Did you delete the folder - C:\QooBox ?

There were a ton of infected files there. It's puzzling why Kaspersky didn't detect any from there.


--------



Open NOTEPAD.exe and copy/paste the text in the quotebox below into it:

Code:
@echo off
if exist "%temp%\log.txt" del "%temp%\log.txt"

for %%g in (
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-13F4B4C78199D4682"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-13FAA3AE144846B5B"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-13FB24381D0E1290"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-13FFB53AB335F631C"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-140803F5C6026752E"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-140A47CF32DB118"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-143DA40363D666E10"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-144765B502DC71FE1"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-144CF652E3A636358"
"C:\Documents and Settings\All Users\Application Data\Authentium\Curtains150\prf\3FyIifGQQQKq\VirusBin\Infected-ACCB240D1EE312B0"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\MalwareAlarm.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NNCMGRS.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NNCMGRS1.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NNCMGRS2.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NNCMGRS3.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NNCMGRS4.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NNCMGRS5.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NousTechUCleaner.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NousTechUCleaner1.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\NousTechUDefender.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumonde1.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack1.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack3.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack4.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack6.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack7.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\VirtumondeCrack8.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondegeneric2.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinBHOje.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinInjectbw.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinInjectbw1.zip"
"C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinQhostabh.zip"
"C:\WINDOWS\Downloaded Program Files\SbCIe02b.dll"
"C:\WINDOWS\system32\in5bCs.dll"
"C:\WINDOWS\system32\drivers\etc\HOSTS.bak"
"C:\WINDOWS\ywgqpzd.exe"
) do (
del /a/f/q %%g >nul 2>&1
if exist %%g echo.%%~g>>"%temp%\log.txt"
)
for %%g in (
"%systemdrive%\VundoFix Backups"
%systemdrive%\Deckard
%systemdrive%\Qoobox
) do (
rd /s/q %%g >nul 2>&1
if exist %%g echo.%%~g>>"%temp%\log.txt"
)
if exist "%temp%\log.txt" ( start notepad "%temp%\log.txt"
) else echo.Deleted Successfully !!
nircmd wait 7000
del %0
Save this as fix.bat Choose to "Save type as - All Files"
It should look like this:
Double click on fix.bat & allow it to run

Post back to tell me what it says



----------


I noted certain things when reviewing your log. I have a question that bears asking. Do you visit crack sites?