Please download and run the below tool named
Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
There are 4 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click Rkill and choose
Run as Administrator
You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
*
Rkill.com
*
Rkill.scr
*
Rkill.pif
*
Rkill.exe
* Double-click on the Rkill desktop icon to run the tool.
*
If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A
black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in
Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.
Once you've gotten one of them to run then try to
immediately run the following.
Now download and run
exeHelper.
* Please download
exeHelper from Raktor to your desktop.
* Double-click on
exeHelper.com to run the fix.
* A black window should pop up, press any key to close once the fix is completed.
* A log file named log.txt will be created in the directory where you ran exeHelper.com
* Attach the
log.txt file to your next message.[/LIST]
Note: If the window shows a message that says
"Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
========================================================================
Print these instructions out.
NOTE. If any of the programs listed below refuse to run, try renaming executive file to something else; for instance, rename hijackthis.exe to scanner.exe
***VERY IMPORTANT! Make sure, you update Malwarebytes before running the scans.***
STEP 1. Download
Malwarebytes' Anti-Malware:
http://www.malwarebytes.org/mbam.php to your desktop.
(Malwarebytes is free to use as a manual scanner. Payment is only required if you wish to have it run and update automatically which is not necessary for our purposes)
* Double-click
mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to
Update Malwarebytes' Anti-Malware and
Launch Malwarebytes' Anti-Malware, then click
Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select
Perform Quick Scan, then click
Scan.
* When the scan is complete, click OK, then
Show Results to view the results.
* Be sure that everything is checked, and click
Remove Selected.
* When completed, a log will open in Notepad.
*
Post the log back here.
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\
log-date.txt
Or at C:\Program Files\Malwarebytes' Anti-Malware\Logs\
log-date.txt
RESTART COMPUTER!
STEP 2. Download
GMER:
http://www.gmer.net/files.php, by clicking on
Download EXE button.
Alternative downloads:
-
http://majorgeeks.com/GMER_d5198.html
-
http://www.softpedia.com/get/Interne...ers/GMER.shtml
Double click on downloaded
.exe file, select
Rootkit tab and click the
Scan button.
When scan is completed, click
Save button, and save the results as
gmer.log
Warning ! Please, do not select the "Show all" checkbox during the scan.
Post the log to your next reply.
RESTART COMPUTER
STEP 3. Download
HijackThis:
http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download
by clicking on
Installer under
Version 2.0.2
[DO NOT download version 2.0.3 (beta)]
Install, and run it.
Post HijackThis log.
NOTE. If you're using Vista, or 7, right click on
HijackThis, and click
Run as Administrator
Do NOT attempt to "fix" anything!
DO NOT make any other changes to your computer (like installing programs, using other cleaning tools, etc.), until it's officially declared clean!!!