I got about 9 “blocked site” messages when I started using my computer today. I read on these forums and downloaded the Malwarebytes program and the OTL posted here as well. I ran both of these and got logs for both. My desktop is blank and all icons are gone as of now, and still, when starting to use my computer I get the blocked site warning.
I know the log says successfully deleted, but it is not. I still get the avast warnings and several windows popping up. Running microsoft’s malware removal tool now…
We are awaiting your OTL log…please attach it to your next post. Thank you. After posting, please make no further changes to your machine until Essexboy assists you; I have alerted him and he comes on the forum late UK time.
[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in netsvcs
%SYSTEMDRIVE%*.exe
/md5start
consrv.dll
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT /s
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBIOS /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
C:\Windows\assembly\tmp\U*.* /s
%Temp%\smtmp\1*.*
%Temp%\smtmp\2*.*
%Temp%\smtmp\3*.*
%Temp%\smtmp\4*.*
CREATERESTOREPOINT
[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Post both logs
Thank you for posting your OTL logs. Essexboy will work with you on them. After everthing is in the clear and you have run your machine for a while, you should upgrade Avast to the current version of 6.0.1367. For now, wait for Essexboy’s instructions.
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.