Hi,
Download the attached "
Combofix-Do.txt" (
from my attachment) and save it to the same folder as Combofix.
Have HijackThis fix the following entries:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 0
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {166E2FE3-E93B-4AE9-AA6E-893C4D4B13FC} - (no file)
O2 - BHO: (no name) - {3536011A-9BCC-480C-B11D-125D5F684BC3} - C:\WINDOWS\system32\uojwporh.dll (file missing)
O2 - BHO: (no name) - {7E40D0DC-03DB-4320-BDEF-1A78F913D316} - (no file)
O2 - BHO: (no name) - {9581FE9A-7316-4F69-8C22-D458BFD28DF3} - (no file)
O2 - BHO: (no name) - {B1629B02-B58F-4F3E-845E-1EFCEB9EC4BD} - (no file)
O2 - BHO: (no name) - {C749B1A2-7863-49D2-9636-A7ABFC57E139} - C:\WINDOWS\system32\sstqo.dll (file missing)
O2 - BHO: (no name) - {EF0613E6-50E2-495D-AFD3-171BACE68636} - (no file)
O4 - Global Startup: NETGEAR WG111T Smart Wizard.lnk = ?
O20 - Winlogon Notify: ddccd - C:\WINDOWS\system32\ddccd.dll (file missing)
O20 - Winlogon Notify: gebcb - C:\WINDOWS\system32\gebcb.dll (file missing)
O20 - Winlogon Notify: geebx - C:\WINDOWS\system32\geebx.dll (file missing)
O20 - Winlogon Notify: jkkjh - C:\WINDOWS\system32\jkkjh.dll (file missing)
O20 - Winlogon Notify: sstqp - C:\WINDOWS\system32\sstqp.dll (file missing)
Close HijackThis.
Now go to you combofix folder (where you saved combofix-do.txt) and drag the
Combofix-Do.txt over on to
Combofix.exe and release.
This will ask Combofix to execute the instructions within my file.
Let Combofix run normally and do its job.
Thereafter, please post fresh HJT and ComboFix logs from normal mode as attachments into this thread.
Regards,
Your friendly momok =)
This thread is for the use of metalhead2025 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.