|
|
|||||||
|
Welcome to the Webuser forum. ![]() Rerun HJT,and put a checkmark beside these :- O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {8F3FA829-7D77-4AAC-9B33-767556E58136} - C:\Windows\system32\byXNgFxW.dll O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\pmnoLbxW.dll,#1 O4 - HKLM\..\Run: [BMb1323777] Rundll32.exe "C:\Windows\system32\yqublddm.dll",s O4 - HKLM\..\Run: [b20104eb] rundll32.exe "C:\Windows\system32\exnhmnwd.dll",b O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing) O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing) O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing) now close all windows and browsers and click FIX CHECKED Then i need you to delete your version of hijackthis and get the latest version from here :- http://www.trendsecure.com/portal/en-US/threat_analytics/HJTInstall.exe when you install it , you will find HJT in C:\program files\trend micro then :- Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**
**Note: Do not mouseclick combofix's window while it's running. That may cause it to stall** |