This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Antivirus.net

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

OK I have Antivirus.net.

I run Windows XP

I have unplugged the computer from the network, and the internet.

AVG virus scan was run before Antivirus.net started blocking everything and it was claen. Last AVG update was 1/4/2011

I was forced by the Antivirus.net to run hijack this in safe mode. Anything attempted in regular running mode is blocked, as an unexecuitable file.


thanks in advance,

skip

Kijack this log file:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 12:13:31 AM, on 2/5/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.17093)
Boot mode: Safe mode with network support

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Documents and Settings\Administrator\Application Data\U3\0266700EC5C20409\LaunchPad.exe
K:\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GM5260
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…TP&M=GM5260
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…TP&M=GM5260
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [showwnd] showwnd.exe
O4 - HKLM\..\Run: [readericon] C:\Program Files\Digital Media Reader\readericon45G.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKLM\..\Run: [IntelAudioStudio] "C:\Program Files\Intel Audio Studio\IntelAudioStudio.exe" TRAY
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [CCUTRAYICON] C:\Program Files\Intel\IntelDH\CCU\CCU_TrayIcon.exe
O4 - HKLM\..\Run: [NMSSupport] "C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe" /startup
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [AlwaysReady Power Message APP] ARPWRMSG.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe
O4 - HKCU\..\Run: [Power2GoExpress] NA
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Intel® Alert Service (AlertService) - Intel Corporation - C:\Program Files\Intel\IntelDH\CCU\AlertService.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG10\avgwdsvc.exe
O23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Intel® Software Services Manager (ISSM) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\ISSM.exe
O23 - Service: Intel® Viiv™ Media Server (M1 Server) - Unknown owner - C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
O23 - Service: Intel® Application Tracker (MCLServiceATL) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\MCLServiceATL.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Intel® Remoting Service (Remote UI Service) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe

–
End of file - 6086 bytes
Hello carsonlp and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 5 days your thread will be closed.

Lets see of the following will allow us to run some deeper system scans:

  • rkill


    • Please download rkill (Courtesy of Bleepingcomputer.com).
    • There are 5 different versions of this tool. If one of them will not run, please try the next one in the list.
    • Note: Vista and Windows 7 Users must right click and select "Run as Administrator" to run the tool.
    • Note: You only need to get one of the tools to run, not all of them.


    1. rkill.exe
    2. rkill.com
    3. rkill.scr
    4. WiNlOgOn.exe
    5. uSeRiNiT.exe

    Note: You will likely see a message from this rogue telling you the file is infected. Ignore the message. Leave the message OPEN, do not close the message.

    Run rkill repeatedly until it's able to do it's job. This may take a few tries.

    You'll be able to tell rkill has done it's job when your desktop (explorer.exe) cycles off and then on again.

  • Please perform the following scan


    • Please download DDS from here and save it to your desktop.
    • Disable any script blocking protection (How to Disable your Security Programs)
    • Double click on the DDS icon to run the tool (may take up to 3 minutes to run).
    • When done, DDS.txt will open.
    • After a few moments, attach.txt will open in a second window.
    • Save both reports to your desktop.
    • Please post the contents of the DDS.txt and Attach.txt logs in your next reply.

  • Please scan your system with GMER


    [external image: Posted Image]
    Download GMER Rootkit Scanner from here or here.
    • Extract the contents of the zipped file to desktop.
    • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent.
    • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
    • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOTKIT" entries


Please post the DDS logs and the GMER log in your next reply. If you enconter any problems with the scans just let me know.
JonTom, Thanks for the help. It took a bit but I was finally able to get rkill to run. The malware kept telling me that Trend Micro was blocking the web page. That had me confused because although I run AVG on this computer, I also run trend on another computer, on the same network. At any rate it prevented me from running any of the suggested files, via the browser. I had to download the rkill.exe on another computer, save it to a memory stick, and run it from there. In fact that is how I have run all the suggested scans. After running rkill things settled down a bit. DDS scan ran fine. When I tried to unzip the Gmer file it ran as if I had started an exe file. I was able to uncheck the boxes you mentioned. Show all was already unchecked, and I left it unchecked. I have 4 'results' files for you. rkill.txt dds.txt ddslog1.txt gmer.txt I am going to past them all to one file which I hope to upload as an attachment. I do not envy you going thru that stuff but please know it is very much appreciated. thanks, skip
Hello carsonlp

Thank you for the logs.

We will begin by running ComboFix on this machine. I can see that you have AVG installed. AVG is known to act aggressively towards ComboFix and prevents it from running. In order to run ComboFix successfully you will have to uninstall AVG from your machine (You can do so through Add/Remove Programs).

Please work your way through the following steps:

Download ComboFix from one of these locations, but do not run it yet.


Link 1
Link 2

IMPORTANT!!! Place ComboFix.exe on your Desktop.


  • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
  • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
  • Copy and Paste the text in the quotebox below into the open Notepad window:

    DDS::
    uInternet Settings,ProxyServer = http=127.0.0.1:8992
    uInternet Settings,ProxyOverride =


  • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
  • Close any open browsers.
  • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Refering to the picture below, drag CFScript.txt into ComboFix.exe

    [external image: Posted Image]
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
  • Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    [external image: Posted Image]
  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
  • When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  • Notes: Do not mouse-click Combofix's window while it is running. That may cause it to stall.
  • Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Should there be issues with internet afterward:

In IE: Tools Menu -> Internet Options -> Connections Tab -> Lan Settings -> uncheck "use a proxy server" or reconfigure the Proxy server again in case you have set it previously.

In Firefox: Tools Menu -> Options… -> Advanced Tab -> Network Tab -> "Settings" under Connection and uncheck the proxyserver, set it to No Proxy.

Please post the ComboFix log in your next reply :)
OK JonTom, Not a successful report this time. I downloaded combofix and placed on memory stick. Ran notepad, copy and pasted DDS:: etc and saved as instructed to memory stick. The only deviation from your exact instructions is that on the computer running windows 7, I opened notepad from the start menu, to do the copy/paste from the forum. I did not do this not from 'start' then 'run' on an xp machine. I presume that makes no difference. Also the grey 'quote' was not included in the copy paste. Moved to infected computer. Uninstalled AVG After reboot to uninstall AVG, Antivirus.net seems to have been revitalized. For the remainder, understand that I am getting constant pop ups and initiations of browser, going to various web sites. (You dont need any viagra by any chance?) ^_^ I tried to install the recovery console. Hooked up to internet and tried to install recovery console. Failed, malware keeps hyjacking the browser. Anything I try to do seems to be overridden or simply dissapears as malware 'refreshes' or overwrites desktop. Attempted to install recovery console from XPCD. CD runs to beginning screen, I try to click on 'other options', system seems to accept click, momentary hourglass, then am right back to initial CD startup screen screen. I tried this a number of times, same result. OK so I'll let Combofix install it. From memory stick, I drag both Combofix and CFScript file to desktop. Right clickeach Icon; 'properties' indicates that I have one text file and one executible file, on desktop, as I would have hoped. I drag the CFScript icon over to the Combofix Icon. I get a small 'progress' window with green boxes being added in from left to right, just briefly … The screen flickers and then nothing. I try double clicking the Combofix Icon, nothing apparent. I try draging CFScript over to Combofix icon again, and again see the 'progress' window momentarily. Now I am convinced I am probably running combofix twice, and the malware is refreshing the desktop, which hides whatever it is I am doing. To test this I try ctl/alt/del, to get a look to see if I am running combofix. I get a screen flicker but no window. I try this several times but no change. Then I press ctl/alt/del and hold them, eventually the buffer 'out runs' the malware and I can see the task manager window. But if I release the buttons, it quickly is overwritten and I am back to my 'apparent' desktop. Do we need to run rkill again? I was tempted, but resisted. thanks, skip
Hello carsonlp

Thank you for the update.

Are you able to download the tools using the infected machine? If you have to transfer tools to the infected machine please let me know (from reading your post it sounds as though you are using a Win7 system to download the required tools and then you are using a USB stick to transfer the tools to the infected XP machine).

I try double clicking the Combofix Icon, nothing apparent.

The malware is interfering with our tools.

Lets try this:

Delete the copy of ComboFix you have on the desktop of the infected machine by dragging it to the Recycle Bin.
Once you have done that empty the bin.

Reboot the infected machine into Safe Mode with Networking:


  • Reboot Your System in Safe Mode with Networking


  • Restart your computer.
  • As soon as BIOS is loaded begin tapping the F8 key until the "Advanced Options" menu appears.
  • Use the arrow keys to select the Safe Mode with Networking menu item.
  • Press Enter.

Download a fresh copy of ComboFix from Here

Do not run the CFScript at this time, just double click on the ComboFix icon and allow the tool to run.

If you are unable to download ComboFix directly from the infected machine you will have to tranfer it to the infected machine using the USB method.

Let me know how you get on in your next reply.
JonTom, Alright. Booted up on infected machine in safe mode with networking. Entered forums, and clicked on 'here'. Downloaded Combofix and ran from 'Downloads Folder' as it would not drag to the desktop. Combofix successfully installed Restore Console. Combofix ran successfully, log is attached. thanks, skip
Hello carsonlp

Thank you for the log. Is this a company machine?

it would not drag to the desktop

It is very important that the tools we use are ran directly from the desktop since they have been designed to be used this way. Running them from a different location can sometimes prevent them from operating correctly. If you use Firefox you can configure it to download things directly to your desktop:

Open Firefox.
Click on the "Tools" tab and select "Options".
Click on the "Main" tab (it may be listed as "General").
Under the downloads section click on the radio button next to "Save files to", then click on the Browse button and select desktop.
Click on okay.

Please delete this copy of ComboFix and get a new one, making sure that it is placed directly onto the your desktop (thank you for your patience).

Once you have done the above, please delete the original CFSCript.txt file you created and carry out the steps listed below:

  • Please work through the following steps


  • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
  • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
  • Copy and Paste the text in the quotebox below into the open Notepad window:

    DirLook::
    C:\3874fa007b870ccb6c

    FileLook::
    ubccvbwsjmo.exe

  • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
  • Close any open browsers.
  • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Refering to the picture below, drag CFScript.txt into ComboFix.exe

    [external image: Posted Image]

  • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
  • Once the log is produced, re-engage your resident anti virus.

Please post the ComboFix log in your next reply.
JonTom, In safe mode … Removed old Combofix. Downloaded new Combofix and saved it to desktop. Start/run/notepad copy and pasted data and saved as instructed to desktop. Drag txt file to combofix ran fine. Attached is log file, Combofixlog2 Not a business computer, bought used, but I am using it to build a business web site. thanks, skip
Hello carsonlp

Not a business computer

Thanks for letting me know.

ComboFix log looks okay. Please work your way through the following steps:


  • Please perform the following scan:


    • Please download MalwareBytes AntiMalware by clicking here and save the file (called mbam-setup.exe) to your desktop.

    • Double click on the mbam-setup.exe icon to install the program.
    • Follow the prompts during installation and have the Installation Wizzard create a desktop icon.
    • Once installed, double click on the MalwareBytes AntiMalware icon to launch the program.
    • Click on the "Update" tab and then on "Check for Updates".
    • The program will now install the latest Malware definition files.
    • Once complete, click on the "Scanner" tab, select "Perform Quick Scan"and then click on "Scan".
    • Once the program has scanned your computer, a log file will be created in Notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.


    • If the scan detects any Malware-related objects, make sure that everything is checked, and click "Remove Selected" <– Very Important.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to restart your computer.
    • The log is automatically saved by MBAM and can be viewed by clicking the "Logs" tab.
    • Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process. If asked to restart your computer, please do so immediately.
    • Come back here to this thread and Paste the log in your next reply.

  • Please un-install J2SE Runtime Environment 5.0 Update 2


    • Click on "Start" then on "Control Panel" and then on "Add or remove programs".
    • Click on "remove a program". A list of currently installed programs will be displayed.
    • Find the "J2SE Runtime Environment 5.0 Update 2" program, click on it once and then click on the "uninstall" button.
    • If you are prompted to re-boot your computer to complete the uninstall please do so.

  • Please update your Java


    • Click on "Start", then on "Control Panel".
    • Go to "Add or Remove Programs" and uninstall any previous versions of Java that you find.
    • Reboot your computer.
    • Next, download the latest version of Java by clicking here
    • Scroll down the page until you reach "Java Platform Standard Edition".
    • Beneath this and to the right, you will see a button marked "Download JRE".
    • Click the "Download JRE" button.
    • Select the platform (Windows, in your case), multi language.
    • Accept the license agreement and click on "Continue".
    • You do not have to register if you do not want to (the registration step is optional).
    • Scroll down and click on the file called jre-6u23-windows-i586.exe located under "Windows Offline Installation".
    • Save the file to your desktop.
    • Do not select Run.
    • Double click on the saved file (jre-6u23-windows-i586.exe) to install the update.
    • Delete the downloaded installation file after completing the above procedure and reboot your system if not prompted to do so.

    Please post the MBAM log in your next reply along with a fresh DDS log.
JonTom, Uncertain results, likely my fault. Downloaded and ran MBAM in safe mode. No problems found. Saved log file to desktop. Could not remove J2Se… in safe mode so went to normal mode and removed J2Se… One error came up 'java.lang.nullpointer exception' . When I asked for details, the program finished running without giving me any more information. Found no other Java in add/remove programs. Downloaded to desktop jre6u 23 … and installed offline. Rebooted even though it wasnt required. Began composing reply to you on forums. Could not find the MBAM log file. So I again downloaded MBAM to desktop, and ran. Found three items, which the software removed successfully. Since I no longer have J2Se (I checked add-remove programs) I am leaving JAVA alone. Waiting further instructions MBAM log file attached thanks, skip

Attachments:

Hello carsonlp

Thank you for the update. MBAM has removed a couple of malware remnants. Lets run an Online scan to check for anythig that might have been missed (Please boot into Safe Mode with Networking for the scan as you are still running without an AV at this time).

  • Please run the following scan


  • Note: You will need to use Internet Explorer for this scan.
  • Note for Vista/Windows 7 Users: ESET is compatible but Internet Explorer must be run as Administrator. To do this, right-click on your Internet Explorer icon and select "Run as Administrator".
  • Please disable your real time security programs before performing the scan.


  • Scan your system with Eset Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use.
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps).
  • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the [external image: Posted Image] icon on your desktop.


  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option to "Remove Found Threats" is UN checked.
  • Push the "Start" button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push [external image: Posted Image]
  • Push [external image: Posted Image], and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the [external image: Posted Image] button.
  • Push [external image: Posted Image]

Please post the ESET log in your next reply.
Hello carsonlp

Thank you for the ESET log.

  • Please work through the following steps


  • Open Notepad (Click on "Start", then on "Run" and type "notepad" (without quotations) in the Open field, then click on "OK").
  • NOTE: Do not Use Wordpad or any other text editor except Notepad or the script will fail.
  • Copy and Paste the text in the quotebox below into the open Notepad window:

    File::
    C:\Documents and Settings\Owner.YOUR-E3513F081B\Local Settings\Application Data\Mozilla\Firefox\Profiles\x1vu5abw.default\Cache\49F2B1E9d01

    SkipFix::

  • Save this as "CFScript.txt" (including the quotation marks), change the "Save as type" to "All Files" and save it to your desktop.
  • Close any open browsers.
  • Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Refering to the picture below, drag CFScript.txt into ComboFix.exe

    [external image: Posted Image]

  • When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
JonTom, Running in normal mode … Unable to download combofix using IE, so I downloaded to desktop using Fire Fox. CFScript.txt copied and pasted as instructed. Ran combofix as instructed. Attached log file. thanks, skip

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI