Are you logged in as an administrator? That radio dial may fail because of it if you aren't.
Ok, let's try this:
Please download APT and unzip the contents to a new folder on your desktop.
Open HijackThis, click do a system scan only and checkmark these:
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\{938F702D-CC21-43FC-BEF0-9382BA4945C3}.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\{938F702D-CC21-43FC-BEF0-9382BA4945C3}.dll
O4 - HKLM\..\Run: [trkfw.exe] C:\WINDOWS\System32\trkfw.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{19B17158-42FD-418B-B9C8-01EC305C7F55}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C3F6454-817B-4435-93DD-962D13D0AE06}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{69767973-9E92-4618-8894-F732ED49292F}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{883F5378-3717-478F-8ADC-48FFAA10B5AA}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{C15126FA-D632-40B0-AFBA-E3721B9534A3}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{CFB1D823-A012-467A-9D9A-1E19EFA0BC57}: NameServer = 85.255.116.30 85.255.112.144
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.30 85.255.112.144
O17 - HKLM\System\CS1\Services\Tcpip\..\{19B17158-42FD-418B-B9C8-01EC305C7F55}: NameServer = 85.255.116.30,85.255.112.144
Close all windows including browser and press fix checked.
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Now, start The Avenger program by clicking on its icon on your desktop.
Re-run fixwareout
Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log and fixwareout report by using Add/Reply
Ok, let's try this:
Please download APT and unzip the contents to a new folder on your desktop.
- Open the folder you just created and click on apt.exe and search in the window for trkfw.exe.
- Open your C:\Windows\system32 folder and search for C:\WINDOWS\System32\trkfw.exe. Don't delete it yet, just leave the system32 folder open so you can see the bad file.
- In APT again, Select trkfw.exe and Click Kill3
- Then immediately delete C:\WINDOWS\System32\trkfw.exe from your system32 folder.
- Close APT.
Open HijackThis, click do a system scan only and checkmark these:
O2 - BHO: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\{938F702D-CC21-43FC-BEF0-9382BA4945C3}.dll
O3 - Toolbar: SearchToolbar - {08BEC6AA-49FC-4379-3587-4B21E286C19E} - C:\WINDOWS\System32\{938F702D-CC21-43FC-BEF0-9382BA4945C3}.dll
O4 - HKLM\..\Run: [trkfw.exe] C:\WINDOWS\System32\trkfw.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{19B17158-42FD-418B-B9C8-01EC305C7F55}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{1C3F6454-817B-4435-93DD-962D13D0AE06}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{69767973-9E92-4618-8894-F732ED49292F}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{883F5378-3717-478F-8ADC-48FFAA10B5AA}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{C15126FA-D632-40B0-AFBA-E3721B9534A3}: NameServer = 85.255.116.30,85.255.112.144
O17 - HKLM\System\CCS\Services\Tcpip\..\{CFB1D823-A012-467A-9D9A-1E19EFA0BC57}: NameServer = 85.255.116.30 85.255.112.144
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.30 85.255.112.144
O17 - HKLM\System\CS1\Services\Tcpip\..\{19B17158-42FD-418B-B9C8-01EC305C7F55}: NameServer = 85.255.116.30,85.255.112.144
Close all windows including browser and press fix checked.
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Files to delete:
C:\WINDOWS\System32\CSANL.EXE
C:\WINDOWS\SYSTEM32\DMLFN.EXE
C:\WINDOWS\system32\{8608C8F0-DE83-44FC-ADAA-F0DED6F2460B}.dll
C:\WINDOWS\system32\{0D114F70-FC0D-4B5E-A2FE-043CB22F7339}.exe
C:\WINDOWS\system32\{0928CABA-40DC-4EE2-92C9-F743DBBA550D}.exe
C:\WINDOWS\system32\{1000B2AD-C398-4E63-A342-EE8D9D0EF3F6}.exe
C:\WINDOWS\system32\{2BE75C23-723D-447E-AC7A-24A37C938847}.exe
C:\WINDOWS\system32\{FE52CAD0-296D-4F1F-B06E-7FB1B4154210}.exe
C:\WINDOWS\system32\{4FE55A5C-BC08-469F-B3AA-999268853972}.exe
C:\WINDOWS\system32\{04075705-A3A9-484E-84DB-52486A2C7317}.exe
C:\WINDOWS\system32\{FE84D989-E9F8-47D5-9506-3D6E09257067}.exe
C:\WINDOWS\system32\{EF9E2DED-76B2-452F-9203-91BC389AAB78}.exe
C:\WINDOWS\System32\{938F702D-CC21-43FC-BEF0-9382BA4945C3}.dll
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Now, start The Avenger program by clicking on its icon on your desktop.
- Under "Script file to execute" choose "Input Script Manually".
- Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
- Paste the text copied to clipboard into this window by pressing (Ctrl+V).
- Click Done
- Now click on the Green Light to begin execution of the script
- Answer "Yes" twice when prompted.
- It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
- On reboot, it will briefly open a black command window on your desktop, this is normal.
- After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
- The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Re-run fixwareout
Please copy/paste the content of c:\avenger.txt into your reply along with a fresh HJT log and fixwareout report by using Add/Reply