Hi and welcome to MalwareTips!
My name is Fiery and I would gladly assist you in removing the malware on your computer.
Before we start:
- Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
- Malware removal can be dangerous. I cannot guarantee the safety of your system and it is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. I would advise you to backup all your important files before we start.
- Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
- The absence of symptoms does not mean your PC is fully disinfected.
- If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
- Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.
<hr>
Please do the following in safe mode. If you don't know how to access safe mode, follow the instructions
here
Download and run
RKill
Download mirror 1 -
Download mirror 2 -
Download mirror 3
- Save it to your Desktop.
- Double click the RKill desktop icon.
- It will quickly run. If it does not run, try another download link from above.
<img title="RKILL Command prompt" src="http://malwaretips.com/images/removalguide/rkill2.png" alt="[Image: run-rkill-2.png]" width="507" height="256" border="0" />
- When Rkill has completed its task, it will <>generate a log</>. You can then <>proceed with the rest of the guide</>.
<img title="RKILL LOG" src="http://malwaretips.com/images/removalguide/rkill3.png" alt="[Image: XP Defender 2013 rkill3.jpg]" width="414" height="187" border="0" /></li>
</ol><br>
<br><>WARNING: Do not reboot your computer after running RKill as the malware process will start again , preventing you from properly performing the next step.</>
Download OTL by Old Timer from here and save it to your Desktop. If you can't access the internet on your infected PC, download it on a clean PC, transfer it to your infected PC using a USB/flash drive.
- Double click on OTL.exe to run it.
- Click the Scan All Users checkbox.
- Change Standard Registry to All
- Check the boxes beside LOP Check and Purity Check
- Click on Run Scan at the top left hand corner.
- When done, two Notepad files will open.
- OTListIt.txt <-- Will be opened
- Extra.txt <-- Will be minimized
- Please post the contents of these 2 Notepad files in your next reply.
- Download aswmbr.exe from the below link:
aswMBR DOWNLOAD LINK <em>(This link will automatically download aswMBR on your computer)</em>
- Double click the aswMBR.exe to run it.
- Click the [Scan] button to start scan
- On completion of the scan click [Save log], save it to your desktop and post in your next reply.