- Please run OTL.exe again
- Under the Custom Scans/Fixes box at the bottom, copy and paste in the following:
Code:
:files
C:\ProgramData\gJ37855LdKdD37855
:otl
[2011/12/11 20:12:02 | 000,000,000 | ---D | M] (ShopToWin13) -- C:\Users\Ron\AppData\Roaming\Mozilla\Firefox\Profiles\geiz0urb.default\extensions\{b9dbe2c0-031f-4cad-911a-f4a7381d79c0}
O4 - HKCU..\Run: [gJ37855LdKdD37855] C:\ProgramData\gJ37855LdKdD37855\gJ37855LdKdD37855.exe ()
O20 - HKLM Winlogon: Shell - (C:\ProgramData\gJ37855LdKdD37855\gJ37855LdKdD37855.exe) -C:\ProgramData\gJ37855LdKdD37855\gJ37855LdKdD37855.exe ()
:commands
[reboot]
- CAREFUL NOW! You must click the Run Fix button, NOT the Run Scan!
- If it asks to reboot the computer, please allow that.
- Finally, post the contents of the log. (Located at C:\_OTL\Moved Files)
This should take care of the AV security Sphere. After running this you can reboot your computer and probably will find its gone.
====================
You have some adware installed on your computer (Shop To Win). Adware is regarded as low-risk malware. While some adware has its uses, it also provides unsolicited advertisements, may slow down your computer and is not alltogether trustworthy (it may upgrade to something nastier). I would suggest you uninstall it (Start >> Control Panel >> Add or Remove Programs). If you are not successful at uninstalling, let me know and we´ll eliminate it manually.
====================
Please download Malwarebytes' Anti-Malware from here.
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select Perform Quick Scan, then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
- If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
- Click OK to either and let MBAM proceed with the disinfection process.
- If asked to restart the computer, please do so immediately.
Post the contents of the MBAM log in your next reply, please.