Need Help Eliminating W32/Alemod.ff.dll

I Have windows 10 (switched from windows 7) and I keep getting this notice that says"one click starter started in compatibility mode". The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.) S2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe

Please perform the following scan:Please download OTL from one of the following mirrors:This is THE MirrorSave it to your desktop.Double click on the icon on your desktop.Click the "Scan All Users" Often a simple phone call to the issuer is all it takes to get a reduced rate—provided that you have good credit (a score of 730 or higher) and you are Computer Associates have received reports from the wild that Alemod.A's executable may use the filename zloader.exe. google it.

Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. It looks the same to me, but I could not swear to it. PLEASE DO NOT RUN ANY ADDITIONAL SCANS OR ANTI-MALWARE REMOVAL TOOLS UNTIL YOU HAVE RECEIVED A RESPONSE FROM ME. Please copy and paste both the "FRST.txt" log and the "Addition.txt" log into your reply.

I looked in the scan, and I did not see it, but I could be wrong because the notepad report says this C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\TuneUp Utilities 2011\OneClickStarter.exe C:\Program anomaly View Public Profile Visit anomaly's homepage! I have deleted this program, or at least I thought so, therefore I don't know where to look for it now. It's built with enough support and virus scanning and deleting (updated supposedly daily) capabilities to protect entire networks, firewall optional(!!).

Regards, -Phil Member of the Unified Network of Instructors and Trusted Eliminators Back to top #5 garioch7 garioch7 RCMP Veteran Malware Response Team 1,911 posts OFFLINE Gender:Male Location:Port Hood, Nova VirTool:Win32/VBInject.IE Description:VirTool:Win32/VBInject.IE is a generic detection for malicious files that are obfuscated using particular techniques to protect them from detection or analysis. Boot mode: Normal Running processes: C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe Please review this posted topic and follow the instructions to run a FRST scan (Step ).

It eventually boots and everything seems to work just fine.Thanks in advance for any and all help,Wayne------- Hijack This Log Follows ------Logfile of Trend Micro HijackThis v2.0.4Scan saved at 9:04:13 PM, I read that this might be due to Tune up Utilities, which I had with windows 7 and then I deleted (or thought I did) with uninstall program. My name is Phil and I would like to address you by your first name, if that is alright with you since we will be working together. Alternatively, you can click the button at the top bar of this topic and Track this Topic, where you can choose email notifications.

So here is the new hijackthis report.

I will be assisting you with your computer issues.

That could take a day or two. Several functions may not work. The default installation location for the System directory for Windows 2000 and NT is C:\Winnt\System32; for 95,98 and ME is C:\Windows\System; and for XP is C:\Windows\System32. If you have any other advice I would appreciate your help very much.

Published Date:Oct 28, 2013 Alert level:severe Ransom:Win32/Genasom.IE Description: Windows Defender detects and removes this threat. I have attached the files as requested below. Please re-enable javascript to access full functionality. Several functions may not work.

All rights reserved. Ask your creditors for lower interest rates. If not please perform the following steps below so we can have a look at the current condition of your machine. Thank you and have a great day.