system
15
Pol - I hope you don’t mind me jumping in but I had my WinPFind analyst tool already open for another thread anyway.
Mark, start WinPFind3U. Copy/Paste the information in the quotebox below into the pane where it says “Paste fix here” and then click the Run Fix button.
[Registry - Non-Microsoft Only]
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
YN -> rqrqomm -> rqrqomm.dll
[Files/Folders - Created Within 30 days]
NY -> winshow.exe -> %SystemRoot%\winshow.exe
NY -> bocouhkq.ini -> %System32%\bocouhkq.ini
NY -> bxsrffnh.exe -> %System32%\bxsrffnh.exe
NY -> caqlphka.dll -> %System32%\caqlphka.dll
NY -> cfnwicad.dll -> %System32%\cfnwicad.dll
NY -> cvqtiqmy.ini -> %System32%\cvqtiqmy.ini
NY -> cxxyvsqv.exe -> %System32%\cxxyvsqv.exe
NY -> dvmjoetv.exe -> %System32%\dvmjoetv.exe
NY -> emdorobt.ini -> %System32%\emdorobt.ini
NY -> epqefoto.exe -> %System32%\epqefoto.exe
NY -> erfgtpgv.ini -> %System32%\erfgtpgv.ini
NY -> evxftikj.exe -> %System32%\evxftikj.exe
NY -> fsdgubhf.ini -> %System32%\fsdgubhf.ini
NY -> gahucgqj.ini -> %System32%\gahucgqj.ini
NY -> ghabwcty.exe -> %System32%\ghabwcty.exe
NY -> gqorhcce.ini -> %System32%\gqorhcce.ini
NY -> hmcdhdlw.ini -> %System32%\hmcdhdlw.ini
NY -> hpfkwomp.ini -> %System32%\hpfkwomp.ini
NY -> hvvycbpm.exe -> %System32%\hvvycbpm.exe
NY -> hwawctdi.exe -> %System32%\hwawctdi.exe
NY -> hxhdipqm.exe -> %System32%\hxhdipqm.exe
NY -> ibuauegt.dll -> %System32%\ibuauegt.dll
NY -> iivpjxjk.exe -> %System32%\iivpjxjk.exe
NY -> inpiutmn.ini -> %System32%\inpiutmn.ini
NY -> jmcmndmr.exe -> %System32%\jmcmndmr.exe
NY -> jxibasda.ini -> %System32%\jxibasda.ini
NY -> kakggcks.ini -> %System32%\kakggcks.ini
NY -> kvyyliof.dll -> %System32%\kvyyliof.dll
NY -> lvgxyqsp.ini -> %System32%\lvgxyqsp.ini
NY -> lxnhaexo.exe -> %System32%\lxnhaexo.exe
NY -> mcrh.tmp -> %System32%\mcrh.tmp
NY -> mpsqtnkp.ini -> %System32%\mpsqtnkp.ini
NY -> mwxpwfnx.exe -> %System32%\mwxpwfnx.exe
NY -> ndrlrvlk.ini -> %System32%\ndrlrvlk.ini
NY -> nnccwnfn.ini -> %System32%\nnccwnfn.ini
NY -> nryafwid.exe -> %System32%\nryafwid.exe
NY -> nthxsrbx.ini -> %System32%\nthxsrbx.ini
NY -> oeohfjck.ini -> %System32%\oeohfjck.ini
NY -> ohcmrdoh.tmp -> %System32%\ohcmrdoh.tmp
NY -> ooyqblwu.ini -> %System32%\ooyqblwu.ini
NY -> pmnlmlk.dll -> %System32%\pmnlmlk.dll
NY -> psqyxgvl.dll -> %System32%\psqyxgvl.dll
NY -> qftklagh.dll -> %System32%\qftklagh.dll
NY -> qiiosgee.exe -> %System32%\qiiosgee.exe
NY -> qiyklfiu.exe -> %System32%\qiyklfiu.exe
NY -> qqmwguyd.exe -> %System32%\qqmwguyd.exe
NY -> qsafjfbr.exe -> %System32%\qsafjfbr.exe
NY -> qubfkmri.exe -> %System32%\qubfkmri.exe
NY -> qvmyndvv.dll -> %System32%\qvmyndvv.dll
NY -> qwruiljg.exe -> %System32%\qwruiljg.exe
NY -> rbrdorry.ini -> %System32%\rbrdorry.ini
NY -> rkpokdfk.ini -> %System32%\rkpokdfk.ini
NY -> rttjqulv.ini -> %System32%\rttjqulv.ini
NY -> skcggkak.dll -> %System32%\skcggkak.dll
NY -> tecfbqsg.ini -> %System32%\tecfbqsg.ini
NY -> tgeuaubi.ini -> %System32%\tgeuaubi.ini
NY -> thrbncyb.dll -> %System32%\thrbncyb.dll
NY -> tkspfget.ini -> %System32%\tkspfget.ini
NY -> ucpueekp.exe -> %System32%\ucpueekp.exe
NY -> uedjhktu.ini -> %System32%\uedjhktu.ini
NY -> uhtbhmns.exe -> %System32%\uhtbhmns.exe
NY -> uogtjtbp.dll -> %System32%\uogtjtbp.dll
NY -> urqbepte.exe -> %System32%\urqbepte.exe
NY -> vtquqiex.dll -> %System32%\vtquqiex.dll
NY -> vvdnymvq.ini -> %System32%\vvdnymvq.ini
NY -> wwhwfjax.exe -> %System32%\wwhwfjax.exe
NY -> xbrsxhtn.dll -> %System32%\xbrsxhtn.dll
NY -> xkfowsux.ini -> %System32%\xkfowsux.ini
NY -> xsfimpjd.exe -> %System32%\xsfimpjd.exe
NY -> xuswofkx.dll -> %System32%\xuswofkx.dll
NY -> xytoteva.dll -> %System32%\xytoteva.dll
NY -> ycebjhku.exe -> %System32%\ycebjhku.exe
NY -> ynwhmodg.dll -> %System32%\ynwhmodg.dll
NY -> ytswoufv.ini -> %System32%\ytswoufv.ini
[Files/Folders - Modified Within 30 days]
NY -> eKMEw.job -> %SystemRoot%\tasks\eKMEw.job
NY -> jVakIwGLcxbxzakDfKhmXqrscHJSGFe.job -> %SystemRoot%\tasks\jVakIwGLcxbxzakDfKhmXqrscHJSGFe.job
NY -> bocouhkq.ini -> %System32%\bocouhkq.ini
NY -> bxsrffnh.exe -> %System32%\bxsrffnh.exe
NY -> caqlphka.dll -> %System32%\caqlphka.dll
NY -> cfnwicad.dll -> %System32%\cfnwicad.dll
NY -> cvqtiqmy.ini -> %System32%\cvqtiqmy.ini
NY -> cxxyvsqv.exe -> %System32%\cxxyvsqv.exe
NY -> dvmjoetv.exe -> %System32%\dvmjoetv.exe
NY -> emdorobt.ini -> %System32%\emdorobt.ini
NY -> epqefoto.exe -> %System32%\epqefoto.exe
NY -> erfgtpgv.ini -> %System32%\erfgtpgv.ini
NY -> evxftikj.exe -> %System32%\evxftikj.exe
NY -> fsdgubhf.ini -> %System32%\fsdgubhf.ini
NY -> gahucgqj.ini -> %System32%\gahucgqj.ini
NY -> ghabwcty.exe -> %System32%\ghabwcty.exe
NY -> gqorhcce.ini -> %System32%\gqorhcce.ini
NY -> hmcdhdlw.ini -> %System32%\hmcdhdlw.ini
NY -> hpfkwomp.ini -> %System32%\hpfkwomp.ini
NY -> hvvycbpm.exe -> %System32%\hvvycbpm.exe
NY -> hwawctdi.exe -> %System32%\hwawctdi.exe
NY -> hxhdipqm.exe -> %System32%\hxhdipqm.exe
NY -> ibuauegt.dll -> %System32%\ibuauegt.dll
NY -> iivpjxjk.exe -> %System32%\iivpjxjk.exe
NY -> inpiutmn.ini -> %System32%\inpiutmn.ini
NY -> jmcmndmr.exe -> %System32%\jmcmndmr.exe
NY -> jxibasda.ini -> %System32%\jxibasda.ini
NY -> kakggcks.ini -> %System32%\kakggcks.ini
NY -> kvyyliof.dll -> %System32%\kvyyliof.dll
NY -> lvgxyqsp.ini -> %System32%\lvgxyqsp.ini
NY -> lxnhaexo.exe -> %System32%\lxnhaexo.exe
NY -> mcrh.tmp -> %System32%\mcrh.tmp
NY -> mpsqtnkp.ini -> %System32%\mpsqtnkp.ini
NY -> mwxpwfnx.exe -> %System32%\mwxpwfnx.exe
NY -> ndrlrvlk.ini -> %System32%\ndrlrvlk.ini
NY -> nnccwnfn.ini -> %System32%\nnccwnfn.ini
NY -> nryafwid.exe -> %System32%\nryafwid.exe
NY -> nthxsrbx.ini -> %System32%\nthxsrbx.ini
NY -> oeohfjck.ini -> %System32%\oeohfjck.ini
NY -> ohcmrdoh.tmp -> %System32%\ohcmrdoh.tmp
NY -> ooyqblwu.ini -> %System32%\ooyqblwu.ini
NY -> pmnlmlk.dll -> %System32%\pmnlmlk.dll
NY -> psqyxgvl.dll -> %System32%\psqyxgvl.dll
NY -> qftklagh.dll -> %System32%\qftklagh.dll
NY -> qiiosgee.exe -> %System32%\qiiosgee.exe
NY -> qiyklfiu.exe -> %System32%\qiyklfiu.exe
NY -> qqmwguyd.exe -> %System32%\qqmwguyd.exe
NY -> qsafjfbr.exe -> %System32%\qsafjfbr.exe
NY -> qubfkmri.exe -> %System32%\qubfkmri.exe
NY -> qvmyndvv.dll -> %System32%\qvmyndvv.dll
NY -> qwruiljg.exe -> %System32%\qwruiljg.exe
NY -> rbrdorry.ini -> %System32%\rbrdorry.ini
NY -> rkpokdfk.ini -> %System32%\rkpokdfk.ini
NY -> rrutv.bak1 -> %System32%\rrutv.bak1
NY -> rrutv.bak2 -> %System32%\rrutv.bak2
NY -> rrutv.ini -> %System32%\rrutv.ini
NY -> rttjqulv.ini -> %System32%\rttjqulv.ini
NY -> skcggkak.dll -> %System32%\skcggkak.dll
NY -> tecfbqsg.ini -> %System32%\tecfbqsg.ini
NY -> tgeuaubi.ini -> %System32%\tgeuaubi.ini
NY -> thrbncyb.dll -> %System32%\thrbncyb.dll
NY -> tkspfget.ini -> %System32%\tkspfget.ini
NY -> ucpueekp.exe -> %System32%\ucpueekp.exe
NY -> uedjhktu.ini -> %System32%\uedjhktu.ini
NY -> uhtbhmns.exe -> %System32%\uhtbhmns.exe
NY -> uogtjtbp.dll -> %System32%\uogtjtbp.dll
NY -> urqbepte.exe -> %System32%\urqbepte.exe
NY -> vtquqiex.dll -> %System32%\vtquqiex.dll
NY -> vvdnymvq.ini -> %System32%\vvdnymvq.ini
NY -> wwhwfjax.exe -> %System32%\wwhwfjax.exe
NY -> xbrsxhtn.dll -> %System32%\xbrsxhtn.dll
NY -> xkfowsux.ini -> %System32%\xkfowsux.ini
NY -> xsfimpjd.exe -> %System32%\xsfimpjd.exe
NY -> xuswofkx.dll -> %System32%\xuswofkx.dll
NY -> xytoteva.dll -> %System32%\xytoteva.dll
NY -> ycebjhku.exe -> %System32%\ycebjhku.exe
NY -> ynwhmodg.dll -> %System32%\ynwhmodg.dll
NY -> ytswoufv.ini -> %System32%\ytswoufv.ini
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new WinPFind3u scan.
Also let me know of any problems you encounter performing these steps or any continuing problems you are having with the computer.
Is there a red line through the avast! icon in the system tray at the bottom right of your screen? The avast! services are reported stopped in the WinPFind log.
EDIT:
Finally finished. Are they all this long???
Yes, give or take a line or two ;D