I've added a Rogue Killer report that I did before reading what was required, so I've added that anyway.....
Thanks in advance.
Posted 21 June 2012 - 08:26 PM
Posted 21 June 2012 - 09:02 PM


Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 22 June 2012 - 12:41 AM
Posted 22 June 2012 - 03:39 AM
Java(TM) 6 Update 22 Java(TM) 6 Update 31
:OTLO2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not foundO6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery presentO33 - MountPoints2\{819ee075-c3bd-11df-9155-002433e7cfb0}\Shell - "" = AutoRunO33 - MountPoints2\{819ee075-c3bd-11df-9155-002433e7cfb0}\Shell\AutoRun - "" = Auto&PlayO33 - MountPoints2\{819ee075-c3bd-11df-9155-002433e7cfb0}\Shell\AutoRun\command - "" = G:\Startme.exe[2012/06/17 14:18:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{FD7CAB3E-E895-4E98-9D68-A307CC601204}:Commands[Purity][EmptyTemp][EmptyFlash][EmptyJava][Reboot]Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 23 June 2012 - 12:07 PM
Posted 23 June 2012 - 12:19 PM
Posted 23 June 2012 - 02:43 PM
:OTL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
[2012/06/17 14:18:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{FD7CAB3E-E895-4E98-9D68-A307CC601204}
:Commands
[Purity]
[EmptyTemp]
[EmptyFlash]
[EmptyJava]
[Reboot]
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 24 June 2012 - 12:10 PM
Posted 24 June 2012 - 04:05 PM







Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 24 June 2012 - 05:51 PM
Posted 24 June 2012 - 06:27 PM

Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 24 June 2012 - 07:42 PM
Posted 24 June 2012 - 08:03 PM
beginSetAVZGuardStatus(True);SearchRootkit(true, true); DeleteFile('C:\WINDOWS\system32\MsSip1.dll'); DeleteFile('C:\WINDOWS\system32\MsSip2.dll'); DeleteFile('C:\WINDOWS\system32\MsSip3.dll'); RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 1','$DLL'); RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 2','$DLL'); RegKeyParamDel('HKEY_LOCAL_MACHINE','SYSTEM\CurrentControlSet\Services\WinTrust\SubjectPackages\MS Subjects 3','$DLL');ExecuteSysClean;RebootWindows(true);end.Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 24 June 2012 - 09:59 PM
Posted 24 June 2012 - 10:11 PM
:OTLO2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found[2012/06/17 14:18:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{FD7CAB3E-E895-4E98-9D68-A307CC601204}:Commands[Purity][EmptyTemp][EmptyFlash][EmptyJava][Reboot]Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 24 June 2012 - 11:13 PM
Posted 24 June 2012 - 11:25 PM
KillAll::
Folder::
C:\Documents and Settings\All Users\Application Data\{FD7CAB3E-E895-4E98-9D68-A307CC601204}
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 24 June 2012 - 11:44 PM
Posted 24 June 2012 - 11:53 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 25 June 2012 - 01:32 PM
Posted 25 June 2012 - 03:33 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 25 June 2012 - 07:43 PM
Posted 25 June 2012 - 08:23 PM
:OTLO2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery presentO6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions presentO7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel presentO7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present[2012/06/17 14:18:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{FD7CAB3E-E895-4E98-9D68-A307CC601204}:Commands[Purity][EmptyTemp][EmptyFlash][EmptyJava][Reboot]Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 26 June 2012 - 08:10 AM
Posted 26 June 2012 - 02:46 PM
and wait for the scan to finish.
and save the logfile to your desktop.Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 26 June 2012 - 05:08 PM
Posted 26 June 2012 - 05:51 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 26 June 2012 - 06:49 PM
Posted 26 June 2012 - 07:13 PM
Please download Malwarebytes' Anti-Malware from Here.Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 12:06 AM
Posted 27 June 2012 - 12:40 AM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 07:41 AM
Posted 27 June 2012 - 02:47 PM
Windows Registry Editor Version 5.00 [-HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery] [-HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions] [-HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel] [-HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions]Close Notepad.
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 04:28 PM
Posted 27 June 2012 - 05:19 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 06:13 PM
Posted 27 June 2012 - 06:34 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 07:36 PM
Posted 27 June 2012 - 08:52 PM
HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery
HKLM\Software\Policies\Microsoft\Internet Explorer\RestrictionsHKCU\Software\Policies\Microsoft\Internet Explorer\Control PanelHKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 09:41 PM
Posted 27 June 2012 - 09:53 PM
Yes, go ahead and use those.If I copy & paste the above instructions, ach time an error message appears, it reads ERROR: Hive returned NULL. If I follow the instructions from RegAssassin It gives me these keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Infodelivery
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\Restrictions
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Control Panel
HKEY_CURRENT_USER\Software\Policies\Microsoft\Internet Explorer\Restrictions
Should I use these?
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 27 June 2012 - 11:50 PM
Posted 28 June 2012 - 12:07 AM

and choose 

and click
to run it.Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 28 June 2012 - 09:33 AM
Posted 28 June 2012 - 10:27 AM
Posted 28 June 2012 - 03:55 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 29 June 2012 - 12:31 AM
Posted 29 June 2012 - 04:21 AM
KillAll:: Driver:: 0269081340819581mcinstcleanup File:: c:\windows\TEMP\026908~1.EXE

Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
Posted 29 June 2012 - 01:46 PM
Posted 29 June 2012 - 03:30 PM
Kevin Zoll [Malware Removal Team Lead]
Emsisoft Team - www.emsisoft.com
If you are seeking Malware Removal support keep it in the forums. It is not permissible to contact support staff by Private Messege (PM), IM (Skype, MSN, AOL, Yahoo, etc.) or Email.
Purchase Emsisoft Anti-Malware and Online Armor Firewall
0 members, 0 guests, 0 anonymous users