Looks alot better already.
Please download and run this tool:
http://www.purityscan.com/ps_uninstaller.exe
Make sure you still have Ccleaner.
Please download
Process Explorer by Systernals from
HERE.
Also download
KillBox by Option^Explicit from
HERE.
Then boot up in
SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.
Click Start>Run and type in: services.msc
Click OK
In the Services window find:
(one by one)
Network Monitor
Windows Overlay Components
Select/highlight and right click the entry, and choose: Properties
On the General tab, under Service Status click the Stop button
Beside: Startup Type, in the drop menu, select: Disabled
Click Apply, then OK
Open
HJT and click config > misc tools > ?delete an NT service?
Copy and past:
(again one by one)
Network Monitor
Windows Overlay Components
Click OK.
Unzip
Process Explorer and double click on
procexp.exe
In the top section of the Process Exlporer screen double click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of
senssrv.dll (if present)once and then click the
kill button.
After you have killed all of the
senssrv.dll's under winlogon click
OK.
Next In the top section of the Process Exlporer screen again , double click on
explorer.exe and again click once on each instance of
senssrv.dll then click the
kill button.
Once you have done that click
OK again.
Next run
HijackThis and place a check beside each of the following:
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\qotkv.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,cjangcq. exe
O2 - BHO: Yvakt Class - {BA3DDC15-3EF1-4DC7-B9B6-ED0403F9422A} - C:\WINDOWS\system32\OUGHYA~1.DLL
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O4 - HKLM\..\Run: [newname] C:\windows\newname6.exe
O4 - HKLM\..\Run: [evbyneoA] C:\WINDOWS\evbyneoA.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [CQ4d6] "C:\WINDOWS\system32\slk8x2peu.exe"
O4 - HKLM\..\RunServices: [tetriz3] C:\WINDOWS\system32\tetriz3.exe
O4 - HKCU\..\Run: [Shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O18 - Filter: text/html - {D332110E-3EDB-417B-B8E2-297B61C074C6} - C:\WINDOWS\system32\OUGHYA~1.DLL
O20 - Winlogon Notify: SensSrv - C:\WINDOWS\SYSTEM32\senssrv.dll
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: Windows Overlay Components - Unknown owner - C:\WINDOWS\evbyneo.exe
Now manually search for , and delete these two files:
cjangcq.exe
C:\WINDOWS\system32\
OUGHYA~1.DLL
And run Ccleaner again.
Then start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)
Copy this list into the windows clipboard:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\smohc.exe
C:\WINDOWS\system32\bfcgvw.exe
C:\WINDOWS\system32\qotkv.exe
C:\WINDOWS\system32\__delete_on_reboot__hmcgmfb.dl l
C:\WINDOWS\system32\__delete_on_reboot__senssrv.dl l
C:\Documents and Settings\Mark\Application Data\Sskcwrd.dll
C:\sk02.exe
C:\Veracruz.exe
C:\WINDOWS\country.exe
C:\WINDOWS\DH.dll
C:\WINDOWS\dh.ini
C:\WINDOWS\keyboard61.dat
C:\WINDOWS\system\svchost.dll
C:\WINDOWS\system\svchost.exe
C:\WINDOWS\tool1.exe
C:\WINDOWS\tool4.exe
C:\WINDOWS\tool5.exe
C:\WINDOWS\TWFyaw
C:\WINDOWS\uninstall_nmon.vbs
C:\WINDOWS\uniq
C:\Program Files\Common Files\Microsoft Shared\Web Folders\__delete_on_reboot__ibm00002.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\__delete_on_reboot__ibm00001.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe
C:\WINDOWS\system32\e6tw76cpw.exe
C:\WINDOWS\system32\qotkv.exe
C:\windows\newname6.exe
C:\WINDOWS\evbyneoA.exe
C:\WINDOWS\SYSC00.exe
C:\WINDOWS\system32\slk8x2peu.exe
C:\WINDOWS\system32\tetriz3.exe
C:\WINDOWS\SYSTEM32\senssrv.dll
C:\Program Files\Network Monitor
C:\WINDOWS\evbyneo.exe
Back in Killbox go > file > paste from clipboard,
Click the
red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Now in normal mode again , please Download
RKFiles.zip
Create a new folder C:\Antispyware\RKFiles
Extract the contents of RKFiles.zip into the new folder you just created.
Next, Create a new Folder on Desktop. Name that Folder QOOLOGIC
Please download
Findqoologic into the new Folder, and then unzip it into the new Folder.
Restart to safe mode again. (tap f8 key during bootup)
Open the C:\Antispyware\RKFiles folder
Double click on RKFILES.BAT
Give it time to run. this may take a while.
Save the text file it creates.
It should save by default to C:\Log.txt
Next, open the QOOLOGIC Folder and Locate and double-click the Find-Qoologic.bat file to run it.
Wait until a text file opens, post it in a reply to your thread after youre done.
It'll take a while to run a full scan so please be patient.
Restart into regular Windows mode and post the contents of C:\log.txt , the find-qoologic results , and a new hijackthis log.
Also it seems you have no firewall , to be better protected from things like this you really should have one. Have a look in our download section for some free firewalls.