Hi 20Chuck02,
This fix shall contain two steps. First we will tell FRST to target malware and then we will preform additional cleaning using ComboFix. At the end we're running re-scan.
--- --- ---
FRST's FixList--- ---
1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating systemStart
C:\Windows\SysWOW64\AI_RecycleBin
C:\Program Files (x86)\Common Files\Spigot
C:\Program Files\Updater By SweetPacks
C:\Users\Chuck\AppData\Local\Temp\10d2ca4a-28d7-4d81-8c1e-dc42bb6c83fc\CliSecureRT64.dll
HKLM-x32\...\Run: [SearchSettings] - "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
FF HKLM\...\Firefox\Extensions: [{C4CFC0DE-134F-4466-B2A2-FF7C59A8BFAD}] - C:\Program Files\Updater By SweetPacks\Firefox
End
2. Save notepad as
fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.3. Run
FRST/FRST64 and press the
Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.The tool will make a log on the Desktop (
Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.--- --- ---
ComboFix--- ---
1. Please download
ComboFix by
sUBs from here and save it to your
Desktop.
If you are unsure how ComboFix works please read this guide carefully.
Note: ComboFix must be downloaded to your Desktop.--------------------------------------------------------------------
2. Temporarily disable your
AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
If you are unsure how to do this please read this or this Instruction.Instructions how to disable avast:- Right click on the avast! system tray icon (
) in the lower right corner of the screen and scroll up to avast! shield controls;
- In the menu that appears, choose Disable Permanently. When you are prompted to turn off security, click Yes.
Note: Do not forget to turn back on this option after the cleaning by choosing avast! shield controls > Enable all shield options.--------------------------------------------------------------------
3. Run
ComboFix. Click on
I Agree!- ComboFix will display DISCLAIMER of warranty on software.
By clicking I Agree ComboFix shall continue.
- ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.
-If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
- ComboFix will scan your computer in stages, total of 50 stages.
Do not mouse-click around while ComboFix is running.
Note:If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.
--------------------------------------------------------------------
4. When the tool is finished, it will produce a log report for you. (typical location: C:\
ComboFix.txt )
Attach log reports ( ComboFix.txt) back to topic.
ComboFix shall also create addition log. Please attach it to your reply.
C:\Qoobox\
ComboFix-quarantined-files.txt--- --- --- --- --- --- --- --- --- ---
Re-check . .--- ---
Re-run FRST64 . .
- Double-click to run it.
-
- Under Optional Scan ensure "Addition.txt" are ticked.
- Press Scan button.
- It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
- The tool shall create another log (Addition.txt). Please attach it to your reply as well.
Once again we shall use FRST for additional checks. Re-run
FRST/FRST64 by double-clicking:
- Type CliSecureRT64.dll;rsa64.dll into the Search: field in FRST then click the Search File(s) button.
- FRST will search your computer for files and when finished it will produce a log Search.txt in the same directory the tool is run.
- Please attach it to your reply.