Hi Alantb,
If you have DST it would be GMT-7 otherwise it's GMT-8.
2 fixes to do. They must be done in the order posted. After these fixes please connect the computer to the internet and follow the rest of the instruction. Do not use this computer for anything else except for downloading tools and this thread. This includes email.
On the
clean computer
Open a new Notepad session
- Click the Start button, click run
- in the run box type notepad
- click ok
- In the notepad, Click "Format" and be certain that Word Wrap is not checked.
- Copy and paste all the text in the code box below into the Notepad.
Do Not copy the word
CODE Note the script starts with
:
:Services
:Reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Gnecihutafuzaca"=-
:Files
c:\windows\system32\drivers\sst9.sys
c:\windows\system32\Spool\prtprocs\w32x86\sst8.tmp
c:\windows\system32\drivers\sst9.tmp
c:\temp\tidyup.exe
ipconfig /flushdns /c
:Commands
[emptytemp]
[createrestorepoint]
[Reboot]
In the notepad
- Click File, Save as..., and set the Save in to your Desktop
- In the filename box, type (including quotation marks) as the filename: "fix2.txt"
- Click save
Next, create this batch file.
Open a new Notepad session
- Click the Start button, click run
- in the run box type notepad
- click ok
- In the notepad, Click "Format" and be certain that Word Wrap is not checked.
- Copy and paste all the text in the code box below into the Notepad.
Do Not copy the word
CODE
ren "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl .exe" "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
ren "c:\program files\AVG\AVG9\avgtray .exe" "c:\program files\AVG\AVG9\avgtray.exe"
ren "c:\program files\Common Files\Ahead\Lib\NeroCheck .exe" "c:\program files\Common Files\Ahead\Lib\NeroCheck.exe"
ren "C:\Documents and Settings\Default User\Start Menu\Programs\Startup\enunum.exe" "C:\Documents and Settings\Default User\Start Menu\Programs\Startup\enunum.old"
ren "c:\program files\CyberLink\PowerDVD\Language\Language .exe" "c:\program files\CyberLink\PowerDVD\Language\Language.exe"
ren "c:\program files\Java\jre6\bin\jusched .exe" "c:\program files\Java\jre6\bin\jusched.exe"
ren "c:\program files\Picasa2\PicasaMediaDetector .exe" "c:\program files\Picasa2\PicasaMediaDetector.exe"
ren "c:\program files\ScanSoft\OmniPage15\OpAgent .exe" "c:\program files\ScanSoft\OmniPage15\OpAgent.exe"
ren "c:\program files\ScanSoft\OmniPage15\Opware15 .exe" "c:\program files\ScanSoft\OmniPage15\Opware15.exe"
ren "c:\program files\ScanSoft\OmniPage15\Ereg\Ereg .exe" "c:\program files\ScanSoft\OmniPage15\Ereg\Ereg .exe"
ren "c:\program files\Spybot - Search & Destroy\TeaTimer .exe" "c:\program files\Spybot - Search & Destroy\TeaTimer.exe"
ren "c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdupdate .exe" "c:\program files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdupdate.exe"
ren "c:\program files\CyberLink\PowerDVD\PDVDServ .exe" "c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
In the notepad
- Click File, Save as..., and set the Save in to your Desktop
- In the filename box, type (including quotation marks) as the filename: "myfix.bat"
- Click save
You will have a new file on your desktop called myfix.bat with an icon that looks like this
Transfer both files,
fix2.txt and
myfix.bat, to your infected computer's desktop.
On the
infected computer
Next, Double click on
OTL.exe - Under the Custom Scans/Fixes box at the bottom, paste in the contents of the notepad,fix2.txt.
Then click the
Run Fix button at the top
- Let the program run unhindered
- Please save the resulting log to be posted in your next reply.
Please post the
OTL fix log
Next
Double click
myfix.bat to run it. A black window may briefly flash on your screen, that's normal.
Next
We need some file informantion
- Make sure to use Internet Explorer for this
- Please go to VirSCAN.org FREE on-line scan service
- Copy and paste the following file path into the "Suspicious files to scan" box on the top of the page:
C:\Documents and Settings\Default User\Start Menu\Programs\Startup\enunum.old
- Click on the Upload button
- If a pop-up appears saying the file has been scanned already, please select the ReScan button.
- Once the Scan is completed, click on the "Copy to Clipboard" button. This will copy the link of the report into the Clipboard.
- Paste the contents of the Clipboard in your next reply.
Next
- Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, underneath Output at the top change it to Minimal Output
- UNCheck the boxes beside LOP Check and Purity Check.
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open a notepad window.
OTL.Txt . Please post it's contents
Please post back with
- OTL fix log
- Virscan results
- OTL.txt
Thanks