This is a pretty nasty form of malware that will take special tools to remove.
Flash Drive CleanupIf you use any flash drives please clean them now.
Download
Flash Disinfector by sUBs and save it to your Desktop.
- Double-click Flash_Disinfector.exe to run it.
- Your desktop and icons may disappear. This is normal.
- It will do a cleanup of removable storage devices, and write a protected Autorun.inf file to help prevent re-infection.
- Follow any prompts that may appear.
- The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
- Wait until it has finished scanning and then exit the program.
- There will be no GUI interface or log file produced.
- Reboot your computer when done.
.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection.----------
Open HijackThis and select
Do a system scan only.
Place a check mark next to the following entries: (if there)
- O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
- O4 - HKLM\..\Run: [My App] C:\WINDOWS\system32\Image.exe
- O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
- O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 Important: Close all open windows except for HijackThis and then click
Fix checked.
Once completed, exit HijackThis.
----------
Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your systemGo to
Start > Run and type
notepad.exe then click
OKCopy and paste the below into Notepad and save as fixme.reg to Your
DesktopREGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
"Alcmtr"=-
"My App"=-
Locate fixme.reg on your Desktop and double-click it. Answer
Yes when prompted to merge with the Registry.
Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.Delete the fixme.reg from the Desktop.
----------
Download ComboFix© by sUBs from one of the below links. Be sure top save it to the
Desktop.
Link #1Link #2**Note: It is important that it is saved directly to your DesktopClose any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.
Temporarily
disable your
antivirus, and any
antispyware real time protection
before performing a scan. Click
this link to see a list of security programs that should be disabled and how to disable them.
Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the
ComboFix log in your next reply.
Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.