Since it has been greatly enhanced my script has gotten to big for a copy/paste so I have put it out to be downloaded.
So go here and download to Desktop then double click it to run it, then click OK to self extract.
Once extracted dbl click to enter Fixer folder. To run it 1st double click Daft click scan and check any found items and click fix.
The just dbl click Fixit.cmd to run it (no copy/paste).
But boot to Safe mode and run it!
Get it here:
http://www.adrive.com/public/97c4357781f45c7e443061094b8cfaff3836f57446eb242ab2ee0b6cd68a0107.html
Only after it has been run the MBAM Quick scan has been run and you have posted the MBAM log. Only then do the below.
Download ComboFix
Get it here:
https://www.techspot.com/downloads/5587-combofix.html
Or here:
http://subs.geekstogo.com/ComboFix.exe
Double click combofix.exe follow the prompts.
Install Recovery Console if connected to the Internet!
When finished, it will open a log.
Attach the log and a new HJT log in your next reply.
Note: Do not click combofix's window while its running. That may cause it to stall.
=========================================
Download SDFix to Desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe
On Desktop run SDdFix It will run (install) then close.
Then reboot into Safe Mode
As the computer starts up, tap the F8 key several times.
On the Boot menu Choose Safe Mode.
Click thu all the prompts to get to desktop.
At Desktop
My Computer C: drive. Double-click to open.
Look for a folder called SD Fix. Double-click to enter SD Fix.
Double-click to RunThis.bat. Type Y to begin.
SD Fix does its job.
When prompted hit the enter key to restart the computer
Your computer will reboot.
On normal restart the Fixtool will run again and complete the removal process then say Finished,
Hit the Enter key to end the script and load your desktop icons.
Once the desktop is up, the SDFix report will open on screen and also be saved to the SDFix folder as Report.txt.
Attach the Report.txt file to your next post.
Mike
EDIT:
Run HJT Scan only and select and Fix all lines listed below
Any line that has (file missing) and/or (no file) at the END of the line, ONLY at the end.
And these..
O4 - HKUS\S-1-5-19\..\Run: [kofefasuzi] Rundll32.exe "C:\WINDOWS\system32\fuzoyalu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [kofefasuzi] Rundll32.exe "C:\WINDOWS\system32\fuzoyalu.dll",s (User 'NETWORK SERVICE')
O20 - AppInit_DLLs: ifboxw.dll c:\windows\system32\kalulana.dll kqocsm.dll c:\windows\system32\rawomuba.dll
Mike