Hi, HilltownJohn. Welcome to LandzDown Forum.
We will do our best to assist you. However, in order to do so, please follow all instructions provided in the sequence given. Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use. This may cause conflicts with the tools being used in the cleanup process.
If you have questions regarding any of the instructions or problems running any tools, please let us know.
For the purposes of cleanup, yes, please use your administrator login. In the event you are unable to download any of the needed files please transfer them from a known clean computer (your wife's laptop).
1) Please download the following two files (RKill link repeated in case you did not keep a copy). In the event you are blocked by the malware from downloading, it will be necessary to go to an uninfected computer and then transfer the files to the infected computer via CD/DVD, external drive, or USB flash drive.FixNCR.regBleeping Computer Downloads: RKill
2) Insert the removable device into the infected computer and open the folder the drive letter associated with it. Double-click the FixNCR.reg file to fix the Registry on your infected computer.
3) Copy the downloaded RKill file to the desktop of the infected computer.
- Double-click rkill to run.
- A command window will open then disappear upon completion, this is normal.
- Please leave rkill on the Desktop until otherwise advised.
- Do NOT restart your computer after running rkill as the malware program(s) will start again.
If you you receive security warnings about rkill, please ignore and allow the download to continue.
4) Since you already downloaded MBAM, please proceed as follows:
** Note **
- Launch Malwarebytes' Anti-Malware then click the Update tab and "Check for Updates
- Once the update has been installed and the program has loaded, select Quick scan
- When the scan is complete, click OK, then Show Results to view the results.
- Be sure that everything is checked, EXCEPT items in System Restore as shown in this sample:
- Click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See the Note below)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Please post contents of that file in your next reply.
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK
to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
In addition to the MBAM log, please return to the "Log Posting Instructions
" topic and provide the requested logs from that topic, noting that it may take more than one reply.