I think my wife has downloaded a virus that Avast can’t get rid of completely. I have constant messages popping up in the corner telling me Avast has blocked a threat. I get up to 51 of these messages before it starts again. They always refer to outgoing mail and that Avast has blocked it, but whatever it is doing it isn’t getting rid of it completely.
Process is always mostly C:\windows\syswow64\svchost.exe
[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs
THEN
Download aswMBR.exe ( 4.5mb ) to your desktop.
Double click the aswMBR.exe to run it Click the “Scan” button to start scan
:Commands
[CREATERESTOREPOINT]
:OTL
O2:64bit: - BHO: (no name) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O4 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001..\Run: [bfxjbhhh] C:\Users\Maria\AppData\Local\dgcfjdgm.exe ()
O4 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001..\Run: [buvgcoev] C:\Users\Maria\AppData\Local\xwteuboc.exe ()
O4 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001..\Run: [mttlkgab] C:\Users\Maria\AppData\Local\qkvwukij.exe ()
O4 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001..\Run: [rwqsbljh] C:\Users\Maria\AppData\Local\rqjkremj.exe ()
O4 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001..\Run: [smkhwaqi] C:\Users\Maria\AppData\Local\vqikptpt.exe ()
O4 - HKU\S-1-5-21-1210587596-3410156555-903348221-1001..\Run: [vqqqkdcd] C:\Users\Maria\AppData\Local\epefeoee.exe ()
[2010/02/11 02:43:14 | 000,036,136 | ---- | C] (Oberon Media) -- C:\ProgramData\FullRemove.exe
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.