Hi avwonder,
Please download DeFogger to your desktop.
Double click DeFogger to run the tool.
[*] The application window will appear
[*] Click the Disable button to disable your CD Emulation drivers.
[*] Click Yes to continue
[*] A ‘Finished!’ message will appear
[*] Click OK
[*] DeFogger will now ask to reboot the machine - click OK
Do not re-enable these drivers until otherwise instructed.
.
We’ll restore that file.
First, locate kittyfix.exe on your desktop, right click it and select delete.
Download a new copy from either link and save it to your desktop. But Do Not run it. We will run it differently.
Link 1
Link 2
* IMPORTANT !!! Save ComboFix.exe to your Desktop
[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
Open a new Notepad session
[*]Click the Start button, click run
[*]in the run box type notepad
[*]click ok
[*]In the notepad, Click “Format” and be certain that Word Wrap is not checked.
[*]Copy and paste all the text in the code box below into the Notepad. Do Not copy the word CODE
DEQUARANTINE::
C:\Qoobox\Quarantine\C\windows\system32\69D804C66D.dll.vir
RootKit::
c:\windows\system32\tdlclk.dll
c:\windows\system32\tdlcmd.dll
In the notepad
[*]Click File, Save as…, and set the Save in to your Desktop
[*]In the filename box, type (including quotation marks) as the filename: “CFScript.txt”
[*]Click save
Using your mouse left button, drag the new file CFscript.txt and drop it on the ComboFix.exe icon as shown below.
This will start ComboFix again. Close all browser/windows first.
Note: Do not mouseclick combofix’s window while it’s running. That may cause it to stall
http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
Please post back with the combofix log.
Thanks