[*] I will be working on your Malware issues this may or may not solve other issues you have with your machine.
[*] The fixes are specific to your problem and should only be used for this issue on this machine.
[*] If you don’t know or understand something, please don’t hesitate to ask.
[*]Please refrain from making any further changes to your computer (Install/Uninstall programs, delete files, edit the registry, etc…)
[*] Please DO NOT run any other tools or scans whilst I am helping you.
[*] It is important that you reply to this thread. Do not start a new topic.
[*] Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
[*] Absence of symptoms does not mean that everything is clear.
… … … … … …
- Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Start
HKLM\...\Policies\Explorer\Run: [42688] C:\PROGRA~2\LOCALS~1\Temp\ccouqoh.scr [204038 2009-07-14] (Hause)
MountPoints2: {00e68579-c837-11e2-8a3a-000df070e542} - "F:\WD SmartWare.exe" autoplay=true
CHR RestoreOnStartup: "hxxp://ite-sy.net/", "hxxp://www.google.com/"
C:\PROGRA~2\LOCALS~1\Temp\ccouqoh.scr
End
-
Save notepad as fixlist.txt
NOTE. It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
-
Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.
… … … … … …
- Reboot your computer and re-run FRST, just click on Scan button and attach here freesh FRST.txt logreport.