Did you install a key logger on your system ?
Start OTS. Copy/Paste the information in the quotebox below into the pane where it says "Paste fix here" and then click the
Run Fix button.
[Unregister Dlls]
[Processes - Safe List]
YY -> restorer64_a.exe -> C:\WINDOWS\System32\restorer64_a.exe
[Modules - Safe List]
YY -> ijejaxakuqejako.dll -> C:\WINDOWS\ijejaxakuqejako.dll
[Registry - Safe List]
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {3b6e57bf-f6b9-4bc9-948b-c7ae92c29edd} [HKLM] -> C:\WINDOWS\System32\c_1ext.dll [Reg Error: Value error.]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YY -> "Jdiqohovojamaze" -> C:\WINDOWS\ijejaxakuqejako.DLL [rundll32.exe "C:\WINDOWS\ijejaxakuqejako.dll",Startup]
YY -> "restorer64_a" -> C:\WINDOWS\System32\restorer64_a.exe [C:\WINDOWS\system32\restorer64_a.exe]
[Registry - Additional Scans - Safe List]
< Registry Shell Spawning - Select to Repair > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command
YN -> regfile [merge] -> Reg Error: Key error.
YN -> txtfile [edit] -> Reg Error: Key error.
[Files/Folders - Created Within 30 Days]
NY -> AntivirusPro_2010 -> C:\AntivirusPro_2010
NY -> AntivirusPro_2010 -> C:\Program Files\AntivirusPro_2010
NY -> rundll22.exe -> C:\WINDOWS\rundll22.exe
[Files/Folders - Modified Within 30 Days]
NY -> oashdihasidhasuidhiasdhiashdiuasdhasd -> C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdhasd
NY -> Ojicomucetuhese.dat -> C:\WINDOWS\Ojicomucetuhese.dat
NY -> Ogazisohahoze.bin -> C:\WINDOWS\Ogazisohahoze.bin
NY -> umysilyz._dl -> C:\Program Files\Common Files\umysilyz._dl
NY -> ehaho._sy -> C:\WINDOWS\System32\ehaho._sy
NY -> opevykoq.db -> C:\Program Files\Common Files\opevykoq.db
NY -> idepaxi.vbs -> C:\WINDOWS\System32\idepaxi.vbs
NY -> ojyxul.dll -> C:\Program Files\Common Files\ojyxul.dll
NY -> ebilyq.scr -> C:\WINDOWS\ebilyq.scr
NY -> nyhuby.inf -> C:\Program Files\Common Files\nyhuby.inf
NY -> ocagovugyj.com -> C:\Documents and Settings\All Users\Application Data\ocagovugyj.com
NY -> ajiqadab.com -> C:\Documents and Settings\All Users\Application Data\ajiqadab.com
NY -> nuhugutyr.vbs -> C:\Program Files\Common Files\nuhugutyr.vbs
NY -> quhepahor.lib -> C:\WINDOWS\System32\quhepahor.lib
NY -> isabik.reg -> C:\Program Files\Common Files\isabik.reg
NY -> wapypum.com -> C:\WINDOWS\System32\wapypum.com
NY -> caxum.pif -> C:\Documents and Settings\All Users\Documents\caxum.pif
NY -> jupikuzavi.reg -> C:\WINDOWS\jupikuzavi.reg
NY -> xudipopiwo.bin -> C:\Documents and Settings\All Users\Application Data\xudipopiwo.bin
NY -> ugupako.bat -> C:\WINDOWS\ugupako.bat
NY -> meqybeno._dl -> C:\Program Files\Common Files\meqybeno._dl
NY -> edydanene.reg -> C:\Program Files\Common Files\edydanene.reg
NY -> hygipato.vbs -> C:\WINDOWS\hygipato.vbs
NY -> wirulekoga.reg -> C:\WINDOWS\wirulekoga.reg
NY -> mubegyp.lib -> C:\WINDOWS\System32\mubegyp.lib
NY -> aryzery.exe -> C:\Program Files\Common Files\aryzery.exe
NY -> jalyviku.sys -> C:\WINDOWS\System32\jalyviku.sys
NY -> qykady.com -> C:\WINDOWS\System32\qykady.com
NY -> apuzu.scr -> C:\Program Files\Common Files\apuzu.scr
NY -> fuzove.sys -> C:\Documents and Settings\All Users\Application Data\fuzove.sys
NY -> ruleqen.bat -> C:\WINDOWS\System32\ruleqen.bat
NY -> unumut.sys -> C:\WINDOWS\unumut.sys
NY -> yfepucolaf.dl -> C:\Program Files\Common Files\yfepucolaf.dl
NY -> ohasyfyr.ban -> C:\Documents and Settings\All Users\Application Data\ohasyfyr.ban
NY -> inojo.vbs -> C:\WINDOWS\System32\inojo.vbs
NY -> ewavoliz.pif -> C:\Documents and Settings\All Users\Application Data\ewavoliz.pif
NY -> wefehijyq.dll -> C:\WINDOWS\wefehijyq.dll
NY -> jugimotopi.inf -> C:\WINDOWS\jugimotopi.inf
NY -> uqudyxa.scr -> C:\WINDOWS\System32\uqudyxa.scr
NY -> ujehisum.bin -> C:\Documents and Settings\All Users\Application Data\ujehisum.bin
NY -> yvujihaqej.bat -> C:\Documents and Settings\All Users\Application Data\yvujihaqej.bat
NY -> restorer64_a.exe -> C:\WINDOWS\System32\restorer64_a.exe
NY -> rundll22.exe -> C:\WINDOWS\rundll22.exe
NY -> vpg_bcsb.ini -> C:\WINDOWS\vpg_bcsb.ini
[Files - No Company Name]
NY -> oashdihasidhasuidhiasdhiashdiuasdhasd -> C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdhasd
NY -> umysilyz._dl -> C:\Program Files\Common Files\umysilyz._dl
NY -> opevykoq.db -> C:\Program Files\Common Files\opevykoq.db
NY -> idepaxi.vbs -> C:\WINDOWS\System32\idepaxi.vbs
NY -> ojyxul.dll -> C:\Program Files\Common Files\ojyxul.dll
NY -> ebilyq.scr -> C:\WINDOWS\ebilyq.scr
NY -> nyhuby.inf -> C:\Program Files\Common Files\nyhuby.inf
NY -> ocagovugyj.com -> C:\Documents and Settings\All Users\Application Data\ocagovugyj.com
NY -> ajiqadab.com -> C:\Documents and Settings\All Users\Application Data\ajiqadab.com
NY -> nuhugutyr.vbs -> C:\Program Files\Common Files\nuhugutyr.vbs
NY -> quhepahor.lib -> C:\WINDOWS\System32\quhepahor.lib
NY -> isabik.reg -> C:\Program Files\Common Files\isabik.reg
NY -> wapypum.com -> C:\WINDOWS\System32\wapypum.com
NY -> caxum.pif -> C:\Documents and Settings\All Users\Documents\caxum.pif
NY -> ehaho._sy -> C:\WINDOWS\System32\ehaho._sy
NY -> xudipopiwo.bin -> C:\Documents and Settings\All Users\Application Data\xudipopiwo.bin
NY -> ugupako.bat -> C:\WINDOWS\ugupako.bat
NY -> meqybeno._dl -> C:\Program Files\Common Files\meqybeno._dl
NY -> edydanene.reg -> C:\Program Files\Common Files\edydanene.reg
NY -> jupikuzavi.reg -> C:\WINDOWS\jupikuzavi.reg
NY -> hygipato.vbs -> C:\WINDOWS\hygipato.vbs
NY -> wirulekoga.reg -> C:\WINDOWS\wirulekoga.reg
NY -> Security Tool.lnk -> C:\Documents and Settings\Owner\Desktop\Security Tool.lnk
NY -> mubegyp.lib -> C:\WINDOWS\System32\mubegyp.lib
NY -> jalyviku.sys -> C:\WINDOWS\System32\jalyviku.sys
NY -> qykady.com -> C:\WINDOWS\System32\qykady.com
NY -> apuzu.scr -> C:\Program Files\Common Files\apuzu.scr
NY -> fuzove.sys -> C:\Documents and Settings\All Users\Application Data\fuzove.sys
NY -> ruleqen.bat -> C:\WINDOWS\System32\ruleqen.bat
NY -> unumut.sys -> C:\WINDOWS\unumut.sys
NY -> yfepucolaf.dl -> C:\Program Files\Common Files\yfepucolaf.dl
NY -> ohasyfyr.ban -> C:\Documents and Settings\All Users\Application Data\ohasyfyr.ban
NY -> inojo.vbs -> C:\WINDOWS\System32\inojo.vbs
NY -> ewavoliz.pif -> C:\Documents and Settings\All Users\Application Data\ewavoliz.pif
NY -> wefehijyq.dll -> C:\WINDOWS\wefehijyq.dll
NY -> jugimotopi.inf -> C:\WINDOWS\jugimotopi.inf
NY -> aryzery.exe -> C:\Program Files\Common Files\aryzery.exe
NY -> uqudyxa.scr -> C:\WINDOWS\System32\uqudyxa.scr
NY -> ujehisum.bin -> C:\Documents and Settings\All Users\Application Data\ujehisum.bin
NY -> yvujihaqej.bat -> C:\Documents and Settings\All Users\Application Data\yvujihaqej.bat
NY -> Ogazisohahoze.bin -> C:\WINDOWS\Ogazisohahoze.bin
NY -> Ojicomucetuhese.dat -> C:\WINDOWS\Ojicomucetuhese.dat
NY -> restorer64_a.exe -> C:\WINDOWS\System32\restorer64_a.exe
NY -> vpg_bcsb.ini -> C:\WINDOWS\vpg_bcsb.ini
NY -> ijejaxakuqejako.dll -> C:\WINDOWS\ijejaxakuqejako.dll
[File - Lop Check]
NY -> 79964237 -> C:\Documents and Settings\All Users\Application Data\79964237
NY -> FunWebProducts -> C:\Documents and Settings\Edie\Application Data\FunWebProducts
[Empty Temp Folders]
The fix should only take a very short time during this you will lose your taskbar and it will ask for a reboot. When the fix is completed a message box will popup telling you that it is finished. Click the
Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.
I will review the information when it comes back in.
THEN Please download Malwarebytes' Anti-Malware from
Here.
Double Click mbam-setup.exe to install the application.
- Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
- The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
- Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.