I'm still battling this virus. Since running MGtools the second time neither problem's recurred.

Please try running the C:\MGtools\GetLogs.bat file again and attach the new MGLogs.zip. It seems that this arose from the run of Combofix. Paste the content of the log into your answer. CONTRIBUTE TO OUR LEGAL DEFENSE All unused funds will be donated to the Electronic Frontier Foundation (EFF).

Kind regards, Attached Files: 01282012_092940.log File size: 15.8 KB Views: 0 hijackthis_2.txt File size: 11.3 KB Views: 0 cymraeg21, Jan 28, 2012 #16 Cookiegal Administrator Malware Specialist Coordinator Joined: Aug When done, DDS will open two (2) logs: DDS.txt Attach.txtSave both reports to your desktop. I then intalled malwarebytes from my SD card on to my desktop pc.I ran it in both normal mode and safe mode. I think the malware is preventing the logs from popping up.

Under TCP/IP Primary Install section find the following: Characteristics = 0x80 Edit 0x80 and replace it with 0xA0 (replace 8 with A) Under File menu click Save and close the notepad. Back to top #42 djs djs Advanced Member Members 76 posts Posted 04 January 2012 - 01:41 PM Here is the ComboFix log that was generated from dropping CFScript on the Tick the checkbox of the malicious entry, then click Fix Checked.   Check and fix the hostfile Go to the "C:\Windows\System32\Drivers\Etc" directory, then look for the hosts file. Still had those popups and was still being re-directed to other sites, so ran ReadMe (know you're not supposed to run it twice, but I could only do 2 of them

Download and run HijackThis To download and run HijackThis, follow the steps below:   Click the Download button below to download HijackThis.   Download HiJackThis   Right-click HijackThis.exe icon, then click Run as Your PC should reboot, if not, reboot it yourself. I'm a bit concerned as to whether I plugged the correct end of the ethernet cable in.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7}\ not found. Contact Support. Don't try to fix it yourself. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.

HJT log also attached. Then attach the below logs: * C:\MGlogs.zip Make sure you tell me how things are working now! I don't recognise Ad-watch. Brilliant, cheers Brouwer, Jan 24, 2012 #20 chaslang MajorGeeks Admin - Master Malware Expert Staff Member You're welcome.

Now download The Avenger by Swandog46 to your Desktop. http://softsystechnologies.com/hijackthis-log/hijackthis-log-any-help-would-be-a-help.html Yes, my password is: Forgot your password? Join our site today to ask your question. The GMER LogUse multiple posts if you can't fit everything into one post.

The removal tool window suddenly popped up. To fix this you must change a registry settings. Please post this log in your next reply. Check This Out GMER will produce a log.

Go to Start ==> Control Panel. Double-click this file: C:\Qoobox\Quarantine\Registry_backups\tcpip.reg.dat and let Windows merge it into the registry Restart the computer and then check the internet connection. Otherwise they might stop OTL.How?

According to McAfee support, Windows Firewall works in tandem with McAfee's firewall.

But maybe I should've taken out the side plugged into...I don't know what it is - a small black box very similar to the router, but with no 'wired' points and Attached Files: TDSSKiller. File size: 50.5 KB Views: 2 MBRCheck_01.23.12_01.25.36.txt File size: 8.3 KB Views: 2 ComboFix.txt File size: 12.8 KB Views: 2 MGlogs.zip File size: 172.7 KB Views: 2 Brouwer, scanning hidden autostart entries ... . Brouwer Private E-2 Windows XP Home 2002 32bit. 1Gb Ram.

HijackThis is a free tool that quickly scans your computer to find settings that may have been changed by spyware, malware or any other unwanted programs. Also don't double click on it, use right click and select Run As Administrator ) Now attach the below log: C:\ComboFix.txt C:\MGlogs.zip chaslang, Jan 22, 2012 #15 Brouwer Private E-2 The two DDS Logs (DDS and Attach.txt)2. this contact form There are only a few things left to remove.

It could be just a leftover registry entry. Remember the location of the extracted file.Turn off all programs.Run the program TDSSKiller.exe which is the file you extracted.Click on Start Scan.If any threats are found select Cure and click Continue. Please provide your comments to help us improve this solution. GMER will produce a log.

Read what Blade81 writes in the post http://www.lavasofts...ndpost&p=124337 from the header "Make your Internet Explorer more secure" and downwards. Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... Attached Files: Lavasoft.zip File size: 406 bytes Views: 1 Cookiegal, Feb 1, 2012 #30 This thread has been Locked and is not open to further replies. Required The image(s) in the solution article did not display properly.