url:mal

Having problems removing this virus. In addition, it looks like my computer also has/had adware-gen [adw], and java:agent-s [trj] and crypto-e [trj]. Doing a boot scan removed jave and crypto. But url:mal remains. Doing the OTL only created the OTL.txt log not the extras.txt log. I tried it again, same result so only the OTL log is attached.

Since I have not gotten any replies yet here is some more information when the avast! pop up window comes up. Half the time it won’t allow me to open either Foxfire or IE.

the latest object: Z0g7ai10.com/tZ90J9DP6t4Ymj02Y2xrPTluMSZiaWQ90… or cikh71ynks66.com/3uK04wXDWpqhFB
Infected: url:mal
Action: blocked
Process: c:\programfiles\mozilla firefox\firefox.exe

Any help/thoughts?

Did you try a Malwarebytes Free scan also ? If yes its can be nice to got the log. If something is detected…

mbam log with infected file. All other logs were clean

I dont like alot to download a file but i think the rest Essex or anyone will help you as its can get complicate. :wink:

Sorry.

so did that remove your problem ?

OBS: you did not update Malwarebytes before you scanned. Latest database is 4875 and you scanned with 4865

Hi there are a few files that need killing

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL DRV - (balytklk) -- C:\WINDOWS\System32\drivers\kuiiqmfy.sys File not found O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. [2010/10/17 17:16:40 | 000,013,590 | ---- | M] () -- C:\WINDOWS\System32\235.js [2010/10/17 17:15:22 | 000,020,480 | -H-- | M] () -- C:\SZKGFS.dat

:Files
ipconfig /flushdns /c
C:\WINDOWS\tasks\At*.job

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Run the script twice, both times, blue screen of death. Any thoughts?

One of the blue screens says:
page_fault_in_nonpage_area

don’t know if this helps at all

Could you try it from safe mode ?

If that fails then :

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[*]Double click on ComboFix.exe & follow the prompts.

[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.

http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

http://img.photobucket.com/albums/v706/ried7/whatnext.png

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.