H ratchetclan4 & mbrinson,
The infection is a Trojan: TR/Crypt.ZPACK.Gen
First read this helpful page: http://forums.majorgeeks.com/showthread.php?t=187883
Now do a scan with MBAM from here: http://www.malwarebytes.org/mbam-download.php
Perform an update for MBAM via Update click button Check for Updates
Run a QuickScan
Give us a complete logfile as an added txtfile…
Clear Cache/Temp Files
Download TFC by OldTimer to your desktop
[*] Please double-click TFC.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
[*]It will close all programs when run, so make sure you have saved all your work before you begin.
[*]Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. Let it run uninterrupted to completion.
[*]Once it’s finished it should reboot your machine. If it does not, please manually reboot the machine yourself to ensure a complete clean.
Finally checking the manual removal procedure:
To remove Crypt.ZPACK.Gen, you must first stop any Crypt.ZPACK.Gen processes that are running in your computer’s memory. To stop all Crypt.ZPACK.Gen processes, press CTRL+ALT+DELETE to open the Windows Task Manager. Click on the “Processes” tab, search for Crypt.ZPACK.Gen, then right-click it and select “End Process” key.
To delete Crypt.ZPACK.Gen registry keys, open the Windows Registry Editor by clicking on the Windows “Start” button and selecting “Run.” Type “regedit” into the box and click “OK.” Once the Registry Editor is open, search for the registry key “HKEY_LOCAL_MACHINE\Software\Crypt.ZPACK.Gen.” Right-click this registry key and select “Delete.” Before doing this make a copy of your existing registry first…
Finally, to completely get rid of Crypt.ZPACK.Gen, you must manually remove other Crypt.ZPACK.Gen files. These Crypt.ZPACK.Gen files can be in the form of EXE, DLL, LSP, TOOLBAR, BROWSER HIJACK, and/or BROWSER PLUGIN. For example, Crypt.ZPACK.Gen might create a file like
%PROGRAM_FILES%\Crypt.ZPACK.Gen\Crypt.ZPACK.Gen.exe. Locate and remove these files,
polonus