05-02-2012 11:00 PM
Let me know what to do next.
Thanks!!!
05-02-2012 11:07 PM
Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Doiwnload the attached CFscript.txt, Now drag the CFScript.txt into the ComboFix.exe

****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
05-03-2012 06:17 AM
Ok, ran Combofix and attached is the log file.
05-03-2012 04:08 PM
Why did you not have the script as the correct name as stated in the instructions, you had "CFscript.txt.URL"
Quads
05-03-2012 04:47 PM
I don't know why or how the .URL extention ended up on the script file. should I run throught the procedure again making sure the script is the correct name?
05-03-2012 04:53 PM
Yes. It should end with .txt (no .URL) Combofix does not understand the name.
Quads
05-03-2012 07:04 PM
Ok, I re-ran ComboFix and attached the log file.
05-03-2012 07:21 PM
That has taken care of the main Rootkit
Now time to scan the hole system to find anything else before using another program to do the final script cleanup
Please read carefully
Please scan with ESET next Using Internet Explorer
I'd like us to scan your machine with ESET OnlineScan
button.
to download the ESET Smart Installer. Save it to your desktop.
button.
and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it.
Quads
05-04-2012 08:16 AM
Ok I ran the ESET Online Scanner, took almost 12 hours to complete and found 39 Infected Files.
San Results attched and Log attached.
05-04-2012 05:29 PM
I can deal with these in the final cleanup process.
Download OTL hxxp://oldtimer.geekstogo.com/OTL.exe (change the hxxp to http) save it to your Desktop.
Double click on OTL.exe to run it. Right click OTL.exe and select run as administator for Vista and Win 7.
Click the Scan All Users checkbox.
Change file age to 60 days
Press the 
Quads
