Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

gameharbor.org Virus Help Please


  • This topic is locked This topic is locked
6 replies to this topic

#1 aaronator

aaronator

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:55 AM

Posted 17 September 2014 - 04:40 AM

Hello. I'm here for the same reason as everyone else. Downloaded Sims 4 and got this annoying startup adware junk. I deeply regret my decisions and now request help from you talented people. I have scanned and have included the files in this topic. Hopefully I can get some help with this rather annoying problem. Thank you.

Attached Files



BC AdBot (Login to Remove)

 


#2 aaronator

aaronator
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:55 AM

Posted 18 September 2014 - 03:23 AM

Why Nobody is anwsering this im helpless. Can anybody Help me to solve this problem Please ?



#3 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:55 PM

Posted 21 September 2014 - 03:10 AM

Hello and welcome to BleepingComputer   :)

 

Step 1

frst.pngfrstfix.png

Press thew7.png + R on your keyboard at the same time. Type notepad and click OK.

  • Copy the entire content of the codebox below and paste into the notepad document:
    start
    HKU\S-1-5-21-3918077518-3712141223-318403584-1002\...\Run: [CMD] => cmd.exe /c start http://extendedunlimited.org && exit
    SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    cmd: dir C:\WINDOWS\0028CB34D5D3460FB308A39A095A5E01.TMP
    Task: {D8EF1221-A115-4209-B700-0DB9BCA612BA} - System32\Tasks\UpdaterEX => C:\Users\000\AppData\Roaming\UPDATE~1\UPDATE~1\UPDATE~1.EXE
    emptytemp:
    end
  • Click FileSave As and type fixlist.txt as the File Name.

Both files, FRST and fixlist.txt have to be in the same location or the fix will not work!

  • Right-click on FRST.gif icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
    (XP users click run after receipt of Windows Security Warning - Open File).
  • Press the Fix button just once and wait.
  • If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
  • When finished FRST will generate a log on the Desktop, called Fixlog.txt.

Please post it to your reply.



#4 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:55 PM

Posted 23 September 2014 - 07:23 PM

Hi,

 

Please respond within 72 hours or this thread will be closed due to lack of activity. 9.23.2014 -- 7:23PM



#5 aaronator

aaronator
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:07:55 AM

Posted 24 September 2014 - 10:32 AM

oh sorry. I have bin very busy and i fixed it already with the help of another on this forum. bUT tHANK yOU ! :!



#6 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:55 PM

Posted 24 September 2014 - 03:56 PM

Np. Glad to hear you got it resolved. Be safe.



#7 thisisu

thisisu

  • Malware Response Team
  • 2,525 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:11:55 PM

Posted 24 September 2014 - 03:57 PM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users