Upload a File to Virustotal
Please visit Virustotal found
HERE
- Click the Browse... button
- Navigate to the file C:\Windows\System32\NeroCheck.exe
- Click the Open button
- Click the Send button
- Copy and paste the results back here please.
--------------------------------------------------------------------------------------
Launch Spybot -> click on the Recovery Icon -> Highlight everything and select the red X that says purge.
------------------------------------------------------------------------------------------------
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [Love default global mess] C:\Documents and Settings\All Users\Application Data\great coal love default\Platform bows.exe
O4 - HKCU\..\Run: [CakeTest] C:\Document~1\Owner\APPLIC~1\GRIMEQ~1\Store Vc.exe
Now
close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these
folders (if present):
C:\Documents and Settings\All Users\Application Data\great coal love default
C:\Documents and Settings\Owner\Application Data\GRIMEQ~1 <- check this one, it will have a longer name
-----------------------------------------------
FileASSASSIN
- Launch Malwarebytes' Anti-Malware
- Select the More Tools Tab
- Under FileASSASSIN select Run Tool
- Navigate to C:\Program Files\DAEMON Tools Lite\SRSAI.exe
- Press Open
------------------------------------------------
Uninstall Combofix
* Click
START then
RUN
* Now type
Combofix /u in the runbox
* Make sure there's a space between Combofix and /u
* Then hit
Enter.
* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
-----------------------------------------------------------------------
Cleanup using OTMoveit2 by OldTimer
Now we can clear out the rest of the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause damage if launched accidentally.
Download OTMoveIt2 by OldTimer
OTMoveIt2.exe and place it on your desktop.
1. Double click
OTMoveIt2.exe to launch it.
If using Vista Right-Click OTMoveIt and choose Run As Administrator
2. Click on the
CleanUp! button.
3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
4. Click
YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
* When finished exit out of OTMoveIt2
-----------------------------------------------------
clear system restore points
This is a good time to clear your existing system restore points and establish a new clean restore point:
- Go to Start > All Programs > Accessories > System Tools > System Restore
- Select Create a restore point, and Ok it.
- Next, go to Start > Run and type in cleanmgr
- Select the More options tab
- Choose the option to clean up system restore and OK it.
This will remove all restore points except the new one you just created.
---------------------------------------------------------------------
After all of this run another Kaspersky and attach the log along with the result from VirusTotal