Alright, from the Panda log there are still some things which we can settle.
1) Click on Start, Run
2) Type MSCONFIG and press Enter
3) Click on the STARTUP tab
4) Look in the list for the following item:
Xupiter Toolbar
5) If this item is in the list. You have Xupiter installed. Uncheck it to temporarily disable the toolbar.
Next please follow the following instructions to remove FunWeb and MyWebSearch:
http://www.funwebproducts.com/uninstall.html
Then download
Look2Me-Destroyer to your desktop.
Before continuing with the fix there is something you must do:
- Click Start -> Run and type in: services.msc
- Check that the following services are running and that their startup is set to automatic:
- Seclogon, or Secondary logon service
- Next your machine needs to be offline, manually disconnect the network cable if necessary.
- Your antivirus, and every other security software MUST be disabled.
Now continue:
- Double-click Look2Me-Destroyer.exe to run it.
- Put a check next to Run this program as a task.
- You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 minute. Click OK
- When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
- Once it's done scanning, click the Remove L2M button.
- You will receive a Done Scanning message, click OK.
- When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
- Your computer will then shutdown.
- Turn your computer back on.
- Re-launch your Anti-virus/Firewall protection.
- Re-connect back to the internet.
If Look2Me-Destroyer does not reopen automatically, reboot and try again.
Download Avenger from here:
Swandog46’s Public Tools Page
Open the program. Check the 'Input script manually' option.
Click the Magnifying Glass icon.
In the box that opens, paste this:
Files to delete:
c:\windows\system\Popular Screensavers.scr
C:\WINDOWS\Favorites\Cool Stuff
C:\WINDOWS\Downloaded Program Files\pinstall.dll
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
C:\WINDOWS\Cookies\ @ad.yieldmanager[1].txt
C:\My Documents\Apps\AQ3-cla-Setup.exe
C:\My Documents\Apps\SmitfraudFix.zip
C:\My Documents\smitRem.exe
C:\unzipped\SmitfraudFix\SmitfraudFix\Process.exe
and click 'Done'
Click the Traffic Light icon to start the program, and OK the prompts to reboot your PC.
Post the Avenger output.txt (which you can find at C:\Avenger\.txt) and the contents of C:\
Look2Me-Destroyer.txt.