Hi this looks different
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:OTL
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {167D9323-F7CC-48F5-948A-6F012831A69F} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {167D9323-F7CC-48F5-948A-6F012831A69F} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-2768925335-3035770563-1745516826-1000\..\Toolbar\WebBrowser: (no name) - {167D9323-F7CC-48F5-948A-6F012831A69F} - No CLSID value found.
O3 - HKU\S-1-5-21-2768925335-3035770563-1745516826-1000\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
@Alternate Data Stream - 178 bytes -> C:\ProgramData\TEMPFC5A2B2
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:3F30E778
@Alternate Data Stream - 1374 bytes -> C:\ProgramData\Microsoft:YV2I4Ig7L0kJanviIz3g6uK
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMPEDD192D
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 1241 bytes -> C:\Users\biteme\AppData\Local\Temp:buuotjz5uF91aaJp9xOT1PFq
@Alternate Data Stream - 1219 bytes -> C:\ProgramData\Microsoft:3Qxd15HiB6PepYrBWZjkE
@Alternate Data Stream - 1208 bytes -> C:\Users\biteme\AppData\Local\Temp:QOqqTz9yrPyk3IKFtPTS3u6x
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:69E87FA2
@Alternate Data Stream - 1187 bytes -> C:\ProgramData\Microsoft:Tv53qOhSSQNQDcCymiCxx7AZ
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:838D4792
@Alternate Data Stream - 1145 bytes -> C:\ProgramData\Microsoft:uqPtSRaZTZSKqcPDmHBVgxacee
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:12B8C802
:Files
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt /c
ipconfig /release /c
ipconfig /renew /c
:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the
Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the
Quick Scan button. Post the log it produces in your next reply.
THEN
Download the latest version of TDSSKiller from here and save it to your Desktop.
[*]Doubleclick on TDSSKiller.exe to run the application
http://dl.dropbox.com/u/73555776/TDSSFront.JPG
[*]Then click on Change parameters.
http://dl.dropbox.com/u/73555776/TDSSConfig.JPG
[*]Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK.
[*]Click the Start Scan button.
[*]If a suspicious object is detected, the default action will be Skip, click on Continue.
http://dl.dropbox.com/u/73555776/TDSSFound.JPG
[*]If malicious objects are found, they will show in the Scan results and offer three (3) options.
[*]Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process.
[*]Get the report by selecting Reports
http://dl.dropbox.com/u/73555776/TDSSEnd.JPG
[*]Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
Please copy and paste its contents on your next reply.