I consider myself (know myself to be) a novice at fixing computer problems. I am a Word and Internet user, and would be grateful for help. We have contracted a virus or something called "Spyware Protection," which is making us unable to open our programs. We CAN access the internet by simply clicking on the Explorer icon, but that's all we can get to work. Messages and word balloons pop up every few seconds on the screen with security warnings and "suchandsuch a program.exe can not start." I see that there is a section in the malware forums devoted to this virus, but some of the instructions were difficult for me to understand.
Thanks for any help!
Matt
Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs.
Please do not run any scans other than those requested
Please follow all instructions in the order posted
All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
Do not attach any logs/reports, etc.. unless specifically requested to do so.
If you have problems with or do not understand the instructions, Please ask before continuing.
Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
Go HERE to get a randomly named copy of GMER. Scroll down to the Download section and click Download EXE. Save it to your desktop.
Locate the file you downloaded
Right click on it and select rename
on the keyboard type exz1hs.scr
hit enter
Download OTL to your desktop.
Locate OTL.exe
Right click on it and select rename
on the keyboard type OTL.scr
hit enter
GMER
Before scanning with GMER, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Right click exz1hs.scr and click "Run as Administrator" to run it. If asked to allow gmer.sys driver to load, please consent .
If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.
In the right panel, you will see several boxes that have been checked. Uncheck the following …
IAT/EAT
Drives/Partition other than Systemdrive (typically C:\)
Show All (don't miss this one)
Then click the Scan button & wait for it to finish.
Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
Save it where you can easily find it, such as your desktop, and post it in your next reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
If GMER will not run in normal windows, please run it in Safe Mode
Next
OTL
Right click on OTL.scr and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
Check the boxes beside LOP Check and Purity Check.
In the window under Custom Scans/Fixes copy and paste the all of the bolded text below
Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.
Please post back with
GMER log
both OTL logs
Please describe the computer's behavior at the moment.