Please read this post completely before begining the fix. If there's anything that you do not understand, kindly ask your questions before proceeding.
Please ensure that there aren't any opened browsers when you are carrying out the procedures below. Save the following instructions in Notepad as this
webpage would not be available when you're carrying out the fix.
IT IS IMPORTANT THAT YOU DON'T MISS A STEP & PERFORM EVERYTHING IN THE RIGHT ORDER.
----------------------------------------
Regarding ComboFix: You posted ComboFix2.txt and ComboFix3.txt. Please see if you can find Combofix.txt and post that
----------------------------------------
DISABLE ANTI-SPYWARE APPLICATIONS
Please disable these Anti-Spyware programs as they may interfere with this fix. You may re-enable them after we clean your system.
Microsoft AntiSpyware
- Right click the Microsoft AntiSpyware icon located in the system tray
- Click on Security Agents Status (Enabled)
- Click on Disable Real-time Protection
----------------------------------------
FIXES AND DELETIONS
REMOVING PURITY SCAN
- First, click Start > Control Panel > Add/Remove Programs
- In the list of installed software, look for
- Oin
- Yazzle by Oin
- Purityscan by Oin
- Snowballwars by Oin
- Cowabanga by OIN
- or anything similar with Oin in it
- If you find it:
- Click on it and click Remove.
----------------------------------------
Download the attached
wyr.zip file at the bottom of this post to your desktop. Double click on the zip folder,
then double click on the .reg file within.
Click
yes to allow it to merge into your registry.
----------------------------------------
Go to
Control Panel click Display>Desktop>Customize Desktop>Website
Under the 'Web pages' box, delete everything present
----------------------------------------
Delete the following Files indicated in
RED and Folders indicated in
BLUE if they still exist.
C:\WINDOWS\SYSTEM32\KBDons.dll
C:\WINDOWS\SYSTEM32\winpfg32.sys
C:\WINDOWS\jivzheh.exe
C:\Program Files\Common Files\Yazzle1281OinUninstaller.exe
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Windows NT\hocycosyp.html
C:\Program Files\ComPlus Applications\kyfefyv.html
RAVMOND.exe>>>
Find via Start>>Search
----------------------------------------
ON-LINE SCANS
Kaspersky - Extended
Establish an internet connection & perform an online scan with Internet Explorer at
Kaspersky Online Scanner
Answer Yes, when prompted to install an ActiveX component.
- The program will then begin downloading the latest definition files.
- Once the files have been downloaded click on NEXT
- Locate the Scan Settings button & configure to:
- Scan using the following Anti-Virus database:
- Scan Options:
- Scan Archives
- Scan Mail Bases
- Click OK & have it scan My Computer
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect.
We only require a report from it.
- Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
* Turn off the real time scanner of any existing antivirus program while performing the online scan
----------------------------------------
FOLLOW-UP
Please return and post these items:
Fresh comboFix log
Kaspersky log
A new HJT log run in Normal Mode
Please note: In order to properly see what is on your system, all HJT logs must be run in the normal mode