dan12
Hi JacKNight
Just a few things to tidy up from the returned logs.
Download the Killbox.
Unzip it to the desktop we will use it soon.
__________________
Copy/paste the following text into a new Notepad document. (You must use Notepad, NOT Wordpad). Make sure that you have NO blank lines at the beginning of the document before REGEDIT4, and ONE blank line at the end of the document as shown in the quoted text:
Save it to your desktop as Fixme.reg. Save it as follows…
File Type: "All Files" (not as a text document or it wont work).
Name: Fixme.reg
________________________
Re-boot into safe mode once more
Locate Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the merged successfully prompt.
________________
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O4 - HKLM\..\Run: [vthejt] C:\WINDOWS\system32\wcdmjv.exe reg_run
O4 - HKCU\..\Run: [spngk] C:\WINDOWS\system32\wcdmjv.exe reg_run
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:
C:\WINDOWS\system32\0q1wzbn.dll < This file
C:\WINDOWS\system32\h70n4m5p.ini < This file
C:\WINDOWS\system32\ltykotzp.exe < This file
___________________
Double-click Killbox.exe to run it.
Select "Delete on Reboot".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:
C:\WINDOWS\system32\wcdmjv.exe
Put a mark next to "Delete on Reboot"
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.
__________________
Now I would like you to reset your system restore points by following the instructions set out below
1) On the Desktop, right-click My Computer
2) Click on Properties. Click the System Restore tab.
3) Look for the box near the top which says
Turn off system restore off on all drives
4) Place a tick in the box to disable
5) Click Apply first, and then click OK and the window will dissapear.
Now reboot your computer….
6) Right-click My Computer once more
7) Click on Properties. Click the System Restore tab again
8) Look for the box near the top which says
Turn off system restore off on all drives
9)Take out the tick from the box so it is empty
10) Click Apply first, and then click OK.
Now restart your computer once more to complete the process
Please post a new HJT log and can you tell me how your machine is running.
Thanks dan
Just a few things to tidy up from the returned logs.
Download the Killbox.
Unzip it to the desktop we will use it soon.
__________________
Copy/paste the following text into a new Notepad document. (You must use Notepad, NOT Wordpad). Make sure that you have NO blank lines at the beginning of the document before REGEDIT4, and ONE blank line at the end of the document as shown in the quoted text:
REGEDIT4 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Hdyj"=- "roqq"=- "spngk"=- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "vthejt"=-
Save it to your desktop as Fixme.reg. Save it as follows…
File Type: "All Files" (not as a text document or it wont work).
Name: Fixme.reg
________________________
Re-boot into safe mode once more
- Next, please reboot your computer in Safe Mode by doing the following:
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
- Instead of Windows loading as normal, a menu should appear use arrow up to highlight
- Select the first option, to run Windows in Safe Mode hit enter.
- For additional help in booting into Safe Mode, see the following site: HERE
Locate Fixme.reg on your desktop and double-click it. When asked if you want to merge with the registry, click YES. Wait for the merged successfully prompt.
________________
Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O4 - HKLM\..\Run: [vthejt] C:\WINDOWS\system32\wcdmjv.exe reg_run
O4 - HKCU\..\Run: [spngk] C:\WINDOWS\system32\wcdmjv.exe reg_run
WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit
Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:
C:\WINDOWS\system32\0q1wzbn.dll < This file
C:\WINDOWS\system32\h70n4m5p.ini < This file
C:\WINDOWS\system32\ltykotzp.exe < This file
___________________
Double-click Killbox.exe to run it.
Select "Delete on Reboot".
Place the following line (complete path) in bold in the "Full Path of File to Delete" box in Killbox:
C:\WINDOWS\system32\wcdmjv.exe
Put a mark next to "Delete on Reboot"
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.
If your computer does not restart automatically, please restart it manually.
__________________
Now I would like you to reset your system restore points by following the instructions set out below
1) On the Desktop, right-click My Computer
2) Click on Properties. Click the System Restore tab.
3) Look for the box near the top which says
Turn off system restore off on all drives
4) Place a tick in the box to disable
5) Click Apply first, and then click OK and the window will dissapear.
Now reboot your computer….
6) Right-click My Computer once more
7) Click on Properties. Click the System Restore tab again
8) Look for the box near the top which says
Turn off system restore off on all drives
9)Take out the tick from the box so it is empty
10) Click Apply first, and then click OK.
Now restart your computer once more to complete the process
Please post a new HJT log and can you tell me how your machine is running.
Thanks dan