivirus

Uninstallation procedure:
  • Press the + R on your keyboard at the same time. Type appwiz.cpl and click OK.
  • Search for each uninstalled entry, right-click it and select Uninstall.
This should be done until any other steps will be taken.





Scan with ZOEK

Please download ZOEK by Smeenk and save it to your desktop (preferred version is the *.exe one)
Temporary disable your AntiVirus and AntiSpyware protection - instructions here.

  • Right-click on icon and select Run as Administrator to start the tool.
  • Wait patiently until the main console will appear, it may take a minute or two.
  • In the main box please paste in the following script:
Code: [Select]
createsrpoint;
autoclean;
emptyalltemp;
bitsadmin /reset /allusers;b
ipconfig /flushdns;b
  • Make sure that Scan All Users option is checked.
  • Push Run Script and wait patiently. The scan may take a couple of minutes.
  • When the scan completes, a zoek-results logfile should open in notepad.
  • If a reboot is needed, it will be opened after it. You may also find it at your main drive (usually C:\ drive)

Post its content into your next reply.
« Last Edit: June 22, 2015, 06:13:01 AM by argus »

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #2 on: June 22, 2015, 07:47:21 AM »
Ok, These are my results.

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #3 on: June 22, 2015, 11:07:40 AM »

Fix with Farbar Recovery Scan Tool

This fix was created for this user for use on that particular machine.
Running it on another one may cause damage and render the system unstable.
Download attached fixlist.txt file and save it to the Desktop:

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.
Please attach it to your reply.

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #4 on: June 22, 2015, 04:21:16 PM »
Ok these are my results. When I rebooted my PC I did not receive the notification from Avast that the malware was blocked. So perhaps my system has been purged?
« Last Edit: June 22, 2015, 04:22:58 PM by David668 »

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #5 on: June 22, 2015, 04:51:00 PM »

Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.
  • Right-click on icon and select Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Make sure that Addition option is checked.
  • Press Scan button and wait.
  • The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.
Please include their content into your next reply.

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #6 on: June 23, 2015, 04:46:44 AM »
My results.

REDACTED

  • Guest
Re: Anythicago & Bestdriver
« Reply #7 on: June 25, 2015, 08:54:54 AM »
How is the situation now?