This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please Pleas Help Me

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

everytime i click a link from google it takes me to another website, which is irrelevant. Also my messages in myspace won't send, it just clicks back to the new message box,here is my log. hope you can help. thanks adam

Logfile of HijackThis v1.99.1
Scan saved at 10:23:11, on 03/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 SP2 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ACTIV Software\ACTIVdriver\ActivDRVservice.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Research Machines\Network Management\RMC3IEngine\bin\utsU.exe
C:\Program Files\Research Machines\Network Management\RM LST SAG\bin\RM LST Station Helper Service.exe
C:\Program Files\Research Machines\Network Management\Printer Credits\RMClientEvtService.exe
C:\Program Files\Research Machines\Network Management\Event Forwarding Service\RMEventForwardingService.exe
C:\Program Files\Research Machines\RM Tutor 2\Controller\RMMacAgent.exe
C:\Program Files\Research Machines\Classmate\PolicyMerger\PolicyMergerS.exe
C:\Program Files\Research Machines\Network Management\Printer Wrapper\RMPrinterWrapper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\H+H\Virtual CD 4\System\vcdsecs.exe
C:\Program Files\Research Machines\Network Management\RM Synchronise\filesynccom.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Research Machines\Classmate\PolicyMerger\PolicyMerger.exe
C:\WINDOWS\Explorer.exe
C:\PROGRA~1\H_H~1\VIRTUA~1\System\VCDPlay.exe
C:\program files\research machines\network management\rm synchronise\rmsyncicon.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\ACTIV Software\ACTIVdriver\ACTIVcontrol.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Research Machines\Network Management\Logoff\rmlogoff.exe
C:\Program Files\Research Machines\Network Management\UserType Indicator\UserTypeIndicator.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Research Machines\RM Tutor 2\Controller\RMLogonMon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\DOCUME~1\JWELCH~1.INT\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Shared Links
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat Reader 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: (no name) - {636438C6-14FF-4696-B588-4D8E9E538417} - C:\WINDOWS\system32\kaaakaa.dll
O2 - BHO: Image Helper - {64D712D1-84D9-281C-CE7D-32439D631863} - C:\WINDOWS\system\bpmtcs32.dll
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [RM Outlook Profile Setup] C:\Program Files\Research Machines\Network Management\Outlook Profile Setup\OutlookProfileSetup.exe
O4 - HKLM\..\Run: [RegLock] RegLock
O4 - HKLM\..\Run: [WorkConnector] C:\Program Files\Research Machines\Network Management\Work Connector\WorkConnector.exe
O4 - HKLM\..\Run: [VCDPlayer] C:\PROGRA~1\H_H~1\VIRTUA~1\System\VCDPlay.exe
O4 - HKLM\..\Run: [RMCDReset] C:\Program Files\Research Machines\CD ROM Player\CDROMPlayer.exe /reset
O4 - HKLM\..\Run: [RMSyncIconTray] c:\program files\research machines\network management\rm synchronise\rmsyncicon.exe
O4 - HKLM\..\Run: [ccApp] -
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [ActivDRVAutostart] C:\Program Files\ACTIV Software\ACTIVdriver\ACTIVcontrol.exe /startup
O4 - HKLM\..\Run: [ACTIVfilter] C:\Program Files\ACTIV Software\ACTIVdriver\ACTIVfilter.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [qbmepdfn] C:\WINDOWS\system32\qbmepdfn.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [qbmepdfn] C:\WINDOWS\system32\qbmepdfn.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: RMLogonMon.lnk = C:\Program Files\Research Machines\RM Tutor 2\Controller\RMLogonMon.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O15 - ProtocolDefaults: 'file' protocol is in Intranet Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Intranet Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Intranet Zone, should be Internet Zone
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://eu-housecall.trendmicro-europe.com/…ivex/hcImpl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = conyersxp.internal
O17 - HKLM\Software\..\Telephony: DomainName = conyersxp.internal
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = conyersxp.internal
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = conyersxp.internal
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: odkajqqu - C:\WINDOWS\SYSTEM32\kaaakaa.dll
O23 - Service: ACTIVdriver Control (ActivDRVcontrol) - ACTIV Software Ltd - C:\Program Files\ACTIV Software\ACTIVdriver\ActivDRVservice.exe
O23 - Service: AutoExNT - Unknown owner - C:\WINDOWS\system32\AutoExNT.Exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: filesynccom - Unknown owner - C:\Program Files\Research Machines\Network Management\RM Synchronise\filesynccom.exe
O23 - Service: NetOp Helper ver. 7.65 (2004168) (NetOp Host for NT Service) - Danware Data A/S - c:\program files\research machines\rm tutor 2\controller\xp sp2\NHOSTSVC.EXE
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: RMC3IEngine (PMSUtilityScheduler) - Research Machines plc - C:\Program Files\Research Machines\Network Management\RMC3IEngine\bin\utsU.exe
O23 - Service: RM Privileged User Service (PrvlUserService) - Research Machines plc - C:\Program Files\Research Machines\Network Management\Privileged User Service\PrvlUserService.exe
O23 - Service: RM LST Station Helper Service - Research Machines plc. - C:\Program Files\Research Machines\Network Management\RM LST SAG\bin\RM LST Station Helper Service.exe
O23 - Service: RM Printer Credits Client Service (RMClientEvtService) - Unknown owner - C:\Program Files\Research Machines\Network Management\Printer Credits\RMClientEvtService.exe
O23 - Service: RM Event Forwarding Service (RMEventForwardingService) - Research Machines plc - C:\Program Files\Research Machines\Network Management\Event Forwarding Service\RMEventForwardingService.exe
O23 - Service: RMMacAgent - Unknown owner - C:\Program Files\Research Machines\RM Tutor 2\Controller\RMMacAgent.exe
O23 - Service: RM Policy Merger Service (RmPolicyMergerS.exe) - Research Machines plc - C:\Program Files\Research Machines\Classmate\PolicyMerger\PolicyMergerS.exe
O23 - Service: RM Printer Wrapper Service (RMPrinterWrapper) - Unknown owner - C:\Program Files\Research Machines\Network Management\Printer Wrapper\RMPrinterWrapper.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: StationTidy - Unknown owner - C:\Program Files\Research Machines\Network Management\Station Tidy\Stationtidy.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Virtual CD v4 Security service (VCDSecS) - H+H Software GmbH - C:\Program Files\H+H\Virtual CD 4\System\vcdsecs.exe
Hi,adam and welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
dan
Hi adam s

I need to check out a file on your system.

Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath,browse and find the file click open which will place it in the field,do this one at a time.

C:\WINDOWS\system32\kaaakaa.dll

Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html

post me the results
dan
Complete scanning result of "kaaakaa.dll", received in VirusTotal at 04.03.2007, 20:45:12 (CET). Antivirus Version Update Result AhnLab-V3 2007.4.4.0 04.03.2007 no virus found AntiVir 7.3.1.48 04.03.2007 TR/Dldr.ConHook.Gen Authentium 4.93.8 04.03.2007 no virus found Avast 4.7.936.0 04.03.2007 no virus found AVG 7.5.0.447 04.03.2007 no virus found BitDefender 7.2 04.03.2007 no virus found CAT-QuickHeal 9.00 04.03.2007 no virus found ClamAV devel-20070312 04.03.2007 no virus found DrWeb 4.33 04.03.2007 no virus found eSafe 7.0.15.0 04.03.2007 Suspicious Trojan/Worm eTrust-Vet 30.6.3536 04.03.2007 no virus found Ewido 4.0 04.03.2007 no virus found FileAdvisor 1 04.03.2007 no virus found Fortinet 2.85.0.0 04.02.2007 no virus found F-Prot 4.3.1.45 04.03.2007 no virus found F-Secure 6.70.13030.0 04.03.2007 no virus found Ikarus T3.1.1.3 04.03.2007 Trojan.Win32.Delf.zj Kaspersky 4.0.2.24 04.03.2007 no virus found McAfee 4999 04.03.2007 no virus found Microsoft 1.2306 04.03.2007 no virus found NOD32v2 2166 04.03.2007 no virus found Norman 5.80.02 04.03.2007 no virus found Panda 9.0.0.4 04.03.2007 Suspicious file Prevx1 V2 04.03.2007 no virus found Sophos 4.16.0 03.30.2007 no virus found Sunbelt 2.2.907.0 04.03.2007 no virus found Symantec 10 04.03.2007 no virus found TheHacker 6.1.6.084 04.02.2007 no virus found VBA32 3.11.3 04.03.2007 no virus found VirusBuster 4.3.7:9 04.03.2007 no virus found Webwasher-Gateway 6.0.1 04.03.2007 Trojan.Dldr.ConHook.Gen Aditional Information File size: 79360 bytes MD5: c62eb64232c9a8c3fa6e434cc96212db SHA1: 7e739d407531f1570538b3608e0a5699f35f02fc packers: UPX
Hi adam

we need to put HJT into a permanent folder.
Create a folder on the desktop, right click on the desktop, new folder, and name it "HJT". Now locate "C:\DOCUME~1\JWELCH~1.INT\LOCALS~1\Temp\Temporary Directory 4 for hijackthis.zip\HijackThis.exe" right click HijackThis.exe copy and
paste it into the folder you created on the desktop.
The reason I ask for this is, unless HJT is in its own folder it will not make backups and should things not go the way we want them to, we will be able to return to a point where we can start again.

please do this before starting the fix.

______________________

Take your time do it in the order I have detailed.

Download ATF Cleaner by Atribune and save it to your Desktop.
Do not use yet!

Ewido is now known as ( AVG Anti-Spyware.)

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
Dont use yet!
____________________

Download win32delfkil.exe.
Save it on your desktop.
Close all windows.
Double click on win32delfkil.exe to start the removaltool.
The computer will reboot automatically.
After reboot a logfile will open: c:\windelf.txt
Post the contents of the logfile,
_______________________

I noticed you have allowed some sites into your trusted zone!
If you use these sites frequently, and trust the sites, and are comfortable leaving these 015 entries in your Trusted Zone, that's up to you.
however, realize that you are taking a big security risk by allowing any site to have unfettered access to your Trusted Zone.
This is your call it's your machine, I can only advise you.


Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O2 - BHO: (no name) - {636438C6-14FF-4696-B588-4D8E9E538417} - C:\WINDOWS\system32\kaaakaa.dll
O2 - BHO: Image Helper - {64D712D1-84D9-281C-CE7D-32439D631863} - C:\WINDOWS\system\bpmtcs32.dll
O2 - BHO: (no name) - {73364D99-1240-4dff-B12A-67E448373148} - C:\WINDOWS\system32\ipv6mons.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [qbmepdfn] C:\WINDOWS\system32\qbmepdfn.exe
O4 - HKCU\..\Run: [qbmepdfn] C:\WINDOWS\system32\qbmepdfn.exe

Please note! The HijackThis O6 section corresponds to an Administrative lock down for changing the options or the homepage in Internet explorer by changing certain settings in the registry.
This entry would legitimately show if an administrator set the restriction on purpose or if the user utilized Spybot S&D's Home Page and Option Lock down features in the Mode ->Advanced Mode -> Tools -> IE Tweaks section. (Or there could be other similar tools with similar options/functions.
Are you the administrator and did you set the restriction? If you didn't, then you can fix the following two entries.
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O15 - ProtocolDefaults: 'file' protocol is in Intranet Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in Intranet Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Intranet Zone, should be Internet Zone
O20 - Winlogon Notify: odkajqqu - C:\WINDOWS\SYSTEM32\kaaakaa.dll

WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit

We need to reveal system folders
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon.
  • Select the Tools menu and click Folder Options
  • After the new window appears select the View tab.
  • Place a checkmark in the checkbox labeled Display the contents of system folders
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types
  • Remove the checkmark from the checkbox labeled Hide protected operating system files
  • Press the Apply and then the ok button and shut down my computer
  • Now your computer is configured to show all hidden files.
  • For you and the tools to be able to see appropriate files we need to Show Hidden Files
Re-boot into safe mode

  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

C:\WINDOWS\SYSTEM32\kaaakaa.dll << This file
C:\WINDOWS\system32\qbmepdfn.exe << This file
C:\WINDOWS\system32\qbmepdfn.exe << This file
C:\WINDOWS\system32\ipv6mons.dll << This file
C:\WINDOWS\system\bpmtcs32.dll << This file
C:\WINDOWS\system32\kaaakaa.dll << This file
____________

Run ATF cleaner
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
  • If you use Firefox browser.
    • Click Firefox at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
  • If you use Opera browser.
    • Click Opera at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.

Run AVG Anti-Spyware

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)

      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
___________________

please do an online scan with Kaspersky Online Scanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Please include new HJT log, AVG Anti-Spyware log and kaspersky log
in your next post
Thanks dan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI