Left Drag mouse and Copy for Pasting all text in the box below. Make sure the slider bar goes to bottom from the @ to the end of the second exit.
Then paste to the black screen of an open command prompt. All may not apply so ignore errors.
Code:
@echo off
cd\
:: Fix associations
ftype exefile="%1" %*
ftype batfile="%1" %*
ftype cmdfile="%1" %*
ftype comfile="%1" %*
ftype scrfile="%1" /S
ftype regfile="regedit.exe" "%1"
ftype piffile="%1" %*
ftype inffile=%SystemRoot%\System32\NOTEPAD.EXE "%1"
ftype vbsfile=%SystemRoot%\System32\WScript.exe "%1" %*
ftype jsfile=%SystemRoot%\System32\WScript.exe "%1" %*
assoc .exe=exefile
assoc .bat=batfile
assoc .cmd=cmdfile
assoc .com=comfile
assoc .scr=scrfile
assoc .reg=regfile
assoc .pif=piffile
assoc .lnk=lnkfile
assoc .inf=inffile
assoc .vbs=VBSFile
assoc .js=JSFile
sc stop TDSSserv.sys
sc delete TDSSserv.sys
sc stop Service_TDSSserv.sys
sc delete Service_TDSSserv.sys
sc stop Legacy_TDSSSERV.SYS
sc delete Legacy_TDSSSERV.SYS
Attrib -h -s -r /s c:\tdss*.*
del /f /q /s c:\tdss*.*
Attrib -h -s -r /s "c:\Legacy_*.*"
del /f /q /s tdss*.* "c:\Legacy_*.*"
reg unload "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata"
reg unload "HKEY_LOCAL_MACHINE\SOFTWARE\tdss"
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata" /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\tdss" /f
attrib -h -s -r c:\WINDOWS\system32\ieupdates.exe
del /f /q c:\WINDOWS\system32\ieupdates.exe
attrib -h -s -r c:\WINDOWS\system32\scui.cpl
del /f /q c:\WINDOWS\system32\scui.cpl
attrib -h -s -r c:\WINDOWS\system32\winsrc.dll
del /f /q c:\WINDOWS\system32\winsrc.dll
attrib -h -s -r /s c:\xwdxqu.txt
del /f /q /s c:\xwdxqu.txt
attrib -h -s -r c:\windows\x
del /f /q c:\windows\x
attrib -h -s -r /s "c:\SxsCaPendDel*.*"
del /f /q /s "c:\SxsCaPendDel*.*"
attrib -h -s -r /s c:\h3s.sys
del /f /q /s c:\qh3s.sys
attrib -h -s -r /s c:\jsdpp32.sys
del /f /q /s c:\jsdpp32.sys
attrib -h -s -r /s c:\oxauau96.sys
del /f /q /s c:\oxauau96.sys
reg delete HKLM\SOFTWARE\swearware /f
reg delete HKCU\Software\Wget /f
reg delete HKLM\Software\Classes\CLSID\{CD363BEC-7150-B887-530D-F3E2E0424EA} /f
sc stop gaopdxserv.sys
sc delete gaopdxserv.sys
attrib -h -s -r /s c:\gaopdx*.*
del /f /q /s c:\gaopdx*.*
reg delete "HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gaopdxserv.sys" /f
reg delete "HKEY_LOCAL_MACHINE\System\ControlSet001\Services\gaopdxserv.sys" /f
reg delete "HKEY_LOCAL_MACHINE\Software\Classes\gaopdxvx" /f
sc stop Service_UACd.sys
sc delete Service_UACd.sys
attrib -h -s -r /s "c:\Service_UACd*.*"
del /f /q /s "c:\Service_UACd*.*"
attrib -h -s -r "c:\program files\Common Files\System\Uninstall*.*"
del /f /q "c:\program files\Common Files\System\Uninstall*.*"
rd /s /q "c:\program files\Common Files\System\Uninstall"
attrib -h -s -r /s "c:\PlayMP3z*.*"
del /f /q /s "c:\PlayMP3z*.*"
rd /s /q "c:\program files\PlayMP3z"
sc stop UACkdqxyyms.sys
sc delete UACkdqxyyms.sys
attrib -h -s -r /s "c:\UAC????????.sys"
del /f /q /s "c:\UAC????????.sys"
attrib -h -s -r /s "c:\uacinit.dll"
del /f /q /s "c:\uacinit.dll"
attrib -h -s -r c:\documents and settings\NetworkService\Application Data\.rdr.ini
del /f /q c:\documents and settings\NetworkService\Application Data\.rdr.ini
attrib -h -s -r c:\documents and settings\NetworkService\Application Data\install.dat
del /f /q c:\documents and settings\NetworkService\Application Data\install.dat
attrib -h -s -r "c:\windows\system32\f06WtR"
del /f /q "c:\windows\system32\f06WtR"
attrib -h -s -r c:\windows\system32\ntnet.drv
del /f /q c:\windows\system32\ntnet.drv
attrib -h -s -r "c:\windows\system32\W70MLRES.DLL"
del /f /q "c:\windows\system32\W70MLRES.DLL"
attrib -h -s -r "c:\windows\system32\dumphive.exe"
del /f /q "c:\windows\system32\dumphive.exe"
attrib -h -s -r "c:\windows\system32\IEDFix.exe"
del /f /q "c:\windows\system32\IEDFix.exe"
attrib -h -s -r "c:\windows\system32\Process.exe"
del /f /q "c:\windows\system32\Process.exe"
attrib -h -s -r "c:\windows\system32\SrchSTS.exe"
del /f /q "c:\windows\system32\SrchSTS.exe"
attrib -h -s -r "c:\windows\system32\VACFix.exe"
del /f /q "c:\windows\system32\VACFix.exe"
attrib -h -s -r "c:\windows\system32\VCCLSID.exe"
del /f /q "c:\windows\system32\VCCLSID.exe"
attrib -h -s -r "c:\windows\system32\WS2Fix.exe"
del /f /q "c:\windows\system32\WS2Fix.exe"
attrib -h -s -r "c:\windows\patch.exe"
del /f /q "c:\windows\patch.exe"
attrib -h -s -r "c:\windows\Readme.txt"
del /f /q "c:\windows\Readme.txt"
attrib -h -s -r "c:\windows\system32\apiri32.dll"
del /f /q "c:\windows\system32\apiri32.dll"
attrib -h -s -r "c:\windows\system32\crrh32.exe"
del /f /q "c:\windows\system32\crrh32.exe"
attrib -h -s -r "c:\windows\system32\d3im32.exe"
del /f /q "c:\windows\system32\d3im32.exe"
attrib -h -s -r "c:\windows\system32\deuau.dll"
del /f /q "c:\windows\system32\deuau.dll"
attrib -h -s -r "c:\windows\system32\fsszd.dll"
del /f /q "c:\windows\system32\fsszd.dll"
attrib -h -s -r "c:\windows\system32\iecw.exe"
del /f /q "c:\windows\system32\iecw.exe"
attrib -h -s -r "c:\windows\system32\ievd32.dll"
del /f /q "c:\windows\system32\ievd32.dll"
attrib -h -s -r "c:\windows\system32\iezj.exe"
del /f /q "c:\windows\system32\iezj.exe"
attrib -h -s -r "c:\windows\system32\ipiz.exe"
del /f /q "c:\windows\system32\ipiz.exe"
attrib -h -s -r "c:\windows\system32\javach.exe"
del /f /q "c:\windows\system32\javach.exe"
attrib -h -s -r "c:\windows\system32\jzimv.dll"
del /f /q "c:\windows\system32\jzimv.dll"
attrib -h -s -r "c:\windows\system32\klieq.dll"
del /f /q "c:\windows\system32\klieq.dll"
attrib -h -s -r "c:\windows\system32\mfcib32.exe"
del /f /q "c:\windows\system32\mfcib32.exe"
attrib -h -s -r "c:\windows\system32\nths.dll"
del /f /q "c:\windows\system32\nths.dll"
attrib -h -s -r "c:\windows\system32\ntzy32.exe"
del /f /q "c:\windows\system32\ntzy32.exe"
attrib -h -s -r "c:\windows\system32\sdkhq.exe"
del /f /q "c:\windows\system32\sdkhq.exe"
attrib -h -s -r "c:\windows\system32\sdkqw32.exe"
del /f /q "c:\windows\system32\sdkqw32.exe"
attrib -h -s -r "c:\windows\system32\sdkxu.exe"
del /f /q "c:\windows\system32\sdkxu.exe"
attrib -h -s -r "c:\windows\system32\sysgr.exe"
del /f /q "c:\windows\system32\sysgr.exe"
attrib -h -s -r "c:\windows\system32\windows.scr"
del /f /q "c:\windows\system32\windows.scr"
sc stop WinSvchostManager
sc delete WinSvchostManager
attrib -h -s -r /s "C:\WinSvcHostmanager*.*"
del /f /q /s "C:\WinSvcHostmanager*.*"
sc stop ntndis
sc delete ntndis
attrib -h -s -r /s C:\ntndis.*
del /f /q /s C:\ntndis.*
sc stop u_lehj
sc delete u_lehj
attrib -h -s -r /s "c:\\u_lehj32*.*"
del /f /q /s "c:\u_lehj32.*.*"
net stop Legacy_SECURITY
attrib -h -s -r /s "c:\Legacy_SECURITY*.*"
del /f /q /s c:\Legacy_SECURITY*.*"
sc stop Service_SECURITY
sc delete Service_SECURITY
attrib -h -s -r /s "c:\Service_SECURITY*.*"
del /f /q /s c:\Service_SECURITY*.*"
attrib -h -s -r /s c:\svcprs32.exe
del /f /q /s c:\svcprs32.exe
attrib -h -s -r /s c:\wmdrtc32.dll
del /f /q /s c:\wmdrtc32.dll
attrib -h -s -r "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe"
del /f /q "C:\Documents and Settings\All Users\Start Menu\Programs\Startup\dllhost.exe"
attrib -h -s -r "C:\WINDOWS\system32\mdmcls32.exe"
del /f /q "C:\WINDOWS\system32\mdmcls32.exe"
attrib -h -s -r /s c:\ebkp*.*
del /f /q /s c:\ebkp*.*
:: AV2009
attrib -h -s -r "%UserProfile%\Desktop\Antivirus 2009.lnk"
attrib -h -s -r "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk"
attrib -h -s -r "%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\S96PZM7V\winsrc[1].dll"
attrib -h -s -r "%UserProfile%\Start Menu\Antivirus 2009\*.*"
del /f /q "%UserProfile%\Desktop\Antivirus 2009.lnk"
del /f /q "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus 2009.lnk"
del /f /q "%UserProfile%\Local Settings\Temporary Internet Files\Content.IE5\S96PZM7V\winsrc[1].dll"
del /f /q "%UserProfile%\Start Menu\Antivirus 2009\*.*"
rd /s /q "%UserProfile%\Start Menu\Antivirus 2009"
attrib -h -s -r "c:\Program Files\Antivirus 2009\*.*"
rd /s/q "c:\Program Files\Antivirus 2009"
reg delete "HKEY_CURRENT_USER\Software\75319611769193918898704537500611" /f
reg delete "HKEY_CLASSES_ROOT\CLSID\{037C7B8A-151A-49E6-BAED-CC05FCB50328}" /f
reg delete "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{037C7B8A-151A-49E6-BAED-CC05FCB50328}" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" "75319611769193918898704537500611" /f
reg delete "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run" "ieupdate" /f
echo Finshed AV2008-9
:: Fix associations
ftype exefile="%1" %*
ftype batfile="%1" %*
ftype cmdfile="%1" %*
ftype comfile="%1" %*
ftype scrfile="%1" /S
ftype regfile="regedit.exe" "%1"
ftype piffile="%1" %*
ftype inffile=%SystemRoot%\System32\NOTEPAD.EXE "%1"
ftype vbsfile=%SystemRoot%\System32\WScript.exe "%1" %*
ftype jsfile=%SystemRoot%\System32\WScript.exe "%1" %*
assoc .exe=exefile
assoc .bat=batfile
assoc .cmd=cmdfile
assoc .com=comfile
assoc .scr=scrfile
assoc .reg=regfile
assoc .pif=piffile
assoc .lnk=lnkfile
assoc .inf=inffile
assoc .vbs=VBSFile
assoc .js=JSFile
exit
exit
This should run and exit!
It is a coverall and you may see a few errors related to it addressing something you do not need. This is normal ignore.
When above finished continue below
Run both MBAM and SAS again Quick scan, as they had found/removed items and could find more. We need a clean log.
Post both new logs and a new HJT log.
Mike