to the Virus/Trojan/Spyware/Malware Removal forum
I am thcbytes
and I am here to help you!
I ask that you refrain from running tools other than those I suggest to you while I am cleaning up your computer
. The reason for this is so I know what is going on with the machine at any time. Some programs can interfere with others and hamper the recovery process.Please perform all steps in the order received and do not proceed if you need clarification.
Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems please stop and tell me about it. When your computer is clean I will alert you of such. I will also provide you with detailed suggestions for prevention.
In the upper right hand corner of the topic you will see a button called Options
. If you click on this in the drop-down menu you can choose Track this topic
. By doing this and then choosing Immediate E-Mail notification
and then clicking on Proceed
you will be advised when we respond to your topic and facilitate the cleaning of your machine.
After 5 days if your topic is not
replied I we assume it has been abandoned and I will close it.I would also like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please be courteous and appreciative for the assistance provided!
Again I would like to remind you to make no
further changes to your computer unless I direct you to do so. Your computer fix will be based on the current
condition of your computer! Any changes might delay my ability to help you.
Now reboot into Safe Mode
- This can be done tapping the F8 key as soon as you start your computer.
- You will be brought to a menu where you can choose to boot into safe mode.
- Make sure you choose the option with networking support.
- Please see here for additional details.
==========Download and Run ComboFix (by sUBs)
You must rename it
before saving it.
Please download ComboFix
from one of these locations:Link 1Link 2
to your Desktop <-- Important!!!
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
- Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Please refer to this link for instructions.
- Double click on thcbytes.exe & follow the prompts.
- As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
- Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. Please include the C:\ComboFix.txt
in your next replyA word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine by running ComboFix on your own.
This tool is not a toy and not for everyday use.
ComboFix SHOULD NOT be used unless requested by a forum helper
==========With your next post please provide: