Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Security Shield
Message
<blockquote data-quote="Jack" data-source="post: 58753" data-attributes="member: 1"><p>1.Ok,ets try to run again this OTL fix.</p><p></p><p>If you have the paid version of Malwarebytes 1.6 or later installed, please disable it for the duration of this run.Also you should temporarily disable your antivirus.</p><p><<strong>>To disable MBAM</<strong>></strong></strong></p><p><strong><strong></strong></strong></p><p><strong><strong>Open the scanner and select the <<strong>>Protection</<strong>> tab.</strong></strong></strong></strong></p><p><strong><strong><strong><strong>Remove the tick from <<strong>>Start protection module with Windows</<strong>>.</strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong>Reboot and then run OTL.</strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><img src="http://i1224.photobucket.com/albums/ee362/Essexboy3/mbamstop.jpg" alt="Posted Image" /></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><ol></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong> <li>Please reopen <img src="http://malwaretips.com/blogs/wp-content/uploads/2012/06/otlicon.png" alt="Posted Image" /> on your desktop.</li></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong> <li><<strong>>Copy</<strong>> and <<strong>>Paste</<strong>> the following code into the <img src="http://malwaretips.com/blogs/wp-content/uploads/2012/06/customscanfix.png" alt="Posted Image" /> textbox.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[code]:OTL</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>MOD - [2012/06/26 01:22:53 | 000,442,368 | ---- | M] () -- C:\Users\Paulgun\AppData\Local\zgmguisgzf.exe</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O4 - HKLM..\Run: [] File not found</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O4 - HKCU..\Run: [DW6] File not found</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O33 - MountPoints2\{e330de2a-e90b-11de-9c8c-00197ee642d9}\Shell\AutoRun\command - "" = F:\WDSetup.exe</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O33 - MountPoints2\{f59e8bd1-3313-11dc-b3c6-00197ee642d9}\Shell - "" = AutoRun</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O33 - MountPoints2\{f59e8bd1-3313-11dc-b3c6-00197ee642d9}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\WDSetup.exe</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[1 C:\Users\Paulgun\Desktop\*.tmp files -> C:\Users\Paulgun\Desktop\*.tmp -> ]</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[2012/06/26 01:32:30 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA%</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[2012/06/26 01:23:30 | 000,018,944 | ---- | C] () -- C:\Windows\Installer\{50904225-4dab-82b5-0359-4c2b153d91d0}\U\800000cb.@</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[2012/06/26 01:23:30 | 000,012,288 | ---- | C] () -- C:\Windows\Installer\{50904225-4dab-82b5-0359-4c2b153d91d0}\U\80000000.@</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[2012/06/26 01:23:30 | 000,001,648 | ---- | C] () -- C:\Windows\Installer\{50904225-4dab-82b5-0359-4c2b153d91d0}\U\00000001.@</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>:files</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>C:\Users\Paulgun\AppData\Local\zgmguisgzf.exe</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>ipconfig /flushdns /c</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>:Commands </strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[createrestorepoint]</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[resethosts] </strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[emptytemp] </strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>[/code]</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li><<strong>>Push </<strong>><img src="http://malwaretips.com/blogs/wp-content/uploads/2012/06/runfix.png" alt="Posted Image" /></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li><<strong>>OTL may ask to reboot the machine. Please do so if asked.</<strong>></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li><<strong>>Click </<strong>>the <<strong>>OK</<strong>> button.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>A report will open. <<strong>>Copy</<strong>> and <<strong>>Paste</<strong>> that report in your next reply.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>If the machine reboots, the log will be located at C:\_OTL\MovedFiles\<<strong>>mmddyyyy_hhmmss.log</<strong>>, where mmddyyyy_hhmmss is the date and the time of the tool run.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></ol></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><hr /></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>2.Next,Let's repair some stuff that can be damaged by malware.</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Download <<strong>><a title="External link" href="http://www.tweaking.com/content/page/windows_repair_all_in_one.html" rel="external">Windows Repair by Tweaking.com</a></<strong>> to your desktop. Use the direct download link for the Portable version of Windows Repair by Tweaking.com</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><ol></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Double-click <<strong>>tweaking.com_windows_repair_aio.zip</<strong>> and extract the <<strong>>Tweaking.com - Windows Repair</<strong>> folder to your desktop.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Now open this folder and double-click <<strong>>Repair_Windows.exe</<strong>>.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Click the <<strong>>Start Repairs</<strong>> tab on the far right.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Click the <<strong>>Start</<strong>> button (bottom right)</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Note: When asked if you would like to create a restore point. It is recommended just in-case something does not go as planned.</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Click <<strong>>Unselect All</<strong>></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Put a checkmark in the following items:</strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><ul></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Repair Windows Firewall</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>Repair Hosts File</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><li>Repair Temp Files</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Remove Policies Set By Infections</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Set Windows Services To Default Startup</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></ul></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong>Note: Leave everything else unchecked</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Put a checkmark in <<strong>>Restart System When Finished</<strong>></li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong> <li>Now click the <<strong>>Start</<strong>> button (bottom right)</li></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p><p><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong><strong></ol></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></strong></p></blockquote><p></p>
[QUOTE="Jack, post: 58753, member: 1"] 1.Ok,ets try to run again this OTL fix. If you have the paid version of Malwarebytes 1.6 or later installed, please disable it for the duration of this run.Also you should temporarily disable your antivirus. <[b]>To disable MBAM</[b]> Open the scanner and select the <[b]>Protection</[b]> tab. Remove the tick from <[b]>Start protection module with Windows</[b]>. Reboot and then run OTL. <img src="http://i1224.photobucket.com/albums/ee362/Essexboy3/mbamstop.jpg" alt="Posted Image" /> <ol> <li>Please reopen <img src="http://malwaretips.com/blogs/wp-content/uploads/2012/06/otlicon.png" alt="Posted Image" /> on your desktop.</li> <li><[b]>Copy</[b]> and <[b]>Paste</[b]> the following code into the <img src="http://malwaretips.com/blogs/wp-content/uploads/2012/06/customscanfix.png" alt="Posted Image" /> textbox. [code]:OTL MOD - [2012/06/26 01:22:53 | 000,442,368 | ---- | M] () -- C:\Users\Paulgun\AppData\Local\zgmguisgzf.exe O4 - HKLM..\Run: [] File not found O4 - HKCU..\Run: [DW6] File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0 O33 - MountPoints2\{e330de2a-e90b-11de-9c8c-00197ee642d9}\Shell\AutoRun\command - "" = F:\WDSetup.exe O33 - MountPoints2\{f59e8bd1-3313-11dc-b3c6-00197ee642d9}\Shell - "" = AutoRun O33 - MountPoints2\{f59e8bd1-3313-11dc-b3c6-00197ee642d9}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\WDSetup.exe [1 C:\Users\Paulgun\Desktop\*.tmp files -> C:\Users\Paulgun\Desktop\*.tmp -> ] [2012/06/26 01:32:30 | 000,000,000 | -HSD | C] -- C:\Windows\System32\%APPDATA% [2012/06/26 01:23:30 | 000,018,944 | ---- | C] () -- C:\Windows\Installer\{50904225-4dab-82b5-0359-4c2b153d91d0}\U\800000cb.@ [2012/06/26 01:23:30 | 000,012,288 | ---- | C] () -- C:\Windows\Installer\{50904225-4dab-82b5-0359-4c2b153d91d0}\U\80000000.@ [2012/06/26 01:23:30 | 000,001,648 | ---- | C] () -- C:\Windows\Installer\{50904225-4dab-82b5-0359-4c2b153d91d0}\U\00000001.@ :files C:\Users\Paulgun\AppData\Local\zgmguisgzf.exe ipconfig /flushdns /c :Commands [createrestorepoint] [resethosts] [emptytemp] [/code]</li> <li><[b]>Push </[b]><img src="http://malwaretips.com/blogs/wp-content/uploads/2012/06/runfix.png" alt="Posted Image" /></li> <li><[b]>OTL may ask to reboot the machine. Please do so if asked.</[b]></li> <li><[b]>Click </[b]>the <[b]>OK</[b]> button.</li> <li>A report will open. <[b]>Copy</[b]> and <[b]>Paste</[b]> that report in your next reply.</li> <li>If the machine reboots, the log will be located at C:\_OTL\MovedFiles\<[b]>mmddyyyy_hhmmss.log</[b]>, where mmddyyyy_hhmmss is the date and the time of the tool run.</li> </ol> <hr /> 2.Next,Let's repair some stuff that can be damaged by malware. Download <[b]><a title="External link" href="http://www.tweaking.com/content/page/windows_repair_all_in_one.html" rel="external">Windows Repair by Tweaking.com</a></[b]> to your desktop. Use the direct download link for the Portable version of Windows Repair by Tweaking.com <ol> <li>Double-click <[b]>tweaking.com_windows_repair_aio.zip</[b]> and extract the <[b]>Tweaking.com - Windows Repair</[b]> folder to your desktop.</li> <li>Now open this folder and double-click <[b]>Repair_Windows.exe</[b]>.</li> <li>Click the <[b]>Start Repairs</[b]> tab on the far right.</li> <li>Click the <[b]>Start</[b]> button (bottom right) Note: When asked if you would like to create a restore point. It is recommended just in-case something does not go as planned.</li> <li>Click <[b]>Unselect All</[b]></li> <li>Put a checkmark in the following items: <ul> <li>Repair Windows Firewall</li> <li>Repair Hosts File</li> <li>Repair Temp Files</li> <li>Remove Policies Set By Infections</li> <li>Set Windows Services To Default Startup</li> </ul> Note: Leave everything else unchecked</li> <li>Put a checkmark in <[b]>Restart System When Finished</[b]></li> <li>Now click the <[b]>Start</[b]> button (bottom right)</li> </ol>[/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b][/b] [/QUOTE]
Insert quotes…
Verification
Post reply
Top