Okay, go ahead and run this:
Please run this Custom CFScript:
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad> click on Format> Uncheck 'Word Wrap> and copy/paste the text in the code below into it:
Code:
File::
C:\ProgramData\gBoK08h45.dat
C:\Users\Sara\AppData\Local\786687y7c168q428n153s8xbl4s1
C:\ProgramData\786687y7c168q428n153s8xbl4s1
C:\Users\Sara\AppData\Local\w7qt08g3tq7oll
C:\ProgramData\w7qt08g3tq7oll
Folder::
C:\avrescue
DDS::
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
SubSystems: Windows = basesrv,1 winsrv:UserServerDllInitialization,3 consrv:ConServerDllInitialization,2 sxssrv,4
Clearjavacache::
CreateRestorePoint::
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste into to your next reply.
==========================================
First, set up a Directory for HijackThis as follows:
Right click Taskbar> Explore> My Computer> Local Drive (C)> File> New> Folder> Name folder HijackThis
Exit Explorer
You now have a folder C:\HijackThis
-----------------------------------------
Download HijackThis and save to your desktop.
- Click on the HJT icon> 'Extract all files'> Extraction Wizard> Click on Browse to right of dialogue box that says 'Select a folder'
- Extract it to the directory on your hard drive you created C:\HijackThis.
- Then navigate to that directory and double-click on the hijackthis.exe file.
- When started click on the Scan button and then the Save Log button to create a log of your information.
- The log file and then the log will open in notepad. Be sure to click on Format> Uncheck Word Wrap when you open Notepad
- Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
- Come back here to this thread and paste (Ctrl+V) the log in your next reply.
NOTE: Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
===========================================
When finished, update the Eset Online Virus scan and run a new scan.
==========================================
Please leave all 3 logs in next reply.