Do this on the computer you are posting from:
Copy the text in the codebox below:
Code:
:OTL
O1 - Hosts: 94.63.240.131 www.google.com
O1 - Hosts: 94.63.240.132 www.bing.com
O4 - HKLM..\Run: [dplaysvr] File not found
O4 - HKLM..\Run: [UserFaultCheck] File not found
O4 - HKLM..\Run: [yBlqxAdBNPjQ.exe] C:\Documents and Settings\All Users\Application Data\yBlqxAdBNPjQ.exe ()
O4 - HKU\.DEFAULT..\Run: [dplaysvr] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKU\egriffin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explor er: NoDesktop = 1
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O37 - HKLM\...exe [@ = cd] -- "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clq.exe" -a "%1" %* (Microsoft Corporation)
O37 - HKU\.DEFAULT\...exe [@ = cd] -- "C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clq.exe" -a "%1" %* (Microsoft Corporation)
[2012/01/06 21:42:11 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\egriffin\Start Menu\Programs\System Check
[2012/01/05 23:28:01 | 000,274,432 | -H-- | C] (Microsoft Corporation) -- C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clq.exe
[4 C:\Documents and Settings\All Users\Application Data\*.tmp files -> C:\Documents and Settings\All Users\Application Data\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\Documents and Settings\egriffin.NHS-H-11-LAPTOP\My Documents\*.tmp files -> C:\Documents and Settings\egriffin.NHS-H-11-LAPTOP\My Documents\*.tmp -> ]
[2012/01/07 14:31:03 | 000,010,726 | -HS- | M] () -- C:\Documents and Settings\egriffin\Local Settings\Application Data\458b23d65nwbwx3n7jmr6o
[2012/01/07 14:31:03 | 000,010,726 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\458b23d65nwbwx3n7jmr6o
[2012/01/06 23:03:05 | 000,000,853 | -H-- | M] () -- C:\Documents and Settings\egriffin\Application Data\Microsoft\Internet Explorer\Quick Launch\System Check.lnk
[2012/01/06 22:08:06 | 000,000,432 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\ei0wBpjTLbRPWj
[2012/01/06 22:07:58 | 000,000,296 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~ei0wBpjTLbRPWj
[2012/01/06 21:52:06 | 000,010,812 | -HS- | M] () -- C:\Documents and Settings\egriffin\Local Settings\Application Data\814788041
[2012/01/06 21:52:06 | 000,010,812 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\814788041
[2012/01/06 21:51:55 | 000,010,816 | -HS- | M] () -- C:\Documents and Settings\egriffin\Local Settings\Application Data\2239678798
[2012/01/06 21:51:55 | 000,010,816 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\2239678798
[2012/01/06 21:44:51 | 000,010,832 | -HS- | M] () -- C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\458b23d65nwbwx3n7jmr6o
[2012/01/06 21:42:49 | 000,000,208 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\~ei0wBpjTLbRPWjr
[2012/01/06 21:42:11 | 000,000,835 | -H-- | M] () -- C:\Documents and Settings\egriffin\Desktop\System Check.lnk
[2012/01/06 21:41:57 | 000,358,178 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\ei0wBpjTLbRPWj.exe
[2012/01/05 23:28:02 | 000,066,560 | -H-- | M] () -- C:\Documents and Settings\All Users\Documents\19792079
[2012/01/05 23:28:01 | 000,441,122 | -H-- | M] () -- C:\Documents and Settings\All Users\Application Data\yBlqxAdBNPjQ.exe
[2012/01/05 23:28:01 | 000,274,432 | -H-- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data\clq.exe
:Services
:Reg
:Files
:Commands
[purity]
Open Notepad and paste it.
Save the document as Fix.txt on to a USB flash drive
On the infected computer the following...
Run OTLPE
- Insert USB stick and find the file Fix.txt. Drag the file Fix.txt and drop it under the Custom Scans/Fixes box at the bottom.
- (The content of Fix.txt should appear in the box)
- Then click the Run Fix button at the top
- Let the program run unhindered, reboot the PC when it is done
- Post the log produced (you'll need to transfer it with USB stick)
- Attempt to reboot normally into Windows.