:OTL
O4 - HKCU..\Run: [DN_PA_VGT] C:\Program Files\Adware Pro\Adware_Pro.exe File not found
O4 - HKCU..\Run: [SearchProtect] C:\Documents and Settings\pvidulic\Application Data\SearchProtect\bin\cltmng.exe (Conduit)
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP346F792
:Files
C:\Program Files\Adware Pro
C:\Documents and Settings\pvidulic\Application Data\SearchProtect
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[RESETHOSTS]
Fiery said:Hi and welcome to MalwareTips!
I'm Fiery and I would gladly assist you in removing the malware on your computer.
PLEASE NOTE: The first 3 posts of ALL new members require approval by mods/admins. Please be patient if you don't see your post immediately after submitting it.
Before we start:
- Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
- Malware removal can be dangerous. I cannot guarantee the safety of your system as malware can be unpredictable. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. Therefore, I would advise you to backup all your important files before we start.
- Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
- Some tools may be flagged by your antivirus as harmful. Rest assure that ALL the tools we use are safe, the detections are false positives.
- The absence of symptoms does not mean your PC is fully disinfected.
- If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
- Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.
<hr>
Open OTL. Under custom scan/fixes, copy and paste the following:
:OTL
O4 - HKCU..\Run: [DN_PA_VGT] C:\Program Files\Adware Pro\Adware_Pro.exe File not found
O4 - HKCU..\Run: [SearchProtect] C:\Documents and Settings\pvidulic\Application Data\SearchProtect\bin\cltmng.exe (Conduit)
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP346F792
:Files
C:\Program Files\Adware Pro
C:\Documents and Settings\pvidulic\Application Data\SearchProtect
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[RESETHOSTS]
Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.
Download TDSSkiller from here
- Double-Click on TDSSKiller.exe to run the application
- When TDSSkiller opens, click change parameters , check the box next to Loaded modules . A reboot will be required.
- After reboot, TDSSKiller will run again. Click Change parameters again and make sure everything is checked.
- click Start scan .
- If a suspicious object is detected, the default action will be Skip, click on Continue. (If it saids TDL4/TDSS file system, select delete)
- If malicious objects are found, ensure Cure (default) is selected, then click Continue and Reboot now to finish the cleaning process.
Post the log after (usually C:\ folder in the form of TDSSKiller.[Version]_[Date]_[Time]_log.txt
Download Malwarebytes Anti-Rootkit from here to your Desktop
- Unzip the contents to a folder on your Desktop.
- Open the folder where the contents were unzipped and run mbar.exe
- Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
- Make sure there is a check next to Create Restore Point and click the Cleanup button to remove any threats. Reboot if prompted to do so.
- After the reboot, perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If there are threats, click Cleanup once more and reboot.
- When done, please post the two logs in the MBAR folder(mbar-log.txt and system-log.txt)
Fiery said:Hi and welcome to MalwareTips!
I'm Fiery and I would gladly assist you in removing the malware on your computer.
PLEASE NOTE: The first 3 posts of ALL new members require approval by mods/admins. Please be patient if you don't see your post immediately after submitting it.
Before we start:
- Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
- Malware removal can be dangerous. I cannot guarantee the safety of your system as malware can be unpredictable. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. Therefore, I would advise you to backup all your important files before we start.
- Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
- Some tools may be flagged by your antivirus as harmful. Rest assure that ALL the tools we use are safe, the detections are false positives.
- The absence of symptoms does not mean your PC is fully disinfected.
- If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
- Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.
<hr>
Open OTL. Under custom scan/fixes, copy and paste the following:
:OTL
O4 - HKCU..\Run: [DN_PA_VGT] C:\Program Files\Adware Pro\Adware_Pro.exe File not found
O4 - HKCU..\Run: [SearchProtect] C:\Documents and Settings\pvidulic\Application Data\SearchProtect\bin\cltmng.exe (Conduit)
@Alternate Data Stream - 146 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP346F792
:Files
C:\Program Files\Adware Pro
C:\Documents and Settings\pvidulic\Application Data\SearchProtect
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[RESETHOSTS]
Then click Run Fix. Let your PC reboot to normal mode. A new log will be created automatically, post the content in the next reply.
Download TDSSkiller from here
- Double-Click on TDSSKiller.exe to run the application
- When TDSSkiller opens, click change parameters , check the box next to Loaded modules . A reboot will be required.
- After reboot, TDSSKiller will run again. Click Change parameters again and make sure everything is checked.
- click Start scan .
- If a suspicious object is detected, the default action will be Skip, click on Continue. (If it saids TDL4/TDSS file system, select delete)
- If malicious objects are found, ensure Cure (default) is selected, then click Continue and Reboot now to finish the cleaning process.
Post the log after (usually C:\ folder in the form of TDSSKiller.[Version]_[Date]_[Time]_log.txt
Download Malwarebytes Anti-Rootkit from here to your Desktop
- Unzip the contents to a folder on your Desktop.
- Open the folder where the contents were unzipped and run mbar.exe
- Follow the instructions in the wizard to update and allow the program to scan your computer for threats.
- Make sure there is a check next to Create Restore Point and click the Cleanup button to remove any threats. Reboot if prompted to do so.
- After the reboot, perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If there are threats, click Cleanup once more and reboot.
- When done, please post the two logs in the MBAR folder(mbar-log.txt and system-log.txt)
Fiery said:Are you able to access normal mode? can you do anything while that TDSSKiller message is up?
Fiery said:Can you navigate to C:\ folder and see if there is a TDSSKiller log?
Also, give Malwarebytes a run
Fiery said:Click Yes.
Then try to find the TDSSKiller log in the C:\ folder and attach it here. While in safe mode, do another OTL scan after using adwCleaner and RogueKiller.
Please download AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool(For Vista or Windows 7, right-click and select Run as Administrator to start)
- Click delete
- Please post the content of that logfile with your next reply.
- You can find the logfile at C:\AdwCleaner[S1].txt
Download & SAVE to your Desktop RogueKiller or from here
- Quit all programs that you may have started.
- Please disconnect any USB or external drives from the computer before you run this scan!
- For Vista or Windows 7, right-click and select Run as Administrator to start
- Wait until Prescan has finished, then click on "Scan" button
- Wait until the Status box shows "Scan Finished"
- Click delete and wait until it saids deleting finished
- Click on "Report" and copy/paste the content of the Notepad into your next reply.
- The log should be found in RKreport[1].txt on your Desktop
Exit/Close RogueKiller+
donnamv said:Fiery said:Click Yes.
Then try to find the TDSSKiller log in the C:\ folder and attach it here. While in safe mode, do another OTL scan after using adwCleaner and RogueKiller.
Please download AdwCleaner by Xplode onto your desktop.
- Close all open programs and internet browsers.
- Double click on AdwCleaner.exe to run the tool(For Vista or Windows 7, right-click and select Run as Administrator to start)
- Click delete
- Please post the content of that logfile with your next reply.
- You can find the logfile at C:\AdwCleaner[S1].txt
Download & SAVE to your Desktop RogueKiller or from here
- Quit all programs that you may have started.
- Please disconnect any USB or external drives from the computer before you run this scan!
- For Vista or Windows 7, right-click and select Run as Administrator to start
- Wait until Prescan has finished, then click on "Scan" button
- Wait until the Status box shows "Scan Finished"
- Click delete and wait until it saids deleting finished
- Click on "Report" and copy/paste the content of the Notepad into your next reply.
- The log should be found in RKreport[1].txt on your Desktop
Exit/Close RogueKiller+
Fiery said:Is there another TDSSKiller log? There should be 2.
And let me know the results of the OTL scan afterwards.
donnamv said:Fiery said:Is there another TDSSKiller log? There should be 2.
And let me know the results of the OTL scan afterwards.
Fiery said:Can you boot your PC normally now? Or does it still say "running TDSSKiller script"?