I am not familiar with how to send logs so if you need anything like that, I'm sorry you'll need to explain how to do it plus I can't even get onto my email or anything.
Thank You for your time!
Dawn
Thank You for your time!
Dawn
Fiery said:Hi and welcome to MalwareTips!
I'm Fiery and I would gladly assist you in removing the malware on your computer.
Before we start:
- Note that the removal process is not immediate. Depending on the severity of your infection, it could take a long time.
- Malware removal can be dangerous. I cannot guarantee the safety of your system as malware can be unpredictable. It is possible that we might encounter situations where the only recourse is to re-format and re-install your operating system. Therefore, I would advise you to backup all your important files before we start.
- Please be patient and stay with me until I give you the green lights and inform you that your PC is clean.
- Some tools may be flagged by your antivirus as harmful. Rest assure that ALL the tools we use are safe, the detections are false positives.
- The absence of symptoms does not mean your PC is fully disinfected.
- If you are unclear about the instructions, please stop and ask. Following the steps in the order that I post them in is vital.
- Lastly, if you have requested help on other sites, that will delay and hinder the removal process. Please only stick to one site.
<hr>
Do you have another PC where you can download tools and transfer the files to the infected PC using an USB? Also, try this to see if you are able to access the internet.
Start your computer in Safe Mode with Networking.
- Remove all floppy disks, CDs, and DVDs from your computer, and then <>restart your computer</>.</li>
[*]<>Tap the "F8 key" continuously</> until you get the Advanced Boot Options screen.</li>
[*]On the Advanced Boot Options screen, use the arrow keys to <>highlight Safe Mode with Networking</> , and then <>press ENTER</>.
<br>
<img title="Safe Mode with Networking screen" src="http://malwaretips.com/images/removalguide/safemode.jpg" alt="[Image: Safemode.jpg]" width="539" height="292" border="0" /></li>
</ol>
Download OTL by Old Timer from here and save it to your Desktop.
- Double click on OTL.exe to run it.
- Click the Scan All Users checkbox.
- Check the boxes beside LOP Check and Purity Check
- Click on Run Scan at the top left hand corner.
- When done, two Notepad files will open.
- OTL.txt <-- Will be opened
- Extra.txt <-- Will be minimized
- Please attach the contents of these 2 Notepad files in your next reply.
If you don't know how to attach the files, please follow the instructions here: http://malwaretips.com/Thread-How-to-use-the-attachment-system?pid=16072#pid16072
tl
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290257
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290257
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290259
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290259
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
IE - HKU\.DEFAULT\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
IE - HKU\S-1-5-18\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
IE - HKU\S-1-5-21-3615664846-1967934640-507609581-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290257
IE - HKU\S-1-5-21-3615664846-1967934640-507609581-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.22find.com/newtab?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290257
IE - HKU\S-1-5-21-3615664846-1967934640-507609581-1005\..\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}: "URL" = http://search.22find.com/web/?utm_source=b&utm_medium=mlv&from=mlv&uid=ST98823A_3PK0GLL2XXXX3PK0GLL2&ts=1360290259
IE - HKU\S-1-5-21-3615664846-1967934640-507609581-1005\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD21}: "URL" = http://dts.search-results.com/sr?src=ieb&appid=221&systemid=1&sr=0&q={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "22find"
FF - prefs.js..browser.search.order.1: "22find"
FF - prefs.js..browser.search.selectedEngine: "22find"
[2012/06/29 16:01:02 | 000,000,686 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\searchresultstb.xml
[2012/05/17 20:45:53 | 000,002,515 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\Search_Results.xml
O4 - HKLM..\Run: [qeshel] C:\Documents and Settings\Dawn\Application Data\qeshel.dll ()
O4 - HKLM..\Run: [CheckRun22find_uninstaller] C:\Documents and Settings\Dawn\Application Data\CheckRun22find.exe ()
O4 - HKLM..\Run: [dpneip] C:\Documents and Settings\Dawn\Application Data\dpneip.dll (Graphics Co., Ltd.)
O4 - HKLM..\Run: [wuvtcp] C:\Documents and Settings\Dawn\Application Data\wuvtcp.dll ()
O4 - HKU\S-1-5-21-3615664846-1967934640-507609581-1005..\Run: [cvpkmbqm] C:\Documents and Settings\Dawn\Local Settings\Application Data\xmnsvqif.exe (Sqikkmj)
O4 - HKU\S-1-5-21-3615664846-1967934640-507609581-1005..\RunOnce: [3C946E6B620E104D00003C9431DC1532] C:\Documents and Settings\All Users\Application Data\3C946E6B620E104D00003C9431DC1532\3C946E6B620E104D00003C9431DC1532.exe ()
[2013/03/19 00:16:01 | 000,006,537 | ---- | M] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\1f1d6ba3-23b2-4e15-82a7-a14baac0b137.crx
[2013/03/17 22:06:40 | 000,046,499 | ---- | M] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\viwxipdd
[2013/03/17 21:59:39 | 000,407,040 | ---- | M] () -- C:\Documents and Settings\Dawn\Local Settings\Application Data\bxnxubqv.exe
[2013/03/17 21:58:45 | 000,635,392 | ---- | M] () -- C:\Documents and Settings\Dawn\Application Data\qeshel.dll
[2013/03/17 21:57:30 | 000,171,520 | ---- | M] () -- C:\Documents and Settings\Dawn\Application Data\wuvtcp.dll
[2013/03/17 02:35:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
:Files
ipconfig /flushdns /c
:Commands
[EMPTYTEMP]
[RESETHOSTS]
:OTL
SRV - [2012/11/21 13:53:08 | 000,042,504 | ---- | M] (COMPANYVERS_NAME) [Auto | Stopped] -- C:\Program Files\CouponXplorer_5z\bar\1.bin\5zbarsvc.exe -- (CouponXplorer_5zService)
FF - HKLM\Software\MozillaPlugins\@CouponXplorer_5z.com/Plugin: C:\Program Files\CouponXplorer_5z\bar\1.bin\NP5zStub.dll (MindSpark)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\5zffxtbr@CouponXplorer_5z.com: C:\Program Files\CouponXplorer_5z\bar\1.bin [2012/11/21 13:53:13 | 000,000,000 | ---D | M]
O4 - HKLM..\Run: [CouponXplorer Search Scope Monitor] C:\Program Files\CouponXplorer_5z\bar\1.bin\5zSrchMn.exe (MindSpark)
[2012/10/13 15:01:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\A & T\Application Data\searchresultstb
[2012/04/16 12:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Babylon
[2012/04/16 12:41:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dawn\Application Data\Babylon
:Files
C:\Program Files\CouponXplorer_5z