Hi babbs and welcome to TSF.
You may wish to
Subscribe to this thread (Thread Tools) so that you are notified when you receive a reply.
Please read these instructions carefully and then print out or copy this page to Notepad in order to assist you when carrying out the fix.
If there is anything you don't understand, please ask BEFORE proceeding with the fixes.
You have a few things so let’s try and get rid of the pop ups first.
Please Download
Look2Me-Destroyer and save the file to your desktop.
* Print out these instructions and close
ALL windows before continuing.
* Double-click
Look2Me-Destroyer.exe to run it.
* Put a check next to
"Run this program as a task".
* You will receive a message saying
"Look2Me-Destroyer will close and re-open in approximately 10 seconds". Click
OK.
* When Look2Me-Destroyer re-opens, click the
"Scan for L2M button", your desktop icons will disappear, this is normal.
* Once it's done scanning, click the
"Remove L2M button".
* You will receive a
"Done Scanning message", click
OK.
* When completed, you will receive this message:
"Done removing infected files! Look2Me-Destroyer will now shutdown your computer", click
OK.
* Your computer will then shutdown.
* Turn your computer back on.
* Please post the contents of
C:\Look2Me-Destroyer.txt at the end of this fix.
If you receive a message from your firewall about this program accessing the internet please allow it.
If you receive a runtime error '339' please download
MSWINSCK.OCX and place it in your
C:\Windows\System32 Directory.
Download and unzip BFUzip from
http://www.merijn.org/files/bfu.zip
Run the program and click the Web button as shown here:
Use this URL to copy into the address bar of the Download script window:
http://metallica.geekstogo.com/alcanshorty.bfu
- Execute the script by clicking the Execute button.
- When it finishes running, click the Save button for a copy of the log
- Post the log created by the script when you have completed the fix
If you have any questions about the use of BFU please read here:
http://metallica.geekstogo.com/BFUinstructions.html
Rescan with HijackThis and post a fresh log.