Looks pretty good. Couple more steps;
First you need to run HJT again and place a checkmark next to the following entry;
O2 - BHO: gooochi browser optimizer - {d1fa2a29-3f8b-b045-2e9b-1998e216e484} - C:\WINDOWS\system32\qsuheivghvlz.dll (file missing)
Once you have placed the checkmark then click the Fix Checked button.
Exit HJT.
Now we need to do a fix with Combofix. Please download it from HERE
save it to the desktop.
Open Notepad and copy/paste the text in the below quote box into it:
KILLALL::
Folder::
C:\WINDOWS\S2F0aGFyaW5l
C:\WINDOWS\system32\g82.exe
C:\WINDOWS\system32\sfig
C:\WINDOWS\system32\provdll
C:\WINDOWS\system32\OBDE
C:\WINDOWS\system32\imp32
C:\WINDOWS\system32\olixds01
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{d1fa2a29-3f8b-b045-2e9b-1998e216e484}]
C:\WINDOWS\system32\qsuheivghvlz.dll
- Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
- At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
- You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
- Now use your mouse to drag CFscript.txt on top of ComboFix.exe
- Follow the prompts.
- When it finishes, a log will be produced named c:\combofix.txt
Note:
Do not mouseclick combofix's window while it is running. That may cause it to stall.
Once you have completed the above, reboot the system. Run a new HJT scan. Post back here with that new combofix.txt file and the new HJT log.


Reply With Quote