Don`t worry about the AVG Antispyware, it`s fine.
We need to temporarily disable Spybot search & Destroy`s tea time, as it may interfere with any fix we are trying to run.
Disable Spybot's TeaTimer. This is a two step process.
First:
- Right click Spybot in the System Tray (looks like a calendar with a padlock symbol)
- Choose
Exit Spybot S&D Resident
Second:
- Open Spybot S&D
- Click
Mode, check
Advanced Mode
- Go To Left Panel, Click
Tools, then also in left panel, click
Resident
- If your firewall raises a question, say
OK
- Uncheck the box labeled
Resident Tea-Timer and OK any prompts.
- Use
File, Exit to terminate Spybot
- Reboot your machine for the changes to take effect.
Delete all files in AVG Antispyware quarantine.
Run HJT with no other programmes open(except notepad). Click the scan button. Have HJT fix the following, by placing a tick in the little box next to(
if there).
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://download.microsoft.com/download/0/a/9/0a9587bc-2dc5-420e-89e0-f74d8b75b12 8/setup.exe
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {F2D99483-3BC2-4737-955B-E7F761C36FCD} - C:\WINDOWS\system32\vturs.dll (file missing)
Click on the fix checked button.
Close HJT.
Go
HERE, download and install the latest version of Java.
Once it`s installed, go to add remove programmes in your control panel and uninstall all previous versions of Java, except version 6 update 3. Close Control panel.
Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..
Pay particular attention to this :-
Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:
File::
C:\WINDOWS\system32\srutv.bak2
C:\WINDOWS\system32\srutv.bak1
C:\WINDOWS\system32\B86DDD8C09.sys
C:\WINDOWS\RUxMRU5LVUlQRVI\loUglocMpo5klpK.vbs
Folder::
C:\Qoobox
C:\Vundofix backups
C:\WINDOWS\RUxMRU5LVUlQRVI
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F2D99483-3BC2-4737-955B-E7F761C36FCD}]
Save this as
CFScript.txt
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.
Regards Howard
This thread is for the use of nikoanime only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.