Hello, aureliane.B! Let's start with some important instructions:
- Avoid installing or uninstalling programs during the malware removal process, because doing so can cause discrepancies between the information in different log files created by different programs at different times.
- Do NOT run tools such as Combofix unless instructed by a BleepingComputer staff member. These tools can break your computer if used improperly, so you should only run them if you know what you are doing or if the person who told you to use Combofix knows what they're doing.
- If you want to, you should back up all important documents and files to an external storage device or online file backup service. Malware infections--and attempts to fix them--can prevent your computer from booting up, making your files unaccessable; this means that backing up your files to an USB flash drive or to an online service like Dropbox before attempting to remove malware is a good idea.
Step 1: Rkill
- Please download Rkill by Grinler, and save it to your desktop.
- Run the program. If you are using Windows Vista or above, you should right click the program and select "Run as administrator".
- A Black DOS box should appear; this indicates that the program is functioning.
- The program will generate a log file on your desktop. Post the contents of that file in your next reply.
- Do not restart your computer until the other steps are finished.
Step 2: Please download MiniToolBox by Farbar, and save it to your desktop.
Run the program. Please select the following options:
- Flush DNS
- Report IE proxy settings
- Reset IE proxy settings
- Report FF proxy settings
- Reset FF proxy settings
- List winsock entries
- List content of Hosts
- List installed programs
- List last 10 event viewer errors
- List restore points
After the program finishes its job, it will create a log file called "Result.txt" on your desktop. Post the contents of that file in your next reply.
Step 3: Run ESET online scanner
- Using Internet Explorer, navigate to http://www.eset.com/us/online-scanner-popup/ (If you used another web browser, such as Firefox, you will have to download an installer file)
- Accept any security warnings which may appear.
- Click on the advanced settings part, and select "Scan for potentially unsafe applications","remove found threats", and "Scan archives".
- Check "scan for potentially unwanted applications".
- Click "start".
- Eset will download updates and scan your computer; this may take a few minutes to a few hours.
- When the scan completes, click "list threats".
- Click "Export", and save the log file to your desktop.
- Post the contents of the log file to your next forum post. Please note that if ESET does not detect anything, it may not necessarily generate a log file.
Step 4: Please download AdwCleaner by Xplode, and save it to your desktop.
- Click on the "scan" button.
- The tool will scan your computer for adware; this may take a few minutes.
- After the scan has finished, click on the "Report" button. A logfile, AdwCleaner[R0].txt, will show.
- After viewing the log, close the log file window. View the list of adware detections, and uncheck ones that you do not want to remove(i.e. the ones which you're sure to be benign).
- Press the "Clean" button. You will be requested to restart your computer.
- After restarting your computer, a log file called AdwCleaner[S0].txt will show. Post the contents of that log file in your next reply.
Step 5: Please download Junkware Removal Tool by thisisu to your desktop.
- Please turn off your antivirus program before running the tool to avoid conflicts. Remember to turn your antivirus back on afterwards.
- Run the program. If you are using Windows Vista or above, right-mouse click JRT.exe and select "Run as Administrator" instead of double-clicking.
- The tool will start scanning your computer. A DOS box will appear; this is normal and indicates that the tool is working.
- After the scan finishes, a log file called JRT.txt will appear on your desktop. Post the contents of that log file in your next reply.