Do this on the computer you are posting from:
Copy the text in the codebox below:
Code:
:OTL
SRV - File not found [Auto] -- -- (ASKService)
DRV - File not found [File_System | Boot] -- -- (48296937)
DRV - File not found [Kernel | On_Demand] -- -- (.redbook)
DRV - File not found [Kernel | On_Demand] -- -- (.i8042prt)
DRV - File not found [Kernel | On_Demand] -- -- (.AFS2K)
IE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [REVHmWCGeSNc.exe] C:\Documents and Settings\All Users\Application Data\REVHmWCGeSNc.exe (Microsoft Corp)
O4 - HKU\Administrator_ON_C..\Run: [Media Finder] File not found
O4 - HKU\Administrator_ON_C..\Run: [MediaGet2] File not found
O4 - HKU\Administrator_ON_C..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroyx\TeaTimer.exe ()
O4 - HKU\LocalService_ON_C..\Run: [TabletWizard] File not found
O4 - HKU\NetworkService_ON_C..\Run: [TabletWizard] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKU\Administrator_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get.../ultrashim.cab (Reg Error: Key error.)
[2012/02/05 17:13:10 | 000,356,352 | -H-- | C] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\ZiUScmDdQAYPtc.exe
[2012/02/05 16:58:34 | 000,444,416 | -H-- | C] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\REVHmWCGeSNc.exe
[2012/02/06 17:17:30 | 000,048,016 | -HS- | M] () -- C:\WINDOWS\System32\c_53016.nl_
[2012/02/05 22:38:14 | 000,000,833 | -H-- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/02/05 22:32:35 | 000,000,304 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~ZiUScmDdQAYPtc
[2012/02/05 22:32:21 | 000,000,448 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\ZiUScmDdQAYPtc
[2012/02/05 22:32:09 | 000,000,192 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~ZiUScmDdQAYPtcr
[2012/02/05 17:13:26 | 000,000,815 | -H-- | M] () -- C:\Documents and Settings\Administrator\Desktop\System Check.lnk
[2012/02/05 17:13:10 | 000,356,352 | -H-- | M] (Microsoft Corp) -- C:\Documents and Settings\All Users\Application Data\ZiUScmDdQAYPtc.exe
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
:Services
:Reg
:Files
:Commands
[purity]
Open Notepad and paste it.
Save the document as Fix.txt on to a USB flash drive
On the infected computer the following...
Run OTLPE
- Insert USB stick and find the file Fix.txt. Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.
- (The content of Fix.txt should appear in the box)
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- Post the log produced (you'll need to transfer it with USB stick)
- Remove the CD and shut down computer manually.
- Attempt to reboot normally into Windows.