tonym209,
It is very important to complete the steps in the exact order as they are given.
Also, please provide the logs requested as this is the only way for me to determine what neeeds to be fixed.
If the log doesn't exist or wasn't created please let me know this also.
- - - - - Next - - - - -
1. Close any open browsers.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
3. Open notepad and copy/paste the text in the quote box below into it:
File::
c:\windows\system32\gojajado.dll.zip
c:\windows\system32\gojajado.dll.tmp
c:\windows\isRS-000.tmp
c:\windows\system32\BIT1E4.tmp
c:\windows\system32\BIT1E5.tmp
c:\windows\system32\xa.tmp
c:\windows\system32\gehudehe.dll
c:\windows\system32\davafuhu.dll
c:\windows\system32\rotirufe.dll
c:\windows\system32\joseloho.dll
c:\windows\system32\feboyonu.dll
c:\windows\system32\yekenize.dll
c:\windows\system32\nudewolu.dll
c:\windows\system32\munuropi.dll
c:\windows\system32\hebebubo.dll
c:\windows\system32\mirupuho.dll
c:\windows\system32\dukemido.dl
c:\windows\system32\ronigofu.dll
c:\windows\system32\losiluso.dll
c:\windows\system32\betifupu.dll
c:\windows\system32\dogubina.dll
c:\windows\system32\firovopa.dll
c:\windows\system32\vopugoke.dll
c:\windows\system32\banewelu.dll
c:\windows\system32\bonipola.dll
c:\windows\system32\dezifamu.dll
c:\windows\system32\jatipife.dll
c:\windows\system32\ripagupa.dll
Folder::
c:\documents and settings\All Users\Application Data\17866404
C:\Program Files\Viewpoint\
Registry::
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8fc99202-224f-4666-b16f-805fd53dc23a}]
[-HKEY_CLASSES_ROOT\CLSID\{8fc99202-224f-4666-b16f-805fd53dc23a}]
[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5366673-E8CA-11D3-9CD9-0090271D075B}]
[-HKEY_CLASSES_ROOT\CLSID\{A5366673-E8CA-11D3-9CD9-0090271D075B}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7"=-
[-HKEY_CLASSES_ROOT\CLSID\{71B6ACF7-4F0F-4FD8-BB69-6D1A4D271CB7}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CPM2f592ec1"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"netivuwuwe"=-
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"netivuwuwe"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{B8111CD6-49A3-4B0F-9F01-0041CEC2DCDB}]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{FD7EEB46-63C8-4CAE-90E0-E012BF0A99F2}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppinitDLLs"=""
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\ShellServiceObjectDelayLoad]
"EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4"=-
[-HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}]
[-HKEY_CLASSES_ROOT\CLSID\{EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4}\InProcServer32]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4"=-
[-HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4}]
[-HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4}\InProcServer32]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Notification Packages"=hex(7):73,63,65,63,6c,69,00,00
Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe
[external image: Posted Image]
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
- - - - - Next - - - - -
Reboot
- - - - - Next - - - - -
Please re-run DDS
- Disable any script blocking protection (How to Disable your Security Programs)
- Double click DDS icon to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
On your next post please provide the following:
- ComboFix.txt
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.