:Files
C:\6a4
c:\documents and settings\Administrator\Start Menu\Programs\Startup\283.js
c:\documents and settings\Bronwyn and Kym\Start Menu\Programs\Startup\283.js
c:\documents and settings\All Users\Start Menu\Programs\Startup\283.js
c:\documents and settings\Default User\Start Menu\Programs\Startup\283.js
:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Loged back on to check your reply only to find control panel again disabled and malicious URL pop Ups appearing again.Should I still run the otl as requested in your last post.This post is done from my mobile phone.
Yes but we will do some additional work as the drive you are plugging in is infected and we need to stop that first
Plug in the drive
Download McShield to your desktop and install
It will initially run a scan and show the result as a toaster by the system clock
Then in the control centre select scanner and tick unhide items on flash drives
Will do when I get home tonight.
The drive I plugged in originally has not been connected to the pc since the problem started,that is why I posed my last question.
I hope I have not confused the issue by not stating this earlier.
Regard’s,
Kym
Hi essexboy,
Sorry to take so long to get back to you,got called away on business at short notice and only just got back.
The MC2 Shield log is attached as requested.
Will now run the fresh OTL fix and post that log when complete.
Regard’s,
Kym
Not sure if I have done the fix correctly.
Tried running it in normal mode and nothing happened for over an hour,so I rebooted in safe mode and ran the fix,took a few minutes.
Rebooted and ran the quick scan in normal mode,log attached.
If I have messed things up I am sorry.
Kym
Sorry I thought that was the log I attached in my last post,obviously not.
MalwareBytes is still unable to be run,control panel still deactivated and malicious pop up warnings still appearing but not as often.
PC is running faster than it was.
My connection manager indicates I am downloading a bucket load of data as well,not sure what or why.
Kym
Sorry this is taking so long,work is extremely busy and I am doing 14-16 hour days,so not getting a lot of time to myself.
I re ran combo fix as requested,log attached.
Control panel has reappeared in start box,malicious url pop ups have stopped again.
MalwareBytes has updated and is accessable.
Will see what happens when I close the pc and log on again.
Regard’s,
Kym
OK,so run a new OTL scan,retreive the log and leave the pc running until I run the new fix.
Will run when I get home tonight.
This post from the work pc.
Kym
Ended up having to work all through easter ,so have only just had time to run OTL.
Log is attached.
PC will remain on until I hear back from you.
Regard’s,
Kym
:OTL
O4 - HKCU..\Run: [7d7e7] C:\Documents and Settings\Bronwyn and Kym\Application Data\6b6\7d7e7.js ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\203c2.js ()
O4 - Startup: C:\Documents and Settings\Bronwyn and Kym\Start Menu\Programs\Startup\203c2.js ()
[2013/03/23 22:50:39 | 000,000,000 | -HSD | C] -- C:\6a4
[2013/03/28 23:04:58 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\Bronwyn and Kym\Application Data\6b6
[2013/03/05 14:35:47 | 000,000,000 | -HSD | C] -- C:\Program Files\74607
:Reg
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
"7d7e7"=-
:Files
C:\Documents and Settings\Bronwyn and Kym\Start Menu\Programs\Startup\*.js
c:\Documents and Settings\All Users\Start Menu\Programs\Startup\*.js
[override]
C:\Windows\System32\wscript.exe
[stopoverride]
:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
Not having much luck with the fix.
Pasted the fix into OTL clicked “run fix” and left it to run.
Six hours later,nothing has happened.PC appears to be locked up and can not close OTL to try and run fix again.
PC is still on,will not reboot until I hear back.
Kym