Hi stubbie, welcome to the forum.
To make cleaning this machine easier
- Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs. - Please do not run any scans other than those requested
- Please follow all instructions in the order posted
- All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
- Do not attach any logs/reports, etc.. unless specifically requested to do so.
- If you have problems with or do not understand the instructions, Please ask before continuing.
- Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
You have a nasty rootkit that can sometimes be quite stuborn to remove.
Your system has been infected by one or more
Rootkits/Backdoor Trojans.
Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. It may be prudent to backup your information, reformat, and reinstall.
I strongly suggest you do the following immediately:
- From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
- DO NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passwords and transaction information.
If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.
Should you wish to continue cleaning this machine please follow the instructions below.
Are you missing some shortcuts or folders? I see several folders that are hidden. I see part of the rootkit that you are infected with, do you have any other problems or symptoms?
Next
Let's have a quick look at a couple of things before we start.
Please open OTL
- Make sure all other windows are closed and to let it run uninterrupted.
- When the window appears, click the None button near the top (it may looked greyed out)
- In the Extra Registry section change it to All
- In the window under Custom Scans/Fixes copy and paste the following
%temp%\smtmp\*.* /s >
%USERPROFILE%\..|smtmp;true;true;true /FP
- Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open 2 notepad windows,
OTL.Txt and
Extra.txt. Please post these logs.
Download
aswMBR.exe to your desktop.
Right click aswMBR.exe and click "Run as Administrator" to run it
Click the "Scan" button to start scan
[external image: Posted Image]
On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]
There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.
Please post back with
- both OTL logs
- aswMBR log
- MBR.zip (attached)
Thanks