seraphia OK this is a biggie - by the time we have finished the MS files should be in the majority again. I may have duplicated some files and missed a few out as my eyes started to wander
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. [b]
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exe
O2 - BHO: (no name) - {00B99484-CB8D-4A41-AD4B-E7C2FAD1E900} - \
O2 - BHO: SpruceBHO - {54DE7259-C729-45B1-BBD8-4BE9B5BD8248} - C:\Program Files\Spruce\Spruce.dll
O2 - BHO: (no name) - {6A8AFD43-167C-46EA-B467-EE608496ADB1} - C:\WINDOWS\system32\comsvc.dll
O2 - BHO: (no name) - {76F262CF-0308-0FB4-F7A3-043266F3A47C} - (no file)
O2 - BHO: (no name) - {8E3FBDE2-7DBD-4040-85D9-29BBC559C129} - (no file)
O2 - BHO: {e592f23c-1eef-26b9-5a94-fa107124b65c} - {c56b4217-01af-49a5-9b62-fee1c32f295e} - C:\WINDOWS\system32\oahblfgu.dll
O2 - BHO: (no name) - {D1D0FE44-1D40-4BB6-9AF1-8B03F4DB180A} - (no file)
O2 - BHO: (no name) - {D27987B8-7244-4DE0-AE10-39B826B492F1} - C:\WINDOWS\system32\bronto.dll
O4 - HKLM..\Run: [Medichi] medichi.exe
O4 - HKLM..\Run: [Medichi2] medichi2.exe
O4 - HKLM..\Run: [Undefined] C:\WINDOWS\system32\winter.exeO2 - BHO: (no name) - {2F02D978-0FF6-80F7-60BB-0426224AB7B3} - (no file)
O4 - HKCU..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User ‘Default user’)
O4 - Startup: infos.exe
O4 - Global Startup: autos.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O20 - AppInit_DLLs: murka.dat
O20 - Winlogon Notify: winxyl32 - winxyl32.dll (file missing)
O20 - Winlogon Notify: wvuurqq - wvuurqq.dll (file missing)
O20 - Winlogon Notify: __c00B267E - C:\WINDOWS\system32__c00B267E.dat
[/b]Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis.
THEN
Please download the OTMoveIt2 by OldTimer.
[*] Save it to your desktop.
[*] Please double-click OTMoveIt2.exe to run it.
[*]Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
C:\WINDOWS\medichi2.exe
C:\WINDOWS\system32\40CA400c__.ini2
C:\WINDOWS\system32\sygwswcq.dll
C:\WINDOWS\system32\winter.exeO2
C:\WINDOWS\system32\__c00B267E.dat
C:\WINDOWS\system32\winter.exe
C:\WINDOWS\medichi.exe
C:\Program Files\Spruce
C:\WINDOWS\system32\oahblfgu.dll
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\bronto.dll
C:\WINDOWS\system32\qwjopxox.dll
C:\WINDOWS\system32\oahblfgu.dll
C:\WINDOWS\system32\__c004AC04.dat
C:\WINDOWS\system32\appmgmt
C:\WINDOWS\system32\kuapoqgl.ini2
C:\Program Files\Outerinfo
C:\WINDOWS\system32\iifdcaw.dll
C:\Program Files\New Folder
C:\hide
C:\WINDOWS\system32\lgqopauk.dll
C:\WINDOWS\system32\nkxypvlu.dll
C:\WINDOWS\system32\ksfewljl.dll
C:\WINDOWS\system32\mhlrfmpi.dll
C:\WINDOWS\system32\npvoeqvq.dll
C:\WINDOWS\system32\fdkcxlur.dll
C:\WINDOWS\system32\vwkldmrv.dll
C:\WINDOWS\system32\ccabgguq.dll
C:\WINDOWS\system32\lfisjdwa.dll
C:\WINDOWS\system32\svtuxgan.dll
C:\WINDOWS\system32\dwgqykcn.dll
C:\WINDOWS\system32\xwruqidm.dll
C:\WINDOWS\system32\noiyaysq.dll
C:\WINDOWS\system32\duwxxyig.dll
C:\WINDOWS\system32\__c009F310.exe
C:\WINDOWS\system32\nqqaoreq.dll
C:\WINDOWS\system32\thpqwtxh.dll
C:\WINDOWS\murka.dat
C:\WINDOWS\system32\xaswieba.dll
C:\WINDOWS\system32\itodfsbx.dll
C:\WINDOWS\system32\eswbrxcx.dll
C:\WINDOWS\system32\hjqdxqug.dll
C:\WINDOWS\system32\ckpitoou.dll
C:\WINDOWS\system32\cokvhpem.dll
C:\WINDOWS\system32\lfmowrxd.dll
C:\WINDOWS\system32\apvsxdso.dll
C:\WINDOWS\system32\njprckha
C:\Program Files\SecCenter
C:\WINDOWS\system32\proper.exe
C:\WINDOWS\system32\jshqaljp.dll
C:\Program Files\Helper
C:\WINDOWS\system32\ineWc12
C:\Documents and Settings\HP_Administrator\X.exe
C:\WINDOWS\system32\bronto.dll
C:\WINDOWS\system32\shtmthfi.dll
C:\WINDOWS\system32\qsegimhm.dll
C:\Program Files\EliteProtector
C:\Documents and Settings\HP_Administrator\Application Data\antivirus.exe
C:\WINDOWS\system32\ymlfwnbq.dll
C:\WINDOWS\system32\hmvplwiv.dll
C:\WINDOWS\system32\lnbyrkfr.dll
C:\WINDOWS\system32\baimajvk.dll
C:\WINDOWS\system32\drivers\ptjpswgy.dat
C:\WINDOWS\system32\comsvc.dll
C:\WINDOWS\system32\__c00B267E.dat
C:\Program Files\Gjioitzm
C:\WINDOWS\system32\sttss.ini2
C:\WINDOWS\system32\drvwizr.dll
C:\WINDOWS\system32\drvwiz.dll
C:\WINDOWS\system32\lpcywinp.exe
C:\WINDOWS\83122.exe
C:\WINDOWS\system32\sstts.dll
[*] Return to OTMoveIt2, right click in the “Paste List of Files/Folders to be Moved” window (under the light blue bar) and choose Paste.
[*]Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
purity
[*] Return to OTMoveIt2, right click in the “Paste List Of Files/Patterns To Search For and Move” window (under the yellow bar) and choose Paste.
[*]Click the red Moveit! button.
[*]Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
[*]Close OTMoveIt2
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.