Hi Phoebe82,
This is info about the malware file:
http://virscan.org/report/33612dc52ef7113cc2a28b6aa53847de.htmlLook for mentioned file:
G:\WINDOWS\system32\WLCtrl32.dll
Right click the file and choose "Change Name".
change the name of the file.
Download IceSword and unzip to your desktop into a folder.
- Open that folder, doubleclick the "Sword icon" to be able to start IceSword.
- Left click file.
- Choose This computer in icesword and navigate to this driver files:
DeleteFile('C:\WINDOWS\System32\Drivers\Ipw75.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Bip20.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Bip64.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Dkr18.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Dlr52.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ems30.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Exe20.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Fmt20.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Fmt86.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ipv42.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ipv74.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ipw86.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Jqw17.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Jrx30.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Jrx63.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Lsa07.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Lsy28.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Mta85.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ovd75.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Owd85.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Pwd28.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Pwd52.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Qxe74.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Qxf17.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ryg86.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Sag30.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Sag63.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ucj75.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Vdj17.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Vqx17.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wek63.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wfl52.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Wfl85.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Xfm07.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Xgm07.sys');
DeleteFile('C:\WINDOWS\System32\Drivers\Ygn86.sys');
G:\WINDOWS\System32\Drivers\Yiu73.sys
- Right click and choose delete if any found.
For cleansing routine consider this:
http://virusinfo.info/showthread.php?p=201144Now restart your PC and post a new ComboFix log
Download Malwarebytes' Anti-Malware unto your desktop from here:
http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htmlDoubleclick mbam-setup.exe and choose for "Next" to install this tool.
When the installation is complete, put a tag at "Update MalwareBytes' Anti-Malware" and at bij "Launch MalwareBytes' Anti-Malware".
Then click "Finish".
Choose in mainfarme for tab "Scanner" then select "Perform full scan".
Click "Scan" and make sure all hard disks/partitions are selected.
Then click "Start Scan".
When the scan has finished, you click OK, then "Show Results" to see the scan results.
Make sure all are being selected, then click "Remove Selected".
Whenever the program asks for a restart, allow!.
Then a log will open(mbam-log-XX-XX-XXXX(xx-xx-xx).txt)
Attach this log next to your Combofix log ito your next posting
polonus