My children's computer has some kind of virus invovling a fake virus protection thing. It seems to have also disable McAfee. I have put it in safe mode and run SpyBot, Ad-Aware and some others. That hasn't helped. Also, I can't even get on the internet on it to download ATF Cleaners.
I hope someone can help.
Malware Logs can sometimes take a lot of time to research and interpret.
Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.
I would like you to run some scans on the infected system so I can take a closer look.
I can't even get on the internet
If you cannot connect to the Internet please use a clean (uninfected) machine to download the tools we require. Please burn the required tools to disk and then transfer them to the infected system.
exeHelper
Please download exeHelper by clicking here and save the file (called exeHelper.com) to your desktop.
Double click on exeHelper.com to run the fix.
A black window should pop up. Press any key to close once the fix is completed.
Post the contents of log.txt (it Will be created in the directory where you ran exeHelper.com).
NOTE: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
If you are having trouble downloading exeHelper, will run from a USB stick (copy the program to a USB stick using a different computer then plug into the infected system and run the program).
Please download Flash Disinfector
If you ran exeHelper from a USB stick, or if you used a USB stick to transfer the required tools, please download Flash Disinfector.
Click here to download Flash Disinfector and save the file (called Flash_Disinfector.exe) to your desktop.
Double click on the Flash_Disinfector.exe icon to run the program and follow any prompts that may appear.
The program may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so if prompted.
Wait until Flash disinfector has finished scanning and then exit the program.
Reboot your computer.
Please perform the following scan
Please download DDS from here or here and save it to your desktop.
Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
When done, DDS.txt will open.
After a few moments, attach.txt will open in a second window.
Save both reports to your desktop.
Please post the contents of the DDS.txt and Attach.txt logs in your next reply.
Please scan your system with GMER
Please download GMER from here and save the file to your desktop.
NOTE: The saved ".exe" file will have a completely random name. This is normal.
You can also download the zipped GMER program from here, here or here.
If you download GMER from one of the zipped links, unzip the file (called gmer.zip) to your desktop.
Before scanning, please make sure that all other running programs are closed and that no other actions (such as a scheduled antivirus scan) will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double click on the "randomname.exe" or "gmer.exe" to run the program.
Caution! These types of scans can produce false positives. Do NOT take any action on any "<— ROOKIT"entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
Click on "NO".
In the right panel, you will see a number of boxes that have check marks placed next to them.
Leave these boxes as they are, but please ensure that the "Show all" box is un-checked.
Now click the "Scan" button.
Once the scan is complete, you may receive another notice about rootkit activity. This is normal.
Click on "OK".
GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt".
Save the file where you can easily find it, such as your desktop.
Post the contents of GMER.txt in your next reply.
In your next reply please provide the exeHelper log, the DDS logs and the GMER log.