Hello and Welcome to TSF.
Please
Subscribe to this Thread to get immediate notification of replies as soon as they are posted. To do this click
Thread Tools, then click
Subscribe to this Thread. Make sure it is set to
Instant notification by email, then click
Add Subscription.
Please note that the forum is very busy and if I don't hear from you within three days this thread will be closed.
------------------------------------------------------
One or more of the identified infections is a backdoor trojan.
This type of infection allows hackers to remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge.
If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known
clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.
Please read this:
How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud?
------------------------------------------------------
Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.
Please stay with me until given the 'all clear' even if symptoms seemingly abate.
Kindly follow my instructions and
please do no fixing on your own or running of scanners unless requested by a helper.
------------------------------------------------------
While Spybot's TeaTimer is an excellent tool for the prevention of spyware, it can sometimes prevent tools from fixing certain things.
Please disable TeaTimer for now until you are clean. TeaTimer can be re-activated once your logs are clean.
- Open Spybot Search & Destroy.
- In the Mode menu click "Advanced mode" if not already selected.
- Choose "Yes" at the Warning prompt.
- Expand the "Tools" menu.
- Click "Resident".
- Uncheck the "Resident "TeaTimer" (Protection of overall system settings) active." box.
- If TeaTimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
- In the File menu click "Exit" to exit Spybot Search & Destroy.
------------------------------------------------------
Download
ResetTeaTimer- and Save it to your Desktop.
- Double-click ResetTeaTimer.zip
- Double-click ResetTeaTimer.bat and click Run to remove all entries set by TeaTimer.
- A DOS window will open and close again, this is normal.
------------------------------------------------------
If for some reason
during these fixes you receive prompts from Spybot about whether to Allow or Deny any changes, please
Allow them all.
------------------------------------------------------
Please visit this webpage for download links, and instructions for running ComboFix:
http://www.bleepingcomputer.com/comb...o-use-combofix
* Ensure you have disabled all antivirus and antimalware programs so they do not interfere with the running of ComboFix.
Get help
here
Please post the
C:\ComboFix.txt in your next reply for further review.
------------------------------------------------------