do you recognize this folder created yesterday - I will assume you do and leave it be, but please let me know if you don't
C:\ijji
-----------------------------------------------------------------------
Open
notepad and copy and paste next bold in it:
reg query "HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon" >> C:\look.txt
Save this as
look.bat , choose to save as *
all files and place it on your desktop.
It should look like this on your desktop:
Doubleclick look.bat
Notepad will open with some txt in it. Copy and paste the contents in your next reply.
-------------------------------------------------------------------------
Disable Teatimer
- Right click the Spybot -SD Resident Icon located in your system tray, Select Exit Spybot - S&D Resident
- Open Spybot S&D
- Click on Mode at the top and make sure that Advanced is checked
- Expand the Tools tab in the left pane
- Single click on the Resident Icon also in the left pane
- Uncheck Resident "TeaTimer" (Protection of over-all system settings) Active
- Close spybot
-------------------------------------------------------------------------
Run CFScript
Open
notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..
Pay particular attention to this :-
Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
File::
C:\WINDOWS\system32\kypdgjue.dll.vir
C:\WINDOWS\system32\ucqpxqan.dll.vir
C:\WINDOWS\system32\kigympvm.dll.vir
C:\WINDOWS\system32\dscraexk.dll.vir
C:\WINDOWS\system32\nnnmkJde.dll.vir
C:\WINDOWS\system32\mlJCULee.dll.vir
C:\WINDOWS\system32\mlJCULee.dll
C:\WINDOWS\system32\nnnmkJde.dll
C:\WINDOWS\system32\hgGabcdD.dll
C:\WINDOWS\system32\dwsykqru.ini
C:\WINDOWS\system32\dscraexk.dll
C:\WINDOWS\system32\kypdgjue.dll
C:\WINDOWS\system32\kigympvm.dll
C:\WINDOWS\system32\ybjixxjq.dll
C:\WINDOWS\system32\ucqpxqan.dll
C:\WINDOWS\system32\eswrihqx.tmp
C:\WINDOWS\system32\hgGabcdD.dll
Folder::
C:\Documents and Settings\All Users\Application Data\Viewpoint
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C5E84927-CFF0-4CA3-A068-02E7C01C1E7C}]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{C5E84927-CFF0-4CA3-A068-02E7C01C1E7C}"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\hgGabcdD]
Save this as
CFScript.txt
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.