Sorry for cutting in but you need to fix this
Fix the above mentioned hijackthis entries
Download
win32delfkil.exe.
Save it on your desktop.
Double click on win32delfkil.exe and install it. This creates a new folder on your desktop: win32delfkil.
Close all windows, open the win32delfkil folder and double click on fix.bat.
The computer will reboot automatically.
Post the contents of the logfile
c\windelf.txt.
=====================================================
Run CFScript
Open
notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..
Pay particular attention to this :-
Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
File::
C:\WINDOWS\system32\dearnts.dll
C:\WINDOWS\system32\jolinos.dll
C:\WINDOWS\system32\rmbsony.dll
C:\WINDOWS\system32\xfimerl.dll
C:\WINDOWS\system32\siemous.dll
C:\WINDOWS\system32\hourpx2.dll
C:\WINDOWS\system32\offecao.dll
C:\WINDOWS\system32\zfexle.dll
C:\WINDOWS\system32\welyri.dll
C:\WINDOWS\system32\googlons.dll
C:\WINDOWS\system32\myusemt.dll
C:\WINDOWS\system32\2245GEZ6.dll
C:\WINDOWS\system32\tg0157b.ini
C:\WINDOWS\system32\tg0157a.ini
C:\WINDOWS\system32\2245JEZE.dll
C:\WINDOWS\tg0157c.ini
Folder::
C:\qoobox
C:\0000C44A
C:\00006021
C:\0000E455
C:\0000D4F3
C:\00006040
C:\000060CD
C:\00005FF2
C:\00005F08
C:\00005D91
C:\0000614A
C:\00005FC3
C:\00005E0E
C:\00006002
C:\0000607F
C:\000062FF
C:\00005F46
C:\00005D33
C:\0000DBE8
C:\00005D81
C:\0000613A
C:\0000F79E
C:\000061C7
C:\00005A55
C:\00005C87
C:\0000D30F
C:\00006801
C:\000083E5
C:\00007520
C:\00007927
Save this as
CFScript.txt
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
====================================================
Attach the combofix log
the windelf.txt log
and a new hijackthis log