Welcome to GTG.
Right click on this file -> C:\Documents and Settings\All Users\Start Menu\Programs\Startup\run_startmenu.cmd and choose Edit. Copy and paste the contents of that file here.
Open up your Notepad editor (Start->Run, type in
notepad and click OK). Copy and paste the text into the quotebox below:
File::
C:\WINDOWS\system32\palorila.exe
C:\WINDOWS\system32\dkdcdmba.exe
C:\WINDOWS\vadokmxt.dll
C:\WINDOWS\dpevflbg.dll
C:\WINDOWS\olgdqarf.exe
C:\WINDOWS\system32\evoxuhgv.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\run_startmenu.cmd
c:\windows\pss\run_startmenu.cmdCommon Startup
Folder::
C:\Documents and Settings\All Users\Application Data\upitghid
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"lgjvaxhu"=-
"uytsitof"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
"uTAxUNdQ8s"=-
Save this as
CFScript.txt in the same location as the ComboFix.exe tool.
Drag the CFScript.txt into ComboFix.exe
Follow the prompts. When finished, it shall produce a log for you. Post that log in your next reply.
Note: Do not click on combofix's window while it's running. That may cause it to stall.
Edited by greyknight17, 24 April 2008 - 06:59 AM.