This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] "Your System Has Been Infected"

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer background all of the sudden says "Your system has been infected" and no matter how many times I try and change the background it won't allow me to not even in safe mode. How do I get rid of this background and or virus or whatever it is? I already tried a system restore and it worked for an hour or two until I shut down my computer and once I restarted it came back. :pullhair:
Hi

:welcome:

I'm martix and I'll be glad to assist you and look over your PC problems.

Before we proceed please read carefully the following guidelines:

  • Malware removal process takes time so be patient and stick with the thread until I’ve given you the “All clean". Absence of symptoms does not mean your machine is clean!
  • Do not run any scans or install/uninstall any applications without being directed to do so.
  • Follow my instructions carefully and in the order they are posted.
  • If you do not understand any step(s) provided, please do not hesitate to ask before continuing.
  • If you do not reply within 5 days after my last response the topic will be closed.
Now we can proceed. Please follow the instructions:


[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


NEXT


Please download DDS by sUBs from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs)
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
—————————————————
  • Post the contents of the DDS.txt and Attach.txt report in your next reply



  • Things I'll need in your next reply:

    1. GMER log
    2. DDS log
Thank you so much heres what you needed it wouldn't let me attach the gmer.text file so I just copied and pasted it into this


GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-19 10:08:29
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\kfkdyfod.sys


—- Kernel code sections - GMER 1.0.15 —-

.rsrc C:\WINDOWS\system32\drivers\atapi.sys entry point in ".rsrc" section [0xF86717A4]

—- User code sections - GMER 1.0.15 —-

.text C:\WINDOWS\system32\WgaTray.exe[124] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\WINDOWS\system32\WgaTray.exe[124] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[236] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\winss.exe[236] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\svchost.exe[352] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe[388] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe[388] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe[472] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\CA\PPRT\bin\ITMRTSVC.exe[472] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Java\jre6\bin\jqs.exe[508] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Java\jre6\bin\jqs.exe[508] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\csrss.exe[644] KERNEL32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\winlogon.exe[668] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\services.exe[716] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\lsass.exe[728] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[760] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe[760] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\svchost.exe[884] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\svchost.exe[964] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[1060] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe[1060] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\System32\svchost.exe[1104] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 008B000A
.text C:\WINDOWS\System32\svchost.exe[1104] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 008C000A
.text C:\WINDOWS\System32\svchost.exe[1104] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 008A000C
.text C:\WINDOWS\System32\svchost.exe[1104] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\System32\svchost.exe[1104] USER32.dll!GetCursorPos 7E42974E 5 Bytes JMP 00F5000A
.text C:\WINDOWS\System32\svchost.exe[1104] ole32.dll!CoCreateInstance 7750057E 5 Bytes JMP 00E8000A
.text C:\WINDOWS\system32\svchost.exe[1252] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\svchost.exe[1356] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\wscntfy.exe[1428] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\WINDOWS\system32\wscntfy.exe[1428] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\System32\alg.exe[1500] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\spoolsv.exe[1596] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\wuauclt.exe[1668] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 007C000A
.text C:\WINDOWS\system32\wuauclt.exe[1668] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 007D000A
.text C:\WINDOWS\system32\wuauclt.exe[1668] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003E000C
.text C:\WINDOWS\system32\wuauclt.exe[1668] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\WINDOWS\system32\wuauclt.exe[1668] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[1680] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\OcHealthMon.exe[1680] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe[1800] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe[1800] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\svchost.exe[1888] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1920] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Viewpoint\Common\ViewpointService.exe[1920] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\Explorer.EXE[2164] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00B2000A
.text C:\WINDOWS\Explorer.EXE[2164] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00B8000A
.text C:\WINDOWS\Explorer.EXE[2164] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 00B1000C
.text C:\WINDOWS\Explorer.EXE[2164] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2308] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[2308] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Documents and Settings\Compaq Evo\Desktop\gmer\gmer.exe[2432] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Documents and Settings\Compaq Evo\Desktop\gmer\gmer.exe[2432] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2956] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe[2956] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2968] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe[2968] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Java\jre6\bin\jusched.exe[2992] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Java\jre6\bin\jusched.exe[2992] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe[3032] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe[3032] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[3040] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe[3040] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe[3140] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe[3140] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\WINDOWS\system32\wuauclt.exe[3484] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00A4000A
.text C:\WINDOWS\system32\wuauclt.exe[3484] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00A5000A
.text C:\WINDOWS\system32\wuauclt.exe[3484] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 003E000C
.text C:\WINDOWS\system32\wuauclt.exe[3484] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\WINDOWS\system32\wuauclt.exe[3484] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[3544] ntdll.dll!NtProtectVirtualMemory 7C90D6EE 5 Bytes JMP 00AE000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3544] ntdll.dll!NtWriteVirtualMemory 7C90DFAE 5 Bytes JMP 00AF000A
.text C:\Program Files\Internet Explorer\iexplore.exe[3544] ntdll.dll!KiUserExceptionDispatcher 7C90E47C 5 Bytes JMP 009C000C
.text C:\Program Files\Internet Explorer\iexplore.exe[3544] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Internet Explorer\iexplore.exe[3544] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\Messenger\msmsgs.exe[3668] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\Messenger\msmsgs.exe[3668] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe[3680] kernel32.dll!TerminateProcess 7C801E1A 1 Byte [C3]
.text C:\Program Files\comcasttb\ComcastSpywareScan\ComcastAntispy.exe[3680] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]
.text C:\Documents and Settings\Compaq Evo\ceoduug.exe[3696] kernel32.dll!TerminateThread 7C81CB3B 1 Byte [C3]

—- Devices - GMER 1.0.15 —-

AttachedDevice \Driver\Tcpip \Device\Ip msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp msfwhlpr.sys (OneCare Firewall Helper Driver/Microsoft Corporation)

Device -> \Driver\atapi \Device\Harddisk0\DR0 82F10618

—- Files - GMER 1.0.15 —-

File C:\WINDOWS\system32\drivers\atapi.sys suspicious modification

—- EOF - GMER 1.0.15 —-

Attachments:

Its important that you follow these instructions and rename Combofix as this Rootkit infection will stop it from running if its not renamed.

Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2


[external image: Posted Image]


[external image: Posted Image]

* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
Please follow the instructions:

You should uninstall Viewpoint Manager.
Click Start>Control Panel>Add/Remove Programs.
Locate and uninstall Viewpoint Manager.

NEXT

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

http://forums.whatthetech.com/Your_System_Has_Been_Infected_t112135.html

Collect::
c:\windows\system32\zzop91.dll

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\zzop91]

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

NEXT

Please download Malwarebytes' Anti-Malware from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Ok done here is the malwarebytes log thingy Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4131 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 5/22/2010 12:10:01 PM mbam-log-2010-05-22 (12-10-01).txt Scan type: Quick scan Objects scanned: 132264 Time elapsed: 8 minute(s), 55 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 46 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{a078f691-9c07-4af2-bf43-35e79eecf8b7} (Adware.Softomate) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\spool\prtprocs\w32x86\C5D.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.

Attachments:

Please do a scan with Kaspersky Online Scanner or from Here.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

[external image: Posted Image]

everytime I run Kaspersky my computer turns off all of the sudden….I can run the first part of it but everytime it gets about 20 minutes into the my computer scan my computer turns off all the sudden.
Let's try different scan:

Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
I finally got it to run all the way through and here is what it gave me: C:\Documents and Settings\Compaq Evo\Desktop\Programs\LimewireSetup.exe probably a variant of Win32/Adware.HotBar.E application C:\Documents and Settings\RIPDADDY\Application Data\Microsoft\Internet Explorer\Desktop.htt Win32/TrojanDownloader.FakeAlert.AED virus C:\Program Files\HBLite\bin\11.0.181.0\HBLiteSAAX.dll a variant of Win32/Adware.HotBar.E application C:\Qoobox\Quarantine\C\Documents and Settings\Compaq Evo\autorun.inf.vir INF/Autorun virus C:\Qoobox\Quarantine\C\Documents and Settings\Compaq Evo\ceoduug.exe.vir Win32/AutoRun.VB.IH worm C:\Qoobox\Quarantine\C\Documents and Settings\Compaq Evo\ceoduug.scr.vir Win32/AutoRun.VB.IH worm C:\Qoobox\Quarantine\C\Program Files\Internet Explorer\msimg32.dll.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL.vir a variant of Win32/Toolbar.MyWebSearch.B application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL.vir Win32/FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE.vir Win32/Adware.FunWeb application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\PROGRA~1\MYWEBS~1\bar\1.bin\MWSOEMON.EXE.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\WINDOWS\system32\0023.DLL.vir Win32/Agent.QOH trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\0035.DLL.vir Win32/Witkinat.A trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\f3PSSavr.scr.vir Win32/Toolbar.MyWebSearch application C:\Qoobox\Quarantine\C\WINDOWS\system32\sdra64.exe.vir a variant of Win32/Kryptik.BTJ trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\smss32.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\warning.html.vir Win32/TrojanDownloader.FakeAlert.AED virus C:\Qoobox\Quarantine\C\WINDOWS\system32\wexe.exe.vir Win32/Witkinat.N trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon32.exe.vir Win32/TrojanDownloader.FakeAlert.AED trojan C:\Qoobox\Quarantine\C\WINDOWS\system32\Drivers\atapi.sys.vir Win32/Olmarik.RF trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP10\A0080211.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP10\A0080252.scr Win32/AutoRun.VB.IH worm C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP10\A0080293.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP10\A0080362.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP10\A0080363.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0080658.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0080685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0080688.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0081685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0081688.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0082685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0082687.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0084685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0085685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0085687.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0086685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0086688.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0087685.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP11\A0087687.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP12\A0087845.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP12\A0087849.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP12\A0087853.exe Win32/Witkinat.A trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP13\A0087860.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP13\A0088860.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP13\A0089860.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP14\A0089862.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP14\A0090860.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP15\A0090862.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP15\A0091199.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0095195.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0095197.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0096195.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0096199.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0097195.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098196.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098200.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098250.sys Win32/Olmarik.RF trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098289.inf INF/Autorun virus C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098290.exe Win32/AutoRun.VB.IH worm C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098291.scr Win32/AutoRun.VB.IH worm C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098302.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098304.dll Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098305.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098306.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098307.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098308.DLL a variant of Win32/Toolbar.MyWebSearch.B application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098309.DLL Win32/FunWeb application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098310.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098311.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098312.SCR Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098313.DLL Win32/Adware.FunWeb application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098314.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098315.EXE Win32/Adware.FunWeb application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098316.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098319.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098320.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098321.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098322.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098323.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098324.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098326.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098327.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098328.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098329.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098330.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098331.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098332.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098333.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098334.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098335.EXE Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098336.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098344.DLL Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098346.DLL Win32/Agent.QOH trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098347.DLL Win32/Witkinat.A trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098349.scr Win32/Toolbar.MyWebSearch application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098352.exe a variant of Win32/Kryptik.BTJ trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098353.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098354.exe Win32/Witkinat.N trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP16\A0098355.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP17\A0100849.dll probably a variant of Win32/Adware.HotBar.E application C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0020102.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0020105.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0021102.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0021104.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0021114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0022114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0023114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0024114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0024115.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0025114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0025117.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0026114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0027114.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP8\A0027115.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0027129.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0028125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0028128.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0029125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0030125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0030126.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0031125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0031127.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0032125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0032128.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0033125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0033127.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0034125.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0034132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0034135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0035132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0035133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0036132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0036135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0037132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0037134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0038132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0038136.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0039132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0039135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0040132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0041132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0041134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0042132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0042135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0043132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0043133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0044134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0045132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0045135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0046132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0046134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0047132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0048132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0048135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0049132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0049133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0050132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0050134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0051132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0051135.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0052132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0052133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0053132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0053133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0054132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0054133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0059136.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0059137.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0060132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0060134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0061132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0061134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0063132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0063134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0064132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0064134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0065132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0065134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0066132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0066134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0067132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0067134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0067142.scr Win32/AutoRun.VB.IH worm C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0072132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0072134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0073132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0073134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0074132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0075132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0075134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0075142.scr Win32/AutoRun.VB.IH worm C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0076132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0077132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0077134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0078132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0078134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0079132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0079134.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0079142.scr Win32/AutoRun.VB.IH worm C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0080132.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0080133.exe Win32/TrojanDownloader.FakeAlert.AED trojan C:\System Volume Information\_restore{9B2C037C-6302-4A28-9F89-88BA78E5FCBC}\RP9\A0080181.scr Win32/AutoRun.VB.IH worm C:\WINDOWS\system32\config\systemprofile\Application Data\Microsoft\Internet Explorer\Desktop.htt Win32/TrojanDownloader.FakeAlert.AED virus
:thumbup: Good Job!

While I'm preparing the fix try to make a scan with GMER:

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If you have problems running it try to run it in Safe mode

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI