We need to use tool with more power.
Step#1
[*] Please download BlitzBlank by emsisoft and save it to your desktop.
[*] Open Blitzblank.exe by double click on it.
[*] Click OK at the warning (and take note of it, this is a VERY powerful tool!).
[*] Click the Script tab and copy/paste the following text there:
DeleteFile:
f:\usuarios\Javier V\AppData\Local\Temp\iswizard\dwm.exe
f:\usuarios\JAVIER~1\AppData\Local\Temp\iswizard\dwm.exe
DeleteFolder:
f:\usuarios\Javier V\AppData\Local\Temp\iswizard
f:\usuarios\JAVIER~1\AppData\Local\Temp\iswizard
[*] Click Execute Now. Your computer will need to reboot in order to replace the files.
[*] When done, post me the report created by Blitzblank. you can find it at the root of the drive C:\
Step#2
Open notepad and copy/paste the text present inside the code box below:
Folder::
f:\usuarios\Javier V\AppData\Local\Temp\iswizard
f:\usuarios\JAVIER~1\AppData\Local\Temp\iswizard
c:\program files (x86)\Bit Coin Miner Removal Tool
f:\usuarios\Javier V\AppData\Roaming\PlusWinks
Save this as CFScript.txt
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Close all browser windows and refering to the picture above.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
Step#3
- Delete old zoek.exe and download new, fresh one.
- Re-run zoek.exe as you did before but use this script:
f:\usuarios\Javier V\AppData\Local\Temp\iswizard;f
f:\usuarios\JAVIER~1\AppData\Local\Temp\iswizard;f
C:\Program Files (x86)\Bit Coin Miner Removal Tool;f
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\anvisoft;v
C:\ProgramData\Anvisoft;v
C:\ProgramData\RegRun;v
dwm.exe;z
dwm.exe;a
iswizard;z
iswizard;a
Torntv;ff
F:\Usuarios\Javier V\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\torntv@torntv.com.xpi;f
bfcpnihmbfoaeoakalclfalkdepgiaje;chr
F:\Usuarios\Javier V\AppData\Roaming\SpecialSavings;fs
doicodjkmhpcdodnbhbcpocidcdlolgk;chr
iibmmjhgclhlahmjniokmhleigemjpbh;chr
F:\Usuarios\Javier V\AppData\Local\CRE\iibmmjhgclhlahmjniokmhleigemjpbh.crx;f
mocblcnaofikinigmceddfghppkkjbog;chr
F:\Usuarios\Javier V\AppData\Roaming\PlusWinks;fs
nbmafkdmkkckhggblphicnnhlgljnoje;chr
apdfllckaahabafndbhieahigkjlhalf;chr
F:\Usuarios\JAVIER~1\AppData\Local\Google\Drive\apdfllckaahabafndbhieahigkjlhalf_live.crx;f
iibmmjhgclhlahmjniokmhleigemjpbh;chr
F:\Usuarios\Javier V\AppData\Local\CRE\iibmmjhgclhlahmjniokmhleigemjpbh.crx;f
niapdbllcanepiiimjjndipklodoedlc;chr
FFdefaults;
chrdefaults;
emptyclsid;
emptyrecycle.bin;
emptyalltemp;
autoclean;
Click on RunScript button and attach here fresh zoek.exe log.