Hello sohil,
This system is in really bad shape. You may want to back up your data and consider a reformat and reinstall.
Is your McAfee current?
Please copy this page to
Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.
***************************************************
1. Disconnect from the internet.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
---------------------------------------------------------------------
Open HijackThis and click on 'Do a System Scan Only'. 'Check' the following entries:
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {F70231A8-C197-496B-A3E5-CF62FB5C246C} - C:\PROGRA~1\bho\DIEMON~1.DLL
O4 - HKLM\..\Run: [psajvbfe] D;]XJOEPXT]tztufn43]Svoemm43/fyf!D;]XJOEPXT]tztufn43]deoqsi/emm!Tubsu
O4 - HKLM\..\Run: [upxdnd] C:\WINDOWS\upxdnd.exe
O4 - HKLM\..\Run: [TIMHost] C:\WINDOWS\TIMHost.exe
O4 - HKLM\..\RunOnce: [CPushSetup] "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files\Common Files\CPUSH\cpush.dll"
Click
'Fix Checked' and close HijackThis.
--------------------------------------------------------------------
Open
notepad and copy/paste the text in the quotebox below into it:
Quote:
File::
C:\WINDOWS\system32\lihawa.dll
C:\WINDOWS\system32\tszhyp.dll
C:\WINDOWS\system32\xsfshj.dll
C:\WINDOWS\system32\rwmvok.dll
C:\WINDOWS\system32\kilb.dll
C:\NTDETECT.EXE
C:\WINDOWS\system32\servet.exe
C:\WINDOWS\system32\mpyhku.dll
C:\WINDOWS\system32\ijefvh.dll
C:\WINDOWS\system32\vuemoe.dll
C:\WINDOWS\system32\gflyga.dll
C:\WINDOWS\system32\ldbpgc.dll
C:\WINDOWS\system32\dekugb.dll
C:\WINDOWS\TIMHost.exe
C:\WINDOWS\system32\TIMHost.dll
C:\WINDOWS\system32\drivers\mxdispdr.sys
C:\music\indi\MyFunCardsFWBInitialSetup1.0.0.15-3.exe
C:\Program Files\Internet Explorer\PLUGINS\SysWin64.Jmp
C:\WINDOWS\10d001.exe
C:\WINDOWS\d04.exe
C:\WINDOWS\upxdnd.exe
Folder::
c:\program files\bho
Driver::
vsadfg
WindowsDown
acvrsthe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{014A26F5-FBAD-4549-9CA1-C38210704BD1}"= -
"{C5E87A05-F463-4841-B19E-DD3EC3862368}"=-
"{A45B2C37-01D0-4D3E-BE5E-CC119B17BE9E}"=-
"{EE12D60D-AD9A-4095-B839-3BE6862679FD}"=-
[-hkey_current_user\software\MyWebSearch]
|
Save this as
CFScript.txt, in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at
C:\ComboFix.txt
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
--------------------------------------------------------------------
Please download
Dr.Web CureIT
Alternate Download Site
http://www.majorgeeks.com/Dr.Web_CureIT_d4783.html - Doubleclick the "drweb-cureit.exe" and click "OK" in the prompt window that will open.
- Then click "start the express scan now". It will first make a quick scan of your system so let it clean what it finds and when it says "done" click on the Green Screwdriver-ActionsTab, Adware-Dialers-Riskware-Hacktools and use dropdown menu and select "Delete"
- Click on the drive(s) you want to scan.
- A red dot * will mark the selected drive(s) then hit the green arrow in lower right corner.
- It will now scan your drive(s) so say YES to ALL.
---------------------------------------------------------------
Download
Deckard's System Scanner (DSS) to your
Desktop.
What DSS will do:
- create a new System Restore point in Windows XP and Vista.
- clean your Temporary Files, Downloaded Program Files, and Internet Cache Files, and also empty the Recycle Bin on all drives.
- check some important areas of your system and produce a report for your analyst to review.
- DSS automatically runs HijackThis for you, but it will also install and place a shortcut to HijackThis on your desktop if you do not already have HijackThis installed.
Note: You must be logged onto an account with administrator privileges.
- Close all applications and windows.
- Double-click on dss.exe to run it, and follow the prompts.
- When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt <-this one will be minimized
- Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt in your next reply.
- Please attach extra.txt to your post.
To attach a file to a new post, simply
- Click the[Manage Attachments] button under Additional Options > Attach Files on the post composition page, and
- copy and paste the following into the "Upload File from your Computer" box:
C:\Deckard\System Scanner\extra.txt
- Click Upload.
-----------------------------------------------------------------
Please include the following in your next reply:
C:\ComboFix.tx
DrWeb results
main.txt
an attached extra.txt
__________________
Member of ASAP since 2005
Member of UNITE since 2006
"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."