Hello,
This morning I was doing some Google work and clicked through to a link that was obviously a "Spam Center "of sorts….I clicked off fast, but then WinPlus popped up asking if I wanted to allow changes to the start up. I have tried to research each item and cannot tell if these are bad, or just happen to be updates that were downloading today. I ran my normal Avira scan and Malewarebytes….MWB found 2 infected files which it removed, then the Avira found nothing….
Thanks,
Sean
Added on 1/5/10:
Tnetworkscannerxcontrol.ocx
Msxml4.DLL
msxml4.dll
jp21exp.dll
deploytk.dll
ITdetector.ocx
Name.dll
(Sorry, I could not get WinPatrol to print a log that showed what is listed under the "Recent" tab……)
Can you post a log from MalwareBytes' so we can what it removed? (open it and go to the Logs tab)
Please also run the following two scans so we can make sure there is nothing else on your machine (they won't take long and do not remove anything, just provide info).
Please download DDS and save it to your desktop.
Disable any script blocking protection
Double click dds.scr to run the tool.
When done two logs should open:
DDS.txt
Attach.txt
Save both reports to your desktop.
—————————————————
Post the contents of the DDS.txt report in your next reply
Attach the Attach.txt report to your post by scrolling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and then click UPLOAD.
We Need to check for Rootkits with RootRepeal
Download RootRepeal from one of the following locations and save it to your desktop.
Open [external image: Posted Image] on your desktop.
Click the [external image: Posted Image] tab.
Click the [external image: Posted Image] button.
In the Select Scan dialog, check [external image: Posted Image]
Push Ok
Check the box for your main system drive (Usually C:), and press Ok.
Allow RootRepeal to run a scan of your system. This may take some time.
Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt. Please post this log in your next reply.