Wow lots of bad entries in HJT log, where to begin
Reopen HJT and do a scan only
Place a tick next to every
R entry (there's a few R0 R1 R3 entries)
Place a tick next to every entry that has "file missing" at the end of the entry itself
Place a tick on all these too:
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SYS2] C:\WINDOWS\system32\bad1.exe
O4 - HKLM\..\Run: [SYS3] C:\WINDOWS\system32\bad2.exe
O4 - HKLM\..\Run: [SYS4] C:\WINDOWS\system32\bad3.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SYS1] C:\WINDOWS\system32\system.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [VistaStartMenu] "C:\Program Files\Vista Start Menu\VistaStartMenu.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
Close any Internet browser (really any other program just close)
Then select Fix
Then close HJT blank window
--------------
Then run the AVG
removal tool
Here is the 32Bit version (
most users):
http://www.avg.com/filedir/util/avg_arm_sup_____.dir/avgremover.exe
Here is the 64Bit version:
http://www.avg.com/filedir/util/avg_arv_sup_____.dir/avgremoverx64.exe
--------------
Then download Combofix
Lots of info on its use
h e r e
Direct download
h e r e
Locate the downloaded Combofix. Double click on it to run, answering any prompts along the way
Note: during Combofix scan (lasting up to 10mins) your Desktop and clock may reset (all normal)
ComboFix will also restart your computer (eventually) and then (eventually) create a log
Save this log file to be attached to a new reply
Also do another scan with HJT (scan and log file) and attach this to a new reply as well
Whilst waiting for my reply, you may want to re-open Malwarebytes;
update it again; and then run another full scan (I'm thinking there may still be more uncovered malwares to remove) I would do this