Hi
No it did not work 100 %
Open HijackThis, click do a system scan only and checkmark these:
O2 - BHO: (no name) - {6626808A-E950-4454-83E0-0CCCDB345568} - C:\WINDOWS\system32\efeby.dll (file missing)
O2 - BHO: (no name) - {8ed3f490-855b-49a7-81b7-738974cd820d} - C:\WINDOWS\system32\pwgohru.dll (file missing)
O2 - BHO: (no name) - {C66EC8C2-BB81-4E76-A909-EF78019F6DE7} - C:\Program Files\Windows NT\vihypi83122.dll (file missing)
O4 - HKCU\..\Run: [Uayoxo] "C:\Program Files\Common Files\??mantec\n?tepad.exe"
O4 - HKCU\..\Run: [Wtai] "C:\DOCUME~1\User1\APPLIC~1\YSTEM~1\wucrtupd.exe" -vt ndrv
Close all windows incluiding browser and press fix checked.
Reboot.
Please download the OTMoveIt2 by OldTimer.
- Save it to your desktop.
- Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
- Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Code:C:\WINDOWS\system32\sdjpnexs.ini C:\WINDOWS\system32\cgegodpr.ini C:\WINDOWS\system32\uyliaknu.ini C:\Program Files\Dot1XCfg C:\WINDOWS\system32\xmderotv.ini C:\WINDOWS\system32\egflybum.ini C:\WINDOWS\system32\rfsfjpeg.ini C:\WINDOWS\system32\jafvxeaw.ini C:\WINDOWS\system32\bvrmahxy.ini C:\WINDOWS\system32\winzs6 C:\WINDOWS\system32\nui4 C:\WINDOWS\system32\extz1 C:\WINDOWS\system32\comm7 C:\WINDOWS\system32\nGpxx01- Return to OTMoveIt2, right click in the "Paste Custom List Of Files/Patterns To Move" window (under the yellow bar) and choose Paste.
- Click the red Moveit! button.
- Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
- Close OTMoveIt2
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Re-run combofix
Post:
- a fresh HijackThis log
- combofix report
- otmoveit2 report