I have followed these steps and cleaned everything that was there.
You seem to have forgotten step 3,but both scanner say the computer is clean, the internet seems ok but for some reason it still wont go to www.facebook.com.
Any help would be great as this is most annoying.
this was my first mbam logfile
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7513
Windows 6.1.7601 Service Pack 1
Internet Explorer 9.0.8112.16421
20/08/2011 09:05:50
mbam-log-2011-08-20 (09-05-50).txt
Scan type: Full scan (C:\|K:\|)
Objects scanned: 396156
Time elapsed: 52 minute(s), 43 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 9
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 32
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\sysdriver32.exe (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\systeminfog (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\SERVICES32.EXE (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\wxpdrivers (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvbtcclient (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srvsysdriver32 (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\2716335.exe (Trojan.Agent) -> Value: 2716335.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\5779199.exe (Trojan.Agent) -> Value: 5779199.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\8468651-loader2.exe (Trojan.Agent) -> Value: 8468651-loader2.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\87562.exe (Trojan.Agent) -> Value: 87562.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Value: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{0BDA0769-FD72-49F4-9266-E1FB004F4D8F} (PUP.Dealio.TB) -> Value: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\106130.exe (Trojan.Downloader.Gen) -> Value: 106130.exe -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Services32.exe\close (Trojan.Agent) -> Value: close -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
c:\Windows\rpcminer (Trojan.BCMiner) -> Quarantined and deleted successfully.
Files Infected:
c:\Windows\Temp\2716335.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Users\Steve\AppData\Local\Temp\5779199.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\8468651-loader2.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\87562.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\program files (x86)\iobit toolbar\IE\4.5\iobittoolbarie.dll (PUP.Dealio.TB) -> Quarantined and deleted successfully.
c:\program files (x86)\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully.
c:\Users\Steve\Desktop\installers\removewat.exe (HackTool.Wpakill) -> Quarantined and deleted successfully.
c:\Users\Steve\Desktop\vso convertxtodvd 4.1.19.364 final incl serial + keygen\Keygen\Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
c:\Windows\Temp\17789_myunrar2.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\Temp\78267052.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Windows\Temp\811249.exe (Trojan.Agent.H) -> Quarantined and deleted successfully.
c:\Windows\Temp\8544666.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\Windows\Temp\93097_myunrar2.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\Windows\update.1\svchost.exe (Trojan.Dropper) -> Quarantined and deleted successful
and since cleaning it the new one is completely empty.
I have just realised that a lot of sites i try to go to I get redirected to gomeo and also notice it loading something from 7daysoftheweek.com
I hope that might help you work this out for me.
This post has been edited by Madforit: 20 August 2011 - 03:29 AM