Open notepad and copy/paste the text in the quote box below into it:
File::
C:\Documents and Settings\All Users\Application Data\WildTangent
C:\Documents and Settings\All Users\Application Data\kgvsrrma
C:\Documents and Settings\All Users\Application Data\uzkiodzh
C:\Documents and Settings\All Users\Application Data\odavibsv
C:\WINDOWS\system32\geBrsrRh.dll
C:\WINDOWS\wxdbpfvo.dll
C:\WINDOWS\system32\alabqbkn.exe
C:\WINDOWS\system32\imtdamet.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{BE78B4A0-9873-4C13-ACC2-D898536C9798}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{C3169036-557E-45E1-840F-C845DC406C55}"=-

[-HKEY_CLASSES_ROOT\clsid\{c3169036-557e-45e1-840f-c845dc406c55}]

[-HKEY_CLASSES_ROOT\wxdbpfvo.1]

[-HKEY_CLASSES_ROOT\TypeLib\{D95C697F-D985-4AB1-92B5-40DF04BBE322}]

[-HKEY_CLASSES_ROOT\wxdbpfvo]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"sqrjigmy"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"ece3c94e"=-
Save this as CFScript on your desktop.



Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log with a fresh copy of HijackThis.