Hello and welcome to TechSpot.
It looks like you might have a lop infection.
Please Download NoLop to your desktop from one of the links below...
http://www.spywareedge.net/nolop/NoLop.exe
http://www.thespykiller.co.uk/forum/...pmod;dl=item16
First close any other programs you have running as this will require a reboot
Double click NoLop.exe to run it
Now click the button labelled "Search and Destroy"
<<your computer will now be scanned for infected files>>
When scanning is finished you will be prompted to reboot only if infected, Click OK
Now click the "REBOOT" Button.
A Message should popup from NoLop.
If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HJT log
--If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.--
http://www.boletrice.com/downloads/mscomctl.ocx
Now have HJT fix these entries:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [itch type 16 team] C:\Documents and Settings\All Users\Application Data\cake soft itch type\book bags.exe
O4 - HKCU\..\Run: [road draw] C:\DOCUME~1\WAIHUN~1\APPLIC~1\FORDER~1\DVD OPTION START.exe
Now go into C:\Documents and Settings\%your user name%\application data\forder~1 and delete
DVD OPTION START.exe.
Go into C:\Documents and Settings\All Users\Application Data and delete the folder
cake soft itch type.
Now read the
Viruses/spyware/malware, preliminary removal instructions. Follow all the instructions
to the letter, then post fresh HJT, Combofix, and
AVG Antispyware logs as attachments into this thread. Also post here the results of the AVG Antirootkit scan.
Regards
This thread is for the use of castroguevara only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in the Security and the Web forum.