Hi Dan,
Well there are LOTS of nasty items showing in your log.
First of all, however, you are running HijackThis out of a temporary directory. Can you please create a folder in My Documents and call it Hijack (or something similar). Then extract HijackThis into the folder you have created and run it from there. The reason for this is that HijackThis cannot create backup files whilst it is being run from a temporary folder.
Once you have moved your HJT to a permanent folder then lets begin with this fix;
You are showing a variation of the Virtumonde/Vundo adware variant.
Do this;
Download VirtumundoBegone and save it to your desktop.
VirtumundoBegone
Reboot your computer into Safe Mode
Then double click VirtumundoBeGone.exe you just downloaded and follow the instructions.
Exit when it has finished.
Next go here READ ME Before Posting A Request For Assistance!
Follow ALL the steps given by PP, including the downloading of the Anti-spy tools, the online anti-virus scans and the like.
Once you have completed all the steps and run all the programs he recommends, INCLUDING EWIDO, then reboot the machine and run a new HJT scan. Save the log and post back here with the new HJT log AND the Ewido log and we will see what else has to be done.
Judy


Reply With Quote