Please uninstall the following programs:
LimeWire
- Go to Start then Settings, then Control Panel
- Choose Add or Remove Programs
- Remove all of the above
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Start WinPFind35U. Copy/Paste the information in the codebox below into the pane where it says "Paste fix here" and then click the
Run Fix button.
[Kill Explorer]
[Processes - Non-Microsoft Only]
YY -> command.exe -> %SystemRoot%\TGVsYW5k\command.exe
YY -> kwtbaim.exe -> %ProgramFiles%\Kiwee Toolbar\kwtbaim.exe
YY -> mrofinu1000106.exe -> %SystemRoot%\mrofinu1000106.exe
YY -> 1a232420232427.exe -> %System32%\1A232420232427.exe
YY -> drmupgds.exe -> %ProgramFiles%\Drmupgds\Drmupgds.exe
YY -> router.exe -> %ProgramFiles%\Router\Router.exe
YY -> limewire.exe -> %ProgramFiles%\LimeWire\LimeWire.exe
YY -> bjcjjljo.exe -> %UserAppData%\Microsoft\Windows\bjcjjljo.exe
YY -> winlogo.exe -> %SystemDrive%\Documents and Settings\n3omanc3r\winlogo.exe
[Win32 Services - Non-Microsoft Only]
YY -> (cmdService) Command Service [Win32_Own | Auto | Running] -> %SystemRoot%\TGVsYW5k\command.exe
[Registry - Non-Microsoft Only]
< Run [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NY -> B2BBBCB8BBBCBFC0 -> %System32%\1A232420232427.exe
NY -> KiweeHook -> %ProgramFiles%\Kiwee Toolbar\kwtbaim.exe
YN -> runner1 -> %SystemRoot%\mrofinu1000106.exe
NY -> winlog -> %System32%\winlog.exe
< Run [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
NY -> Drmupgds -> %ProgramFiles%\Drmupgds\Drmupgds.exe
NY -> Etsa -> %SystemRoot%\sуstem\logonui.exe
NY -> Router -> %ProgramFiles%\Router\Router.exe
NY -> SfKg6w -> %UserAppData%\Microsoft\Windows\bjcjjljo.exe
< ShellExecuteHooks [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
NY -> {446624E1-B767-4443-AA6E-0F355CAFD21B} [HKEY_LOCAL_MACHINE] -> %System32%\cbxustq.dll []
< Winlogon\Notify settings [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
NY -> cbxustq -> %System32%\cbxustq.dll
NY -> ycbdnzhz -> %System32%\ycbdnzhz.dll
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
NY -> HKEY_CURRENT_USER\: URLSearchHooks\\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Kiwee Toolbar\KiweeIEToolbar.dll [Kiwee Toolbar]
< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\
NY -> 1 domain(s) and sub-domain(s) not assigned to a zone. ->
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
NY -> {446624E1-B767-4443-AA6E-0F355CAFD21B} [HKEY_LOCAL_MACHINE] -> %System32%\cbxustq.dll [Reg Error: Value does not exist or could not be read.]
NY -> {53f23ba2-2edf-414b-8ff8-756dc123e864} [HKEY_LOCAL_MACHINE] -> %System32%\ttvuntjg.dll [Reg Error: Value does not exist or could not be read.]
NY -> {6367C798-5E74-2CD8-0212-5300B8BC80C7} [HKEY_LOCAL_MACHINE] -> %System32%\ncr.dll [Reg Error: Value does not exist or could not be read.]
NY -> {6564CBCE-5C71-2F8D-5112-5300B8BCDBC3} [HKEY_LOCAL_MACHINE] -> %System32%\adgieuaa.dll [Reg Error: Value does not exist or could not be read.]
NY -> {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Kiwee Toolbar\KiweeIEToolbar.dll [Kiwee Toolbar]
NY -> {709EFF01-BC39-4B61-3EAF-BA3C39AAA672} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\MSN Gaming Zone\zyjix.dll [Reg Error: Value does not exist or could not be read.]
NY -> {A95B2816-1D7E-4561-A202-68C0DE02353A} [HKEY_LOCAL_MACHINE] -> %System32%\ycbdnzhz.dll [Reg Error: Value does not exist or could not be read.]
NY -> {C01FF68B-CFA0-47F5-8442-5A5CDC0B8236} [HKEY_LOCAL_MACHINE] -> %System32%\ddcya.dll [Reg Error: Value does not exist or could not be read.]
NY -> {C36201A4-A4CC-488F-B51A-6D24AD2F3C79} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Windows Media Player\viwyfapaz4444.dll []
NY -> {E6631C60-2861-4810-9182-BCE3879578F1} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Windows Media Player\viwyfapaz83122.dll []
< Internet Explorer ToolBars [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ToolBar
NY -> {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Kiwee Toolbar\KiweeIEToolbar.dll [Kiwee Toolbar]
< Internet Explorer ToolBars [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\
NY -> ShellBrowser\\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Kiwee Toolbar\KiweeIEToolbar.dll [Kiwee Toolbar]
NY -> WebBrowser\\{6638A9DE-0745-4292-8A2E-AE530E7B9B3F} [HKEY_LOCAL_MACHINE] -> %ProgramFiles%\Kiwee Toolbar\KiweeIEToolbar.dll [Kiwee Toolbar]
[Files/Folders - Created Within 90 days]
YN -> 5119 C:\*.tmp files -> C:\*.tmp
YN -> 2 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp
NY -> bszip.dll -> %System32%\bszip.dll
NY -> cbxustq.dll -> %System32%\cbxustq.dll
NY -> ddcya.dll -> %System32%\ddcya.dll
NY -> fdoshxgb.dll -> %System32%\fdoshxgb.dll
NY -> fftmqjqh.dll -> %System32%\fftmqjqh.dll
NY -> gebyyab.dll -> %System32%\gebyyab.dll
NY -> regedit.com -> %System32%\regedit.com
NY -> taskkill.com -> %System32%\taskkill.com
NY -> tasklist.com -> %System32%\tasklist.com
NY -> tiwyvcqg.dll -> %System32%\tiwyvcqg.dll
NY -> ttvuntjg.dll -> %System32%\ttvuntjg.dll
NY -> usrlogon.cmd -> %System32%\usrlogon.cmd
NY -> xkdqnjqh.ini -> %System32%\xkdqnjqh.ini
NY -> ycbdnzhz.dll -> %System32%\ycbdnzhz.dll
NY -> ycbdnzhz.dllbox -> %System32%\ycbdnzhz.dllbox
NY -> 9 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp
NY -> b116.exe -> %SystemRoot%\b116.exe
NY -> b122.exe -> %SystemRoot%\b122.exe
NY -> b149.exe -> %SystemRoot%\b149.exe
NY -> b151.exe -> %SystemRoot%\b151.exe
YN -> mrofinu1000106.exe -> %SystemRoot%\mrofinu1000106.exe
YN -> mrofinu1000137.exe -> %SystemRoot%\mrofinu1000137.exe
[Empty Temp Folders]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the
Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here.
Let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please
download the
OTMoveIt2 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
purity
- Return to OTMoveIt2, right click in the "Paste Custom List Of Files/Patterns To Move" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter
*.log and press the Enter key, navigate to the
C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please download
ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click
Exit on the Main menu to close the program.
For
Technical Support, double-click the e-mail address located at the bottom of each menu.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Please read this
Combofix tutorial before continuing, then follow the instructions below.
Download ComboFix from
Here,
Here or
Here to your Desktop. (If you already have ComboFix, please delete it and download this new version).
When asked to "Save As" save Combofix.exe as Combo-Fix.exe
- Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields)
- Double click combofix.exe and follow the prompts.
- When finished, it shall produce a log for you. Save this log to your desktop as Combofix.txt and post it in your next reply.
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
For the HijackThis uninstall list, please do this while you are posting, then instead of saving the file, Copy and Paste the contents into your reply.
Regards,
RatHat