Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Miserable computer face, Blue with frustration.

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Miserable computer face, Blue with frustration.

Unread postby pgmigg » August 21st, 2018, 9:28 pm

Hello Dave,

Unfortunately, but somehow you did not run the FRST fix and posted partially the fixlist instead of fixlog.
In the event that this was done successfully, a randomly named file with a list of instructions for the correction would be destroyed automatically, by closing the work of the FRST at the press of the FIX button.

Nevertheless do not be upset - the scan with the Malwarebytes AdwCleaner was successful.

Please do not try to return to my previous posts and do not run anything from there.
Below you will find new instructions.

Just this time, please be more attentive.

Step 1.
  1. Please copy FRST64.exe from your Download directory to the Desktop. <------------- it is very important step for you!!!
  2. Then right click on FRST64.exe and select Run as administrator, but this time when it opens ....
  3. Press Ctrl+y (Ctrl and y keys at the same time)
  4. A blank randomly named .txt Notepad file will be opened.
  5. Copy and paste the following into it (don't include Code: Select all) ....
    Code: Select all
    HKLM-x32\...\Run: [fst_us_143] => [X]
    HKU\S-1-5-21-28108215-2538129268-678420320-1002\...\MountPoints2: {2d6c1ba1-f1ba-11e4-82d3-a01d4808520a} - "F:\VZW_Software_upgrade_assistant.exe" 
    HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxySettingsPerUser] 0 <==== ATTENTION (Restriction - ProxySettings)
    ProxyServer: [.DEFAULT] => 1
    AutoConfigURL: [.DEFAULT] => file://C:/Users/CrisYouSasyMedic/AppData/Local/LPT/NewConfig.txt
    ProxyServer: [S-1-5-21-28108215-2538129268-678420320-1002] => 1
    AutoConfigURL: [S-1-5-21-28108215-2538129268-678420320-1002] => file://C:/Users/CrisYouSasyMedic/AppData/Local/LPT/NewConfig.txt
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1bNV5iGB7j76kR7EOZGkeQkbUBtqSnxyioASX7XiWPTst6sI9KCYqB5_pjxa3Wij2s2bTLp6N7jJBcdJwZ311GW516UswWsJFdEbWi_6uNVdmU-Zx1j8-VygoeXeZyfVf0WBe3H91G_hz5PzT8Kg1f5wodu9sgZYShH5Ism5nYHk,&q={searchTerms}
    HKU\S-1-5-21-28108215-2538129268-678420320-1002\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.facebook.com/topic/Philip-Seymour-Hoffman/108351132526165?source=whfrt&position=1&trqid=6039082446727169189
    SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
    SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\.DEFAULT -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?p=mKO_AwFzXIpYRa0T-NJ1bNV5iGB7j76kR7EOZGkeQkbUBtqSnxyioASX7XiWPTst6sI9KCYqB5_pjxa3Wij2s2bTLp6N7jJBcdJwZ311GW516UswWsJFdEbWi_6uNVdmU-Zx1j8-VygoeXeZyfVf0WBe3H91G_hz5PzT8Kg1f5wodu9sgZYShH5Ism5nYHk,&q={searchTerms}
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
    Toolbar: HKU\S-1-5-21-28108215-2538129268-678420320-1002 -> No Name - {093F479D-712E-46CD-9E06-62E734A05F68} -  No File
    AlternateDataStreams: C:\ProgramData\Temp:11590865 [177]
    AlternateDataStreams: C:\ProgramData\Temp:1416AAA6 [330]
    AlternateDataStreams: C:\ProgramData\Temp:2AD33723 [162]
    AlternateDataStreams: C:\ProgramData\Temp:2AF322BF [312]
    AlternateDataStreams: C:\ProgramData\Temp:2CB9631F [134]
    AlternateDataStreams: C:\ProgramData\Temp:363E775E [182]
    AlternateDataStreams: C:\ProgramData\Temp:3EC5BC08 [344]
    AlternateDataStreams: C:\ProgramData\Temp:491270B8 [314]
    AlternateDataStreams: C:\ProgramData\Temp:5E73E1C2 [182]
    AlternateDataStreams: C:\ProgramData\Temp:6B709AD7 [346]
    AlternateDataStreams: C:\ProgramData\Temp:7687A3E3 [382]
    AlternateDataStreams: C:\ProgramData\Temp:98CF1A39 [189]
    AlternateDataStreams: C:\ProgramData\Temp:9DBE6481 [130]
    AlternateDataStreams: C:\ProgramData\Temp:A4AF8D0D [165]
    AlternateDataStreams: C:\ProgramData\Temp:A6D6E537 [177]
    AlternateDataStreams: C:\ProgramData\Temp:A7DA2BCD [334]
    AlternateDataStreams: C:\ProgramData\Temp:A88BE334 [316]
    AlternateDataStreams: C:\ProgramData\Temp:B54E4B5A [342]
    AlternateDataStreams: C:\ProgramData\Temp:B6E6C4EA [179]
    AlternateDataStreams: C:\ProgramData\Temp:BEE39E9B [364]
    AlternateDataStreams: C:\ProgramData\Temp:C22674B6 [294]
    AlternateDataStreams: C:\ProgramData\Temp:C3899C0B [171]
    AlternateDataStreams: C:\ProgramData\Temp:C78DADEA [178]
    AlternateDataStreams: C:\ProgramData\Temp:CAC06C34 [177]
    AlternateDataStreams: C:\ProgramData\Temp:CBAF0C30 [183]
    AlternateDataStreams: C:\ProgramData\Temp:F5D01D7C [384]
    AlternateDataStreams: C:\ProgramData\Temp:F84B8DB5 [155]
    AlternateDataStreams: C:\ProgramData\Temp:F9F58B80 [180]
    AlternateDataStreams: C:\ProgramData\Temp:FAB64002 [146]
    AlternateDataStreams: C:\ProgramData\Temp:FBD274CF [171]
    AlternateDataStreams: C:\ProgramData\Temp:FC70A22A [370]
    HKLM\...\StartupApproved\StartupFolder: => "McAfee Security Scan Plus.lnk"
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Startup.exe]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{2EECD738-5844-4A99-B4B6-146BF802613B}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Extension Compatibility\{98889811-442D-49DD-99D7-DC866BE87DBC}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Startup.exe]
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\Application\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\Application\helperbar@helperbar.com\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\images\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\Application\helperbar@helperbar.com\components\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders|C:\Users\CrisYouSasyMedic\AppData\Local\Smartbar\Application\helperbar@helperbar.com\chrome\PublisherImages\
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Google\Chrome\NativeMessagingHosts\sb.host|""
    DeleteValue: HKEY_USERS\S-1-5-21-28108215-2538129268-678420320-1002\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Muvic.exe
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\Startup.exe|Params
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-28108215-2538129268-678420320-1002\Products\A0108BE1134FF8F478A405B6B2153F2D\InstallProperties|DisplayName
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{1EB8010A-F431-4F8F-874A-506B2B51F3D2}|DisplayName
    DeleteValue: HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\App Paths\Startup.exe|Params
    DeleteValue: HKEY_USERS\S-1-5-21-28108215-2538129268-678420320-1002\Software\Microsoft\Installer\Products\A0108BE1134FF8F478A405B6B2153F2D|ProductName
    DeleteValue: HKEY_USERS\S-1-5-21-28108215-2538129268-678420320-1002\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION|Muvic.exe
    DeleteValue: HKEY_USERS\S-1-5-21-28108215-2538129268-678420320-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall\{08998c2c-b970-4110-8c1f-7a405e284254}|DisplayName
    CMD: ipconfig /flushdns
  6. Press Ctrl+s (Ctrl and s keys at the same time) to save this file (directory will be selected as the Desktop automatically).
  7. Now press the Fix button once and wait until the FRST will process it.
  8. When FRST finishes you will be prompted to reboot your computer. Click OK.
  9. Your computer should now restart. On reboot navigate to your Desktop where you should find fixlog.txt. Copy and paste the contents in your reply.

Please post each log separately to prevent it being cut off by the forum post size limiter.
Check each after you've posted it to make sure it's all present, if any log is cut off you'll have to post it in sections...

Don't post anything as attachments unless I will ask you about it specifically!

Please include in your next reply:
  1. Do you have any problems executing the instructions?
  2. Content of the C:\AdwCleaner[S1].txt
  3. Contents of the fixlog.txt log file
  4. Do you see any changes in computer behavior?


Failure to post replies within 72 hours will result in this thread being closed
User avatar
Posts: 5501
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00
Register to Remove

Re: Miserable computer face, Blue with frustration.

Unread postby EnterDavysLocker » August 23rd, 2018, 9:59 pm

hello again pgmigg, I want to thank you for your help, and apologize for wasting some of your time, but do you mind if I hold off on this fix for the moment? I am ordering a new computer in the beginning of this next month in a couple weeks, I'm afraid I'll mess something up on this one and my Kid has to do daily lessons on home study. I'm hoping it will last long enough till the other computer get here, then I'd like to get the help from you again if possible.? if I mess up one of those steps then I won't have a computer running at the moment. Dave
Active Member
Posts: 12
Joined: August 3rd, 2018, 7:01 pm

Re: Miserable computer face, Blue with frustration.

Unread postby pgmigg » August 24th, 2018, 11:31 am

Hello Dave,

Dave wrote:I want to thank you for your help, and apologize for wasting some of your time, but do you mind if I hold off on this fix for the moment?
You are welcome and it is your choice.
Dave wrote:I am ordering a new computer in the beginning of this next month in a couple weeks, I'm afraid I'll mess something up on this one and my Kid has to do daily lessons on home study.
Good idea! :D
Dave wrote:I'm hoping it will last long enough till the other computer get here, then I'd like to get the help from you again if possible.? if I mess up one of those steps then I won't have a computer running at the moment.
Looking back, including the situation of a year ago with the same computer and another very experience helper, it seems to me that the best solution for you will not be to ask for help, which you naturally can always do, but make the backup of all your files, reformat the hard drive and install the Windows system from scratch. This method will simultaneously solve all problems, including infections.

In addition to the easy but hard-to-clean infection, your old computer has a lot of operating system problems, drivers and God knows what else, including a mismatch between system updates and programs, which in the end is highly likely to lead to the initial advice to reinstall the Windows, after few attempts to understand what is happening, which by the way, should not be done with us, but at the relevant technical forum...

It is also necessary to take into account the difficulties that you experience when carrying out instructions from helpers.

Good luck, Dave! :)

User avatar
Posts: 5501
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Miserable computer face, Blue with frustration.

Unread postby EnterDavysLocker » August 25th, 2018, 11:11 pm

this was my wife's computer and she passed away. Okay, I'll take your advice and I won't ask for help I'll take it to a repair shop. thanks for your help. Dave
Active Member
Posts: 12
Joined: August 3rd, 2018, 7:01 pm

Re: Miserable computer face, Blue with frustration.

Unread postby pgmigg » August 26th, 2018, 12:21 am

Hello Dave,

Dave wrote:this was my wife's computer and she passed away.
I'm sorry for your loss, Dave.
Dave wrote:Okay, I'll take your advice and I won't ask for help I'll take it to a repair shop.
Be sure to back up all the files you need and are important for you before taking the computer to the repair shop.
I highly recommend you to get technical help for your not related to malware problems outside of our forum and would like to refer you to a technical support forum like: Tech Support Guy.
Dave wrote:thanks for your help.
You are welcome, Dave!

User avatar
Posts: 5501
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00

Re: Miserable computer face, Blue with frustration.

Unread postby pgmigg » August 26th, 2018, 12:25 am

As suggestions have been made for possible resolutions for the issues noted in this topic, and no additional questions have been asked, it is presumed this topic has been finalized.
Therefore, it is now closed.
User avatar
Posts: 5501
Joined: July 8th, 2008, 1:25 pm
Location: GMT-05:00
Register to Remove


  • Similar Topics
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!

Who is online

Users browsing this forum: No registered users and 138 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware