Hi tweaker,
Your system has been infected by one or more Rootkits/Backdoor Trojans.
This may allow hackers to remotely control your computer, steal critical system information and Download and Execute files
More information on Remote Access Trojans can be found here.
I strongly suggest you do the following immediately:
[*] From a known clean computer, change all your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
[*] DO NOT change passwords or do any transactions while using the infected computer until it has been cleaned.
.
This tool should take care of most of it. We’ll check the services later and see which need to be fixed.
Please read through the instructions to familarize youself with what to expect when the tool runs.
It is vitally important that combofix is renamed before it is even started to download
Please download ComboFix from Link 1 to your Desktop.
Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your [u]desktop
[*]If you are using Firefox, make sure that your download settings are as follows:
-Tools->Options->Main tab
-Set to “Always ask me where to Save the files”.
[*]During the download, before you save it to your desktop, rename Combofix to jgh.exe
[]It is important you rename Combofix during the download, but not after.
[]Please do not rename Combofix to other names, but only to the one indicated.
[]Close any open browsers.
[]Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix
[*]Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause “unpredictable results”.
[*]Click on this link [color=green]to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don’t know how to disable it, please ask.
[*]Right click on ComboFix.exe (jgh.exe in your case), click Run as Administrator & follow the prompts.
Notes:
1.Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer’s settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. If after running combofix you recieve an message “Illegal operation attempted on a registery key that has been marked for deletion” or similar reboot the computer.
Please post back with
[*]combofix log
How is the computer?
Thanks