Do a HijackThis scan & place a check next to these items and select "Fix checked":
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php...MjI6Ojg5&lid=2
O4 - HKCU\..\Run: [Power2GoExpress] NA
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {BB383206-6DA1-4E80-B62A-3DF950FCC697} (Create & Print ActiveX Plug-in) - http://ak.imgag.com/imgag/cp/install/AxCtp2.cab
---------------
Open
notepad and copy/paste the text in the quotebox below into it:
Code:
http://www.techsupportforum.com/security-center/hijackthis-log-help/173893-trojan-downloader-help.html
Suspect::
C:\WINDOWS\system32\agremove.exe
File::
C:\WINDOWS\uccspecb.sys
Save this as "
CFScript"
Refering to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.
Additonally, ComboFix will generate a zipped file on your Desktop, called Submit [Date Time].zip
Please submit this file before proceeding to the next step.
---------------
Click here perform an online scan >>
Online Scanner
---------------
In your next post, please include fresh logs from:
- Fresh Hijackthis log taken just before replying
- Online scan
- ComboFix's log
Please provide details of any problems you encountered whilst performing the above steps &
update us on how the computer behaves now
__________________
Question - what have you done for the community today?