Double-click MalwareBytes' (Note to Vista users, please right-click and select Run as Administrator.)
Go to Update tab to update Malwarebytes' Anti-Malware
Then click Check for Updates.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform Quick Scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so. Failure to reboot will prevent MBAM from removing all the malware.
OTL by OldTimer - Version 3.2.9.1 log created on 08102010_211003
Files\Folders moved on Reboot…
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\XTR8CD5A\signup2_mb[1].htm moved successfully.
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\APWLE7LL\jump1[2].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8IQLVFHY\general[1].css not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\8IQLVFHY\onus1[1].htm moved successfully.
File\Folder C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1KOV8BCV\flexcrollstyles[1].css not found!
C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\1KOV8BCV\flexcroll[1].js moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully.
File\Folder C:\Documents and Settings\Owner\Local Settings\Temp\JETC44D.tmp not found!
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\HKY388RE\indexCAIWQH8R.htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\HKY388RE\like[1].htm moved successfully.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\88MGJ7JI\iframe[1].htm moved successfully.
File\Folder C:\WINDOWS\temp\07b02e78-bd31-4773-87df-8c163557640e.tmp not found!
File\Folder C:\WINDOWS\temp\0a2dbed0-3855-4e87-bf7f-b0bea4ee8de7.tmp not found!
C:\WINDOWS\temp\3b7d3be2-f888-4dd0-8790-5907902be48a.tmp moved successfully.
File\Folder C:\WINDOWS\temp\3def6bec-79cf-4723-b4c3-c0f9b28a6943.tmp not found!
File\Folder C:\WINDOWS\temp\46bb4e6e-7559-45b9-98a7-23a1423e229d.tmp not found!
C:\WINDOWS\temp\5e26f0df-205f-4a84-9804-39dd1535ed30.tmp moved successfully.
C:\WINDOWS\temp\5fbe6887-8764-4213-b2ad-61cbb181be70.tmp moved successfully.
File\Folder C:\WINDOWS\temp\8481d721-d0c8-4650-94ca-11b7cb2c1f30.tmp not found!
File\Folder C:\WINDOWS\temp\8c932e78-b757-4f0c-95a6-219be0a68199.tmp not found!
File\Folder C:\WINDOWS\temp\96ac3a4d-4f46-4c5d-baef-9d1e70b03be4.tmp not found!
File\Folder C:\WINDOWS\temp\bec122b0-24df-4ffb-81cd-3e200ef7d07b.tmp not found!
File\Folder C:\WINDOWS\temp\c5c89a03-e0ef-4f8a-a840-927fb9f5b590.tmp not found!
File\Folder C:\WINDOWS\temp\cd4a4472-46a1-42b6-bf26-df9777afae2b.tmp not found!
File\Folder C:\WINDOWS\temp\ee2a3116-e6aa-43cb-98e3-9b9c8d881ef6.tmp not found!
Registry entries deleted on Reboot…
SystemLook log
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 21:32 on 10/08/2010 by Owner (Administrator - Elevation successful)
========== dir ==========
C:\Documents and Settings\Owner\Local Settings\Application Data\hgqlrggjs - Parameters: "/s"
—Files—
None found.
No folders found.
C:\Documents and Settings\Owner\Local Settings\Application Data\kngmupcgq - Parameters: "/s"
—Files—
None found.
No folders found.
C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} - Parameters: "/s"
To optimize scanning time and produce a more sensible report for review:
Close any open programs.
Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan. Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the license, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license is accepted, reset to 100%.
First try…pc froze during installation of Kaspersky scanner and virus definitions.
Soft boot to restart.
Got as far as 45 minutes into the Kaspersky scan and a virus came up, caught by AVG???
AVG Firewall, Resident Shield and antispy were turned off prior to scan, how could that happen?
AVG strongly recommend to restart, I chose to ignore.
This is when my pc froze up.
Do you think if I update Windows, this may help?
Make sure each time you boot up the AVG real time protection is off, because the auto start may have activated it.
If not, give another scanner a try.
Eset online scannner
You can use either Internet Explorer or Mozilla FireFox for this scan.
Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
Please go here then click on: [external image: Posted Image]
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install. All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.
Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
When prompted allow the Add-On/Active X to install.
Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
Now click on Advanced Settings and select the following:
Scan for potentially unwanted applications
Scan for potentially unsafe applications
Enable Anti-Stealth Technology
Now click on: [external image: Posted Image]
The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
When completed the Online Scan will begin automatically.
Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
When completed select Uninstall application on close if you so wish.
Now click on: [external image: Posted Image]
Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.