Andro1d

Trusted Helpers
  • Content Count

    737
  • Joined

  • Last visited

Posts posted by Andro1d

  1. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your computer problem today.

    Please download this file - combofix.exe by sUBs

    • Save it to your Desktop
    • Please, never rename Combofix unless instructed.
    • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
    • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.
      "%userprofile%\desktop\ComboFix.exe" /KillAll

    • Click OK and this will start ComboFix in a special way.
    • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

    Note:

    Do not mouse-click combofix's window while it is running. That may cause it to stall.

    * After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

    * Reconnect to the internet

    * Post the following logs/Reports:

    • ComboFix.txt
    • Fresh HijackThis log run after all the other tools have performed their cleanup.

  2. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your computer problem today.

    Download OTViewIt to your desktop.

    • Close all windows and open it
    • Click Run Scan and let the program run uninterrupted
    • It will produce two logs for you, one will pop up called OTViewIt.txt, the other will be saved on your desktop and called Extras. Post both those logs here.
    • You may need to use two posts to get it all on the forum

  3. Hello again,

    Please do an online scan with Kaspersky WebScanner

    I highly recommend using Internet Explorer for best results!

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

    Click on the Accept button and install any components it needs.

    • The program will install and then begin downloading the latest definition files.
    • Once they are downloaded, the database will be updated.
      Please accept any ActiveX or Java notifications
    • After the files have been updated, go to the left side of the page under the Scan section and select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete, click on View scan report
    • Now, click on the Save Report as button.
    • Save the file to your desktop.
    • Copy and paste that information in your next post.

  4. I will never recommend any new Symantec products no matter what the reviews say. I have worked with it in the past, and have worked with their newer programs, and I still strongly dislike their products.

    I would highly recommend ESET NOD32 if you are looking to pay for a new subscription. It is very effective, low on resources, and has outstanding proactiv detection. This means it doesn't always rely on a "signature" from the company in order to detect threats. It is what I use and what many people in the malware removal community recommend.

    http://www.eset.com/products/nod32.php

  5. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    I am not seeing anything malicous from this log, so lets dig a little deeper.

    Step 1

    Please download ATF Cleaner by Atribune.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    Step 2

    Download OTViewIt to your desktop.

    • Close all windows and open it
    • Click Run Scan and let the program run uninterrupted
    • It will produce two logs for you, one will pop up called OTViewIt.txt, the other will be saved on your desktop and called Extras. Post both those logs here.
    • You may need to use two posts to get it all on the forum

  6. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    Step 1

    Please download ATF Cleaner by Atribune.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    Step 2

    Open HijackThis, click Config, click Misc Tools

    Click "Open Uninstall Manager"

    Click "Save List" (generates uninstall_list.txt)

    Click Save, copy and paste the results in your next post.

    Step 3

    Please do an online scan with Kaspersky WebScanner

    I highly recommend using Internet Explorer for best results!

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

    Click on the Accept button and install any components it needs.

    • The program will install and then begin downloading the latest definition files.
    • Once they are downloaded, the database will be updated.
      Please accept any ActiveX or Java notifications
    • After the files have been updated, go to the left side of the page under the Scan section and select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete, click on View scan report
    • Now, click on the Save Report as button.
    • Save the file to your desktop.
    • Copy and paste that information in your next post.

    Step 4

    In your next post, please post the following

    • uninstall_list.txt
    • Kaspersky Scan Report

  7. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    Sorry for the delay!

    Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.

    Please re-open HijackThis and scan. Check the boxes next to all the entries listed below.

    O4 - HKLM\..\Run: [sysberay2] C:\windows\che3.exe

    O4 - HKLM\..\Run: [sysftray2] C:\windows\bolivar23.exe

    O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe

    Now close all windows other than Hijackthis, then click Fix Checked. Close HijackThis.

    Then

    Please copy (Ctrl C) and paste (Ctrl V) the following text in the code box to Notepad. Save it as "All Files" and name it FixServices.bat. Please save it on your desktop.

    @echo off
    sc stop BOONTY
    sc delete BOONTY
    sc stop Boonty Games
    sc delete Boonty Games
    DEL fixservices.bat

    Double click fixservices.bat. A window will open and close. This is normal.

    Then

    Reboot into safe mode.

    Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

    Please enter Safe Mode by using the Arrow Keys and then hit Enter.

    Please go to Start > Control Panel > Add or Remove Programs and remove the following (if present):

    Boonty

    Please note any other programs that you dont recognize in that list in your next response

    Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these folders (if present):

    C:\Program Files\Common Files\BOONTY Shared

    Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these files (if present):

    C:\windows\che3.exe

    C:\windows\bolivar23.exe

    After that, Reboot into Normal Mode.

    Please post a fresh HJT log after completing the above.

  8. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    Sorry for the delay!

    Please Do a system scan and save a logfile button in HJT. It will scan and the log should open in notepad. Please post that log in this thread and we will then go from there.

  9. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    Sorry for the delay!

    Step 1

    Please download ATF Cleaner by Atribune.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    Step 2

    Open HijackThis, click Config, click Misc Tools

    Click "Open Uninstall Manager"

    Click "Save List" (generates uninstall_list.txt)

    Click Save, copy and paste the results in your next post.

    Step 3

    Please do an online scan with Kaspersky WebScanner

    I highly recommend using Internet Explorer for best results!

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

    Click on the Accept button and install any components it needs.

    • The program will install and then begin downloading the latest definition files.
    • Once they are downloaded, the database will be updated.
      Please accept any ActiveX or Java notifications
    • After the files have been updated, go to the left side of the page under the Scan section and select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete, click on View scan report
    • Now, click on the Save Report as button.
    • Save the file to your desktop.
    • Copy and paste that information in your next post.

  10. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    Sorry for the delay!

    Download OTViewIt to your desktop.

    • Close all windows and open it
    • Click Run Scan and let the program run uninterrupted
    • It will produce two logs for you, one will pop up called OTViewIt.txt, the other will be saved on your desktop and called Extras. Post both those logs here.
    • You may need to use two posts to get it all on the forum

  11. Hi everyone,

    Well I have another networking issue in my brother's PC. For our setup we have a Belkin 802.11 g wireless router connected wirelessly to a Nintendo Wii, and 2 Windows XP machines. Everything is good on the Wii and my machine, but it is on his machine where it shows its connected to the network just fine, but has no internet in Opera or IE. Now when I restart, the internet will work for a few minutes, then will just go out. I have googled this but I get lots of results with typing stuff into the CMD and getting logs, but I can't read those at all. I have tried manually reseting the WinSock, using WinSockXPFix, using System Repair Engineer, and ran ipconfig/renew. I am out of ideas, any help is greatly appreciated.

    Thanks again,

    Monster

  12. Nice job your log looks clean!

    Please use the following suggestions to help prevent reinfection.

    Time for some housekeeping

    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK
      • CF_Cleanup.png

      [*] When shown the disclaimer, Select "2"

    The above procedure will:

    • Delete the following:
      • ComboFix and its associated files and folders.
      • VundoFix backups, if present
      • The C:\Deckard folder, if present
      • The C:_OtMoveIt folder, if present

      [*] Reset the clock settings.

      [*] Hide file extensions, if required.

      [*] Hide System/Hidden files, if required.

      [*] Reset System Restore.

    The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. As a note, all of the tools and utilities mentioned are either free or have free versions available.

    Malwarebytes' Anti-Malware - A very powerful tool which searches and kills malware that infects your system.

    **Tutorial on installing & using this product can be found HERE**

    SpywareBlaster - Great prevention tool to keep malware from installing on your system.

    **Tutorial on installing & using this product can be found HERE**

    SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

    **Tutorial on installing & using this product can be found HERE**

    ZonedOut - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders.

    Firewall A firewall is very important, in order to protect your computer from hackers. I notice that you don't have one installed! Therefore I recommend Comodo, Online Armor, or Outpost.

    **Tutorial on Firewalls can be found HERE**

    It is important to run only one of each type of protection program in resident mode at a time since conflicts can make them less effective. This would mean only one resident antivirus, firewall and scanning type of anti-spyware. Programs like SpywareBlaster and IE-Spyads do not conflict with any of these since they don't have a real time scanning engine that would conflict.

    Windows Updates - It is highly recommended to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

    It is also highly recommended to stay on top of your updates at all times, for Windows and all the above mentioned applications. This will ensure that you stay protected at the maximum level possible.

    Finally, I strongly recommend action-smiley-036.gifHow did I get infected in the first place? (by Tony Klein)

    Good luck and safe surfing :)

  13. Hey,

    Please do an online scan with Kaspersky WebScanner

    I highly recommend using Internet Explorer for best results!

    Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

    Click on the Accept button and install any components it needs.

    • The program will install and then begin downloading the latest definition files.
    • Once they are downloaded, the database will be updated.
      Please accept any ActiveX or Java notifications
    • After the files have been updated, go to the left side of the page under the Scan section and select My Computer.
    • This will start the program and scan your system.
    • The scan will take a while so be patient and let it run.
    • Once the scan is complete, click on View scan report
    • Now, click on the Save Report as button.
    • Save the file to your desktop.
    • Copy and paste that information in your next post.

  14. Hey,

    Please delete the old CFScript off of your dektop.

    1. Please open Notepad

    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    File::
    C:\WINDOWS\system32\tcvdhd.dll
    C:\WINDOWS\system32\rvfduvbf.dll
    C:\WINDOWS\system32\bcamtryd.dll
    C:\WINDOWS\system32\jkkKeeDw.dll
    C:\sqmnoopt04.sqm
    C:\sqmdata04.sqm
    C:\WINDOWS\system32\qdoahcie.dll
    C:\WINDOWS\system32\mgwlun.dll
    C:\WINDOWS\system32\qsxjef.dll
    C:\WINDOWS\system32\iuujefha.dll

    Folder::
    C:\Program Files\PCHealthCenter

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ab3a1ea-08b8-4537-9be4-75014d32fe81}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{71DAD6B9-06A8-4F66-A93F-ACBACC67B651}]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    CFScriptB-4.gif

    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:

    • Combofix.txt
    • A new HijackThis log.

  15. Ok, lets try a different approach.

    Please download the OTMoveIt2 by OldTimer.

    • Save it to your desktop.
    • Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
      [kill explorer]
      C:\WINDOWS\system32\tcvdhd.dll
      C:\WINDOWS\system32\rvfduvbf.dll
      C:\WINDOWS\system32\bcamtryd.dll
      C:\WINDOWS\system32\jkkKeeDw.dll
      C:\sqmnoopt04.sqm
      C:\sqmdata04.sqm
      C:\Program Files\PCHealthCenter
      HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ab3a1ea-08b8-4537-9be4-75014d32fe81}
      HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{71DAD6B9-06A8-4F66-A93F-ACBACC67B651}
      [emptytemp]
      [start explorer]


    • Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
    • Close OTMoveIt2

    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

  16. Hello again,

    1. Please open Notepad

    • Click Start , then Run
    • Type notepad .exe in the Run Box.

    2. Now copy/paste the entire content of the codebox below into the Notepad window:

    File::
    C:\WINDOWS\system32\tcvdhd.dll
    C:\WINDOWS\system32\rvfduvbf.dll
    C:\WINDOWS\system32\bcamtryd.dll
    C:\WINDOWS\system32\jkkKeeDw.dll
    C:\sqmnoopt04.sqm
    C:\sqmdata04.sqm

    Folder::
    C:\Program Files\PCHealthCenter

    Registry::
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ab3a1ea-08b8-4537-9be4-75014d32fe81}]
    [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{71DAD6B9-06A8-4F66-A93F-ACBACC67B651}]

    3. Save the above as CFScript.txt

    4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

    CFScriptB-4.gif

    5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:

    • Combofix.txt
    • A new HijackThis log.

  17. Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

    If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

    Everyone else please begin a New Topic.

  18. Hello and Welcome to the forums. :)

    I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today.

    Please download this file - combofix.exe by sUBs

    • Save it to your Desktop
    • Please, never rename Combofix unless instructed.
    • Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
    • Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box.
      "%userprofile%\desktop\ComboFix.exe" /KillAll

    • Click OK and this will start ComboFix in a special way.
    • When finished, it will produce a log. Please save that log to a Notepad File to post in your next reply along with a fresh HJT log.

    Note:

    Do not mouse-click combofix's window while it is running. That may cause it to stall.

    * After you have saved the logs, restart your system to re-enable all the programs that were disabled during the running of ComboFix.

    * Reconnect to the internet

    * Post the following logs/Reports:

    • ComboFix.txt
    • Fresh HijackThis log run after all the other tools have performed their cleanup.

  19. Nice job your log looks clean!

    Please use the following suggestions to help prevent reinfection.

    Also, you may delete any tools I had you download during the cleaning process.

    System Restore maintains a backup of your programs and may also backup infections, so please reset it to make a clean Restore Point.

    Please do this:

    On the Desktop, right-click My Computer > click Properties > click the System Restore tab.

    Check Turn off System Restore.

    Click Apply > a window will pop up and ask if you really want to turn it off > click Yes.

    Please wait a few moments to let it clear.

    Now please remove the check from Turn off System Restore.

    Click Apply, and then click OK.

    System Restore will be working again and will have a new Restore Point.

    The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. As a note, all of the tools and utilities mentioned are either free or have free versions available.

    Malwarebytes' Anti-Malware - A very powerful tool which searches and kills malware that infects your system.

    **Tutorial on installing & using this product can be found HERE**

    SpywareBlaster - Great prevention tool to keep malware from installing on your system.

    **Tutorial on installing & using this product can be found HERE**

    SpywareGuard - Works as a Spyware "Shield" to protect your computer from getting malware in the first place.

    **Tutorial on installing & using this product can be found HERE**

    ZonedOut - Puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.

    ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out malware that like to reside in the temp folders.

    Firewall A firewall is very important, in order to protect your computer from hackers. I notice that you don't have one installed! Therefore I recommend Comodo, Online Armor, or Outpost.

    **Tutorial on Firewalls can be found HERE**

    It is important to run only one of each type of protection program in resident mode at a time since conflicts can make them less effective. This would mean only one resident antivirus, firewall and scanning type of anti-spyware. Programs like SpywareBlaster and IE-Spyads do not conflict with any of these since they don't have a real time scanning engine that would conflict.

    Windows Updates - It is highly recommended to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.

    It is also highly recommended to stay on top of your updates at all times, for Windows and all the above mentioned applications. This will ensure that you stay protected at the maximum level possible.

    Finally, I strongly recommend action-smiley-036.gifHow did I get infected in the first place? (by Tony Klein)

    Good luck and safe surfing :)

  20. Hello again,

    Step 1

    Please re-open HijackThis and scan. Check the boxes next to all the entries listed below.

    O20 - AppInit_DLLs: uafmed.dll

    Now close all windows other than Hijackthis, then click Fix Checked. Close HijackThis.

    Step 2

    Open notepad and copy and paste the following code box in it starting with @echo off

    @echo off
    echo Delitor by wng_z3r0 >deleteOutput.txt
    echo. >>deleteOutput.txt
    echo Files to delete: >>deleteOutput.txt
    echo ************************** >>deleteOutput.txt
    echo "C:\WINDOWS\sxmaokgf.exe" >>deleteOutput.txt
    attrib "C:\WINDOWS\sxmaokgf.exe" -h -r -s
    del /f /q "C:\WINDOWS\sxmaokgf.exe"
    echo. >>deleteOutput.txt
    echo END Files to delete: >>deleteOutput.txt
    echo ************************** >>deleteOutput.txt
    echo. >>deleteOutput.txt
    echo. >>deleteOutput.txt
    echo. >>deleteOutput.txt
    echo Files remaining after deletion: >>deleteOutput.txt
    echo ************************** >>deleteOutput.txt
    if exist "C:\WINDOWS\sxmaokgf.exe" echo "C:\WINDOWS\sxmaokgf.exe" is STILL present >>deleteOutput.txt
    if exist "C:\WINDOWS\sxmaokgf.exe" dir /q "C:\WINDOWS\sxmaokgf.exe" >>deleteOutput.txt
    echo. >>deleteOutput.txt
    echo END of file: >>deleteOutput.txt
    echo ************************** >>deleteOutput.txt
    start notepad "%cd%\deleteOutput.txt"
    exit

    Save this as replace.bat , choose to save as *all files and place it on your desktop.

    It should look like this:bat.gif

    (In case you are unsure how to create a bat file, take a look here with screenshots.)

    * Reboot into Safe Mode: ( without networking support !)

    °To get into the Windows Safe Mode, restart your computer and, just before Windows starts to load, tap the F8 key a few times.

    Choose Safe Mode from the menu that will appear and press Enter.

    Once in Safe mode, doubleclick replace.bat you created previously.

    The data needed then should be merged.

    Then please boot back to normal Windows.

    Step 3

    Please download ATF Cleaner by Atribune.

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.

    If you use Firefox browser

    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser

    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    Click Exit on the Main menu to close the program.

    Step 4

    Please download Malwarebytes' Anti-Malware from Here or Here

    Double Click mbam-setup.exe to install the application.

    • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    • If an update is found, it will download and install the latest version.
    • Once the program has loaded, select "Perform Full Scan", then click Scan.
    • The scan may take some time to finish,so please be patient.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Make sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
    • Copy&Paste the entire report in your next reply.

    Extra Note:

    If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.