I have been infected by a malware located in this file WScript.exe. avast constantly popups and tells me that a thread has been found, however, i tried to run malwarebytes and didnt work, i had to change the name of the .exe, then worked, but havent found nothing. Then i runed OTL, and Hijackthis… iv attached the logs, please help!
Re-run OTL.exe.
[*]Copy and paste the following text written inside of the quote box into the Custom Scans/Fixes box.
:OTL
O4 - HKU\S-1-5-21-218718581-1972798830-3493839355-1002..\Run: [2eb82] C:\Users\Alejandro\AppData\Roaming\38a\2eb82.js ()
O4 - Startup: C:\Users\Alejandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\73f.js ()
[2013.06.19 08:13:01 | 000,000,000 | -HSD | C] -- \39c9a
:Files
C:\Users\Alejandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\73f.js
C:\Users\Alejandro\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js
C:\Users\Alejandro\AppData\Roaming\38a
C:\39c9a
C:\Program Files (x86)\WjlmVOnG.dat
C:\Program Files (x86)\U7hijEHm.dat
C:\Program Files (x86)\aViQAtkO.dat
C:\Program Files (x86)\8jE4UJEV.dat
C:\Program Files (x86)\xEZ83eCr.dat
C:\Program Files (x86)\vYG1Bz2Y.dat
C:\Program Files (x86)\7G6iCiLp.dat
C:\Program Files (x86)\19GC1T7N.dat
C:\Program Files (x86)\ltM8bSLu.dat
ipconfig /flushdns /c
:commands
[CREATERESTOREPOINT]
[emptytemp]
[*]Then click the Run Fix button at the top.
[*]Let the program run unhindered; it will reboot the system when it is done and open notepad with logreport. Attach here that logreport.
Thank you very much!!!, my problem was solved!!! Thanks!!
Please upload a folder c: \ _OTL as zip on http://www.wikisend.com/
Paste download link here.