Hi..
Have "Hijack This" fix all the following items in the list below by placing a check in the appropriate boxes.Confirm that you have only the listed ones checked, then press <Fix checked> and Close HJT.
O2 - BHO: (no name) - {1C044AAD-7955-4cbd-8175-501A165C4E5D} - C:\WINDOWS\System32\req.dat (file missing)
O2 - BHO: (no name) - {3BA7697A-CA45-71B4-8001-6D5505F17F37} - C:\WINDOWS\System32\ujcugu.dll (file missing)
O4 - HKLM\..\Run: [obadww] c:\windows\system32\obadww.exe
O4 - HKLM\..\Run: [Ndpdkq] C:\Program Files\Ppmbbrx\Klcmk.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O20 - Winlogon Notify: req - C:\WINDOWS\System32\req.dat (file missing)
Open Windows Explorer and delete the following highlighted file/s
Also delete the following red folder/s
c:\windows\system32\
obadww.exe
C:\Program Files\
Ppmbbrx\Klcmk.exe
Reboot......................
Please download, update and run the
A2 (A squared) anti-trojan. Let it fix whatever it wants to.
Anti-virus
Also, run this pc through the...
Panda Online virus scanner
or
Trend Micro Housecall Online virus scanner
Let it delete whatever it finds. If it cannot delete it, then post the log and we will delete it manually.
=============================================
Please download the trial version of/AVG Anti-Spyware 7.5
here:
http://www.ewido.net/en/download/
Install it, and update the definitions to the newest files.
Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml
Once in Safe Mode, please run AVG, and run a full scan. During the scan it will prompt you to clean files, click OK.
Save the logfile from the scan and post it here along with a new HJT log.