I have a nasty and i need some help in cleaning this off of my system.There is an awful Anitvirus ad that pops up saying that my computer is infected and that "Antivirus Pro 2010" can fix the problem. Sounds to me like this is the problem.
Here is the list of steps I have taken that has lead me to this post.
step 1- the option to view hidden files is not available for me to change (my
Computer/ tools/folder options/ the only thing i see is....
Map network drive...
Disconnect network drive
Synchronize
Also I am logged in as the administrator and under my computer/ properties
there is no tab that is labeled System Restore.
Step 2- Atf- cleaner downloaded
Step 4- Antivirus pro 2010
also these icons keep installing on my desktop...
"C:\Program Files\Internet Explorer\iexplore.exe" nudetube.com
"C:\Program Files\Internet Explorer\iexplore.exe" youporn.com
"C:\Program Files\Internet Explorer\iexplore.exe" pornotube.com
Step 5- show all files option unavaliable
he option to view hidden files is not avaliable for me to change (my
Computer/ tools/folder options/ the only thing i see is....
Map network drive...
Disconnect network drive
Synchronize
Step 6- will not run Microsoft® Windows® Malicious Software Removal Tool .. says it is extracting files/ dialog box disappears and
then nothing...
Step 7- ATF Cleaner Successful
Step 8- Malwarebytes' Anti-Malware will not run setup
Step 9- ESET results are as follows....
C:\Documents and Settings\Guest\Local Settings\Temp\debug.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\Documents and Settings\Guest\Local Settings\Temp\install.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\Documents and Settings\Guest\Local Settings\Temp\svchost.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\Documents and Settings\Guest\Local Settings\Temp\system.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\Documents and Settings\Guest\Local Settings\Temp\taskmgr.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\I386\GTDownDE_87.ocx probably a variant of Win32/Adware.Agent application cleaned by deleting - quarantined
C:\WINDOWS\braviax.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\cru629.dat Win32/Small.EJX trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\braviax.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\cru629.dat Win32/Small.EJX trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\tapi.nfo Win32/Oficla.F trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\wingenocx.dll Win32/Adware.CoreguardAntivirus application cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\wisdstr.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\_scui.cpl a variant of Win32/Kryptik.AKT trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\DLLCACHE\beep.sys a variant of Win32/UltimateDefender.A trojan cleaned by deleting - quarantined
C:\WINDOWS\SYSTEM32\DRIVERS\BEEP.SYS a variant of Win32/UltimateDefender.A trojan unable to clean
C:\WINDOWS\SYSTEM32\DRIVERS\ce369842.sys a variant of Win32/Rustock.NKU trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\1846686026.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\2245236574.exe a variant of Win32/Kryptik.AKT trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\735105362.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\973492060.exe a variant of Win32/Kryptik.AKT trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\csrss.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\install.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\login.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\lsass.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\mdm.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\msupd_2.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\notepad.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\services.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\smss.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\spoolsv.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\svchost.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\system.exe a variant of Win32/Kryptik.AIQ trojan cleaned by deleting - quarantined
C:\WINDOWS\Temp\TMP000000010A13B33D6A0CEDB1 a variant of Win32/Cryptoz trojan cleaned by deleting - quarantined
Operating memory Win32/Olmarik.KI trojan contained infected files
I cannot get Hijack this to run and am stuck at this point...I need a little help!!