Please help remove malware.

I have attached the two text files.

oops here’s other one

OTL logs is saved as Unicode and look like chinese … must be saved as ANSI to be readable

see here how to do it https://forum.avast.com/index.php?topic=151206.msg1098542#msg1098542

Hello, let’s skip OTL

Please download zoek.zip or zoek.rar by smeenk (
http://www.mcshield.net/personal/magna86/Images/Zoek_icon.png
) from here or here and save it to your Desktop.
Unpack the archive…

[*]Close any open browsers
[*]Temporarily disable your AntiVirus program. (If necessary)
If you are unsure how to do this please read this or this Instruction.

[*]Double click on zoek.exe to run the tool .
Please wait for the tool to start…

[*]Copy the text present inside the code box below and paste it into the large window in the zoek tool:

createsrpoint;
gpt.ini;z 
C:\Windows\System32\GroupPolicy;v
C:\Windows\SysWOW64\GroupPolicy;v 
StandardSearch; 
installer-list; 
installedprogs; 
uninstall-list;

[*]Click on
http://www.mcshield.net/personal/magna86/Images/Run%20Script%20by%20zoek.png
button.
Please wait until a logreport will open (this can be after reboot)

[*]Save notepad to your Desktop and attach here zoek-results.log
Note: It will also create a log in the C:\ directory named “zoek-results.log

Weird, it looks normal when I open it…

Anyhoot, I resaved it as ANSI, hope that’s ok.

Looks like TwinEagle responded as I was typing…soooooooo…do I still need to do the zoek log?

Yes, please attach Zoek report too.

I tried downloading both the zip and rar file, but neither files can be extracted…help?

Zoek on Wikisend.

[URL=http://wikisend.com/download/361312/zoek (1).zip]zoek (1).zip[/URL]

If Avast! gives you a hard time, disable the shields… The program is perfectly safe.

It’s not Avast that’s giving me problems. Windows is telling me the zipped folders are empty.
http://imgur.com/q9WSXso

http://imgur.com/q9WSXso

Go here and download .exe

http://hijackthis.nl/smeenk/

here’s the zoek

Re-run zoek with the script below and attach here fresh zoek log results.
[COLOR=red]NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system[/COLOR]

C:\Windows\Sysnative\anqkdai.kna;f
C:\Windows\SysNative\config\systemprofile\AppData\Roaming\skwovj.kik;f
C:\Windows\SysNative\config\systemprofile\AppData\Roaming\lrix.gkx;f
C:\Windows\SysNative\config\systemprofile\AppData\Roaming\wtitli.och;f
emptyalltemp;
autoclean;

***** NEXT *****

Please download Farbar Recovery Scan Tool by Farbar and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.

[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Under Optional Scan ensure “List BCD” and “Driver MD5” are ticked.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.

here are the files

Download attached fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

***** NEXT *****

Once again we shall use FRST for additional checks. Re-run FRST/FRST64 by double-clicking:

[*]Type rpcss.dll into the Search: field in FRST then click the Search File(s) button.
[*]FRST will search your computer for files and when finished it will produce a log Search.txt in the same directory the tool is run.
[*]Please attach it to your reply.

Here are the files, still getting popups =(

Download attached fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

Tell me how is your computer now?

:frowning: ummmm…so I downloaded the fix list (placed it in same location as FRST). Ran the fix, and it asked for a reboot afterwards. I did and it started normally, then after the windows logo it stayed on a black screen for a while and it rebooted again. This process repeated for six times before I hit the power button. I tried opening in safe mode but same result. So I had it do a startup repair…and we’re back! What do you want me to do, continue where I left off?

hmmm…i’m not seeing any popups…here’s the fixlog before the reboot issue.

nevermind, 8 just popped up at once…