You're welcome, mogget.
Please copy this page to
Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
Also be sure to carry out the instructions in the sequence listed below.
***************************************************
Before we begin, I see you have 2 Anti-Virus programs installed and running (Avast and BitDefender). It's never a good idea to have more than 1 installed as they will conflict with one another, cause system slowdowns and may cause other issues with your OS.
Please choose and run only 1. Uninstall the other via Start>Control Panel>Add or Remove programs. Reboot.
--------------------------------------------------------------------
I see a few orphaned entries from previous infections. Open HijackThis and click on 'Do a System Scan Only'. 'Check' the following entries:
R3 - URLSearchHook: (no name) - _{855F3B16-6D32-4fe6-8A56-BBB695989046} - (no file)
R3 - URLSearchHook: (no name) - _{00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O4 - HKLM\..\Run: [Wwgfrvd] C:\Program Files\Rtbql\Bfrkog.exe
O4 - HKCU\..\Run: [180ClientStubInstall] "C:\DOCUME~1\Graham\LOCALS~1\Temp\sais.exe"
Click
'Fix Checked' and close HijackThis.
--------------------------------------------------------------------
Go to Start->Run and type in
regedit and hit OK.
Open
notepad and copy/paste the entire text
in the quotebox below: (don't forget to copy and paste REGEDIT4)
Quote:
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\180ClientStubInstall]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCAgentExe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MCUpdateExe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKAGENTEXE]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VirusScan Online]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VSOCheckTask]
|
Save the file as
"delete.reg".
Make sure to save it with the quotes. Choose to "Save type as - All Files"
It should look like this:
Double click on the
delete.reg file and choose
Yes to merge/add it to the registry. You may delete the file afterwards.
--------------------------------------------------------------------
Reboot your system.
--------------------------------------------------------------------
Let's see if you can get this online scanner to work for you:
Using Internet Explorer, visit
http://www.kaspersky.com/service?chapter=161739400
Answer Yes, when prompted to install an ActiveX component.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK & have it scan My Computer
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.

- Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
---------------------------------------------------------------
Run a new scan with HijackThis and save the log.
---------------------------------------------------------------
Please include the following in your next reply:
Kaspersky results
New HijackThis log
Update on system behavior
__________________
Member of ASAP since 2005
Member of UNITE since 2006
"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."