Start WinPFind35U. Copy/Paste the information in the Codebox below into the pane where it says "Paste fix here" and then click the Run Fix button.
[Kill Explorer][Unregister Dlls][Files/Folders - Created Within 30 days]YY -> 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmpYY -> mdelk.exe -> %SystemRoot%\System32\mdelk.exeYY -> xfcodec.dll -> %SystemRoot%\System32\xfcodec.dllYY -> NV19441972.TMP -> %SystemRoot%\NV19441972.TMPYY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmpYY -> winstart.bat -> %SystemRoot%\winstart.bat[Files/Folders - Modified Within 30 days]YY -> hosts.20080208-161428.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080208-161428.backupYY -> hosts.20080208-164121.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080208-164121.backupYY -> hosts.20080208-164134.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080208-164134.backupYN -> hosts.20080209-111825.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080209-111825.backupYY -> hosts.20080211-151943.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080211-151943.backupYY -> hosts.20080215-154915.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080215-154915.backupYY -> hosts.20080215-154919.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080215-154919.backupYY -> hosts.20080216-231506.backup -> %SystemRoot%\System32\drivers\etc\hosts.20080216-231506.backupYY -> 4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmpYY -> mdelk.exe -> %SystemRoot%\System32\mdelk.exeYY -> xfcodec.dll -> %SystemRoot%\System32\xfcodec.dllYY -> 5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmpYY -> NV19441972.TMP -> %SystemRoot%\NV19441972.TMPYY -> winstart.bat -> %SystemRoot%\winstart.batYY -> qmgr0.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.datYY -> qmgr1.dat -> C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.datYY -> am6g3dcd.exe -> C:\Documents and Settings\user\Local Settings\Temp\am6g3dcd.exeYY -> cleanup.exe -> C:\Documents and Settings\user\Local Settings\Temp\cleanup.exeYY -> t0jpgii1.exe -> C:\Documents and Settings\user\Local Settings\Temp\t0jpgii1.exeYY -> 2 C:\Documents and Settings\user\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\user\Local Settings\Temp\*.tmpYY -> setup.exe -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\setup.exeYY -> drm_dialogs.dll -> C:\Documents and Settings\user\Local Settings\Temp\drm_dialogs.dllYY -> 2 C:\Documents and Settings\user\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\user\Local Settings\Temp\*.tmpYY -> gtapi.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\gtapi.dllYY -> helper.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\helper.dllYY -> ikdll.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\ikdll.dllYY -> InnoHelpers.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\InnoHelpers.dllYY -> isxdl.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\isxdl.dllYY -> PCTLicHelper.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\PCTLicHelper.dllYY -> PCTLicReset.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\PCTLicReset.dllYY -> PCTWSC.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\PCTWSC.dllYY -> SecurityUtil.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\SecurityUtil.dllYY -> _shfoldr.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\_isetup\_shfoldr.dllYY -> 1 C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\_isetup\*.tmp files -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\_isetup\*.tmpYY -> aamig.DLL -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\aamig.DLLYY -> msaa2rdk.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\msaa2rdk.dllYY -> MSAATextA.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\MSAATextA.dllYY -> MSAATextW.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\MSAATextW.dllYY -> msoobci.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\msoobci.dllYY -> oleaccA.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\oleaccA.dllYY -> oleaccrc.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\oleaccrc.dllYY -> oleaccW.dll -> C:\Documents and Settings\user\Local Settings\Temp\is-LIJ73.tmp\MSAA20RDK\oleaccW.dllYY -> Perflib_Perfdata_62c.dat -> C:\Documents and Settings\user\Local Settings\Temp\Perflib_Perfdata_62c.datYY -> 2 C:\Documents and Settings\user\Local Settings\Temp\*.tmp files -> C:\Documents and Settings\user\Local Settings\Temp\*.tmp[Extra Files]C:\WINDOWS\system32\wintems.exe[Empty Temp Folders][Start Explorer][ZipFiles][Reboot]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new WinPFind35u scan and a Hijackthis log, separately (the Hijackthis can be pasted on the reply).
This time, when scanning with
WinpFind35u, under Processes, Services, Drivers and Registry, select the
All button.
I will review the information when it comes back in.
Edited by JSntgRvr, 29 February 2008 - 08:34 PM.