Author Topic: What to do with the afirst.exe Virus  (Read 1703 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
What to do with the afirst.exe Virus
« on: July 30, 2015, 02:49:36 PM »
My wife has a Windows 8.1 Dell laptop running Avast Free AntiVirus 2015 which is up to date, and she just started getting something called an "afirst" or "afirst.exe" type virus.  Any tips on the EASIEST way to get rid of this virus and to also completely BLOCK this type of virus from coming back?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: What to do with the afirst.exe Virus
« Reply #1 on: July 30, 2015, 04:10:04 PM »
Lets have a look see

Please download Farbar Recovery Scan Tool and save it to your Desktop.
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Select  additions at the bottom
  • Press Scan button.

  • It will produce a log called FRST.txt in the same directory the tool is run from. 
  • Please attach both logs generated.

REDACTED

  • Guest
Re: What to do with the afirst.exe Virus
« Reply #2 on: August 03, 2015, 06:53:05 AM »
Thanks.  I have ran the Farbar Recovery Tools Scan and am attaching the 2 Log files in this reply as you requested.  I look forward to your response.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: What to do with the afirst.exe Virus
« Reply #3 on: August 03, 2015, 03:45:53 PM »
I can see a little adware but that is all, is Avast alerting ?

 

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
2015-07-30 12:29 - 2015-07-30 13:29 - 00000000 ____D C:\ProgramData\Browser
2015-07-30 05:04 - 2015-07-30 05:04 - 00000000 ____D C:\Program Files (x86)\Exploremedia
2015-07-30 05:00 - 2015-07-30 09:32 - 00000112 _____ C:\ProgramData\Y11yUB.dat
2015-07-30 04:55 - 2015-07-30 04:55 - 00000000 ____D C:\Program Files (x86)\predm
2015-07-30 04:36 - 2015-07-30 13:30 - 00000000 ____D C:\Program Files\015
2015-07-30 04:36 - 2015-07-30 05:01 - 00000008 _____ C:\END
2015-07-30 04:36 - 2015-07-30 04:50 - 00000000 ____D C:\Program Files\13
2015-07-30 05:00 - 2015-07-30 09:32 - 0000112 _____ () C:\ProgramData\Y11yUB.dat
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.