Step 1: HijackThis Fix.
Locate the HijackThis file from within the Autologger Folder.
Close all other open programs prior to running this tool!!
Right Click Run as Administrator.
Click Scan.
Then checkmark the items listed below.
O3 - Toolbar: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - (no file)
O4 - MSConfig\startupreg: [AvgUi] "C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe" /lps=fmw (2017/02/02)
O4 - HKU\S-1-5-20\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
O4 - HKU\S-1-5-19\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\Sidebar.exe /autoRun
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file)
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - (no file)
O22 - ScheduledTask: (Ready) Microsoft Compatibility Appraiser - \Microsoft\Windows\Application Experience - C:\Windows\system32\CompatTelRunner.exe
O22 - ScheduledTask: (Ready) launchtrayprocess - \Microsoft\Windows\Setup\gwx - C:\Windows\system32\GWX\GWX.exe /tasklaunch (file missing)
O22 - ScheduledTask: (Ready) refreshgwxconfig - \Microsoft\Windows\Setup\gwx - C:\Windows\system32\GWX\GWXDetector.exe (file missing)
O22 - ScheduledTask: (Ready) refreshgwxconfig-B - \Microsoft\Windows\Setup\GWXTriggers - C:\Windows\system32\GWX\GWXDetector.exe (file missing)
O22 - ScheduledTask: (Ready) refreshgwxconfigandcontent - \Microsoft\Windows\Setup\gwx - C:\Windows\system32\GWX\GWXDetector.exe (file missing)
O22 - ScheduledTask: (Ready) refreshgwxcontent - \Microsoft\Windows\Setup\gwx - C:\Windows\system32\GWX\GWXConfigManager.exe /RefreshContent (file missing)
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service S2: Google Update-Dienst (gupdate) - (gupdate) - Microsoft Corporation - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
O23 - Service S3: Adobe Flash Player Update Service - (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (file missing)
O23 - Service S3: Google Update-Dienst (gupdatem) - (gupdatem) - Microsoft Corporation - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe (file missing)
Now click on
fix checked.
After the fix is complete, then
reboot your machine.
Step 2: ClearLNK
Download ClearLNK save it to your desktop.
Drag the file Check_Browsers_LNK from your Collection log made earlier.
As per picture.
A report on the work as a file
ClearLNK- <date> .log
Will be produced, post that log.
Step 3: AVZ Fix
Copy the content of the code box below.
Code:
begin
SetAVZGuardStatus(True);
DeleteService('gupdatem');
DeleteService('gupdate');
DeleteFile('C:\Program Files (x86)\Google\Update\GoogleUpdate.exe','32');
DeleteFile('C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe','32');
RegKeyParamDel('HKEY_LOCAL_MACHINE','SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg\AvgUi','command');
DeleteFile('C:\Program Files (x86)\Cuppat\Application\chrome.exe','32');
DeleteFile('C:\Windows\system32\GWX\GWX.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess','64');
DeleteFile('C:\Windows\system32\GWX\GWXConfigManager.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig','64');
DeleteFile('C:\Windows\system32\GWX\GWXDetector.exe','32');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent','64');
DeleteFile('C:\Windows\system32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B','64');
ExecuteSysClean;
RebootWindows(true);
end.
Open the folder you unzipped Autologger in. Double click the AVZ4 folder Right click AVZ run as admin.
Go to file -- Custom Scripts.
Paste the content of your clipboard into the Custom Script Area.
Click the Run Button.
The program will reboot your machine.
Step 4:Universal Virus Sniffer Scan
Download
uVS English Version To your desktop
Create a new folder on desktop.
Unzip it there.
Right click Start
and run as admin.
Select start under current User.
Then Select File.
The Select: Save Os Image with Checking digitial Signature (Slow)
Allow completion this can take some time.
Then go back to the folder where you Saved -- Unzipped -- UVS
Upload your system image. Here in your next reply.
It will look something similar to this.