We need to delete a service first.
open Notepad, then copy the codes belows in the quote box:
@echo off
sc stop "avg8emc"
sc delete "avg8emc"
sc stop "avg8wd"
sc delete "avg8wd"
del service.cmd and exit
then paste them into the notepad file, name the file
fix.cmd and change the "Save as Type" to
"All File", then save it to your desktop.
Locate the file you just created on the desktop, and double-click to run it.
ok can you post the MBAM log and the SAS log
open hijackthis and place a check next to the item below
O2 - BHO: (no name) - {4F549932-AA0A-43B0-92BF-610AFE73FAB7} - C:\WINDOWS\system32\opnooNeE.dll (file missing)
O2 - BHO: (no name) - {833AE189-F38C-46B6-B02A-18DBEBB50349} - C:\WINDOWS\system32\byXPHbBQ.dll (file missing)
O2 - BHO: (no name) - {E126805E-4A10-49B5-86AB-741286A4B7DA} - C:\WINDOWS\system32\efccBQHy.dll (file missing)
O2 - BHO: (no name) - {ED71602F-B2F6-470F-943F-0DA300E034D8} - C:\WINDOWS\system32\opnlIayw.dll (file missing)
O4 - HKLM\..\Run: [BMe70b46b9] Rundll32.exe "C:\WINDOWS\system32\nahrdlon.dll",s
O4 - HKLM\..\Run: [e4387525] rundll32.exe "C:\WINDOWS\system32\pabmlxke.dll",b
O4 - HKCU\..\Run: [01117964667348514065999782645839] C:\Program Files\Antivirus 2009\av2009.exe
O4 - Startup: Deewoo.lnk = C:\WINDOWS\system32\qcntotdm.exe
O4 - Startup: DW_Start.lnk = C:\WINDOWS\system32\rrwnw64p.exe
O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - D:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O20 - Winlogon Notify: byXPHbBQ - byXPHbBQ.dll (file missing)
O20 - Winlogon Notify: fccdecab - fccdecab.dll (file missing)
O20 - Winlogon Notify: opnlIayw - opnlIayw.dll (file missing)
then click on fix items now close hijackthis and reboot into safe mode you can do this by rebooting then start taping the F8 then select safe mode
uninstall the software be low
Antivirus 2009
PartyGaming
Please
download the
OTMoveIt2 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator")
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighb
Code:
C:\WINDOWS\system32\nahrdlon.dll
C:\WINDOWS\system32\pabmlxke.dll
C:\Program Files\Antivirus 2009
C:\WINDOWS\system32\qcntotdm.exe
C:\WINDOWS\system32\rrwnw64p.exe
- Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the light Yellow bar) and choose Paste.
- Click the red Moveit! button.
- A log of files and folders moved will be created in the c:\_OTMoveIt\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please attach the contents in your next reply.
- Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes.
then post a fresh hijackthis log