[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
It still tries to open a chrome window with ‘brasil-pesquisa.pw’ on startup. I used avast to block the page from loading. But all other, more serious symptoms have disappeared.
[]Right-mouse click JRT.exe and select “Run as Administrator” the tool will open and start scanning your system
[]please be patient as this can take a while to complete depending on your system’s specifications
[]On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
[]post the contents of JRT.txt into your next message.
Could not locate or remove ‘Pesquisa do Google’ (Google Search). Tried reinstalling chrome, then ran JRT. ‘Pesquisa-brasil.pw’ tried to open during the scan, and when I rebooted. Still can’t change IE’s start page, but now it is set to ‘msn.com’. Everything else is working fine.
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Oddly patriotic piece of crap refuses to die. I think it is transmitted by pen drive, and that mine is infected. Is there a way to format the pen drive without the virus getting into the PC again?
Download McShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives
McShield scanned the drive, but didn’t find anything. Avast detected and deleted an autorun.inf trojan. I think its clean now. Only thing left is the site trying to open on startup.
When the Shortcut Cleaner has finished scanning your hard drive it will create a log file on your desktop called sc-cleaner.txt and then display it.
Please post that log
Hi sorry for the delay in getting back, after a lot of research I am unable to find a single solution as to where it is running from. Could you delete your chrome/IE icons from the desktop and the taskbar and let me know if that cures it