Hi and Welcome to the Malwarebytes' forum.
Please first see if any of these procedures to unblock MBAM work for you:http://www.malwarebytes.org/forums/index.php?showtopic=17607Please download
ATF Cleaner by Atribune
- Close Internet Explorer and any other open browsers
- Double-click ATF-Cleaner.exe to run the program.
- Under Main choose: Select All
- Click the Empty Selected button.
If you use Firefox browser- Click Firefox at the top and choose: Select All
- Click the Empty Selected button.
- NOTE: If you would like to keep your saved passwords, please click
- No at the prompt.
If you use Opera browser- Click Opera at the top and choose: Select All
- Click the Empty Selected button.
- NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click
Exit on the Main menu to close the program.
Reboot
Next, download this
Antirootkit Program to a folder that you create such as
C:\ARK, by choosing the "Download EXE" button on the webpage.
Disable the active protection component of your antivirus by following the directions that apply here:
http://www.bleepingcomputer.com/forums/topic114351.htmlNext, please perform a rootkit scan:
- Double-click the randomly name EXE located in the C:\ARK folder that you just downloaded to run the program.
- When the program opens, it will automatically initiate a very fast scan of common rootkit hiding places.
- When this "quick" scan is finished (a few seconds), copy the quick scan report to the windows clipboard, save it as ARKQ.txt and paste it in a reply back here
- Only if the ARK program alerts you to rootkit activity and invites you to complete a complete scan - click the Rootkit/Malware tab,and then select the Scan button.
- Now, relaunch the ARK program, and click the Rootkit/Malware tab,and then select the Scan button.
- Leave your system completely idle while this longer scan is in progress.
- When the scan is done, save the scan log to the Windows clipboard
- Open Notepad or a similar text editor
- Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
- Exit the Program
- Save the Scan log as ARK.txt and post it in your next reply. If the log is very long attach it please.
Please download Combofix from one of these locations:HERE or
HERE I want you to rename Combofix.exe
as you download it to a name of your choice such as
detox.exeNotes:
- It is very important that save the newly renamed EXE file to your desktop.
- You must rename Combofixe.exe as you download it and not after it is on your computer.
You may have to modify your browser settings if you use Firefox, so you can rename Combofix.exe as you download it. To do that:- Open Firefox
- Click Tools -> Options -> Main
- Under the downloads section check the button that says "Always ask me where to save files".
- Click OK
- For Internet Explorer:
- Choose to save, not open the file
- When prompted - save the file to your desktop, and rename it anything with an .exe extension on the end.
Here is a tutorial that describes how to download, install and run Combofix more thoroughly. Please review it and follow the prompts to install Recovery Console - if you have not done that already:
http://www.bleepingcomputer.com/combofix/how-to-use-combofixVery Important! Temporarily disable your antivirus and antimalware real-time protection and any script blocking components of them or your firewall before performing a scan. They can interfere with ComboFix and even remove onboard components so it is rendered ineffective:
http://www.bleepingcomputer.com/forums/topic114351.htmlNote: The above tutorial does not tell you to rename Combofix as I have instructed you to do in the above instructions, so make sure you complete the renaming step before launching Combofix.
Running CombofixIn the event you already have Combofix, please delete it as this is a new version.
- Close any open browsers.
- Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.
1. Double click on the renamed combofix.exe (detox.exe) & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt
3. Post the contents of that log in your next reply with a new hijackthis log.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang. Do not proceed with the rest of the fix if you fail to run combofix.
Please post (do NOT attach) ARKQ.txt or ARK.txt, and C:\ComboFix.txt in your next reply.