Hya Fay , welcome to PCHF.
Please download
Process Explorer by Systernals from
HERE.
Also download
KillBox by Option^Explicit from
HERE.
Then boot up in
SAFE MODE and stay in safe mode (hit f8 when booting up), untill the entire fix is done.
Unzip
Process Explorer and double click on
procexp.exe
In the top section of the Process Exlporer screen double click on
winlogon.exe to bring up the winlogon.exe properties screen. Click on the
Threads tab at the top.
Once you see this screen click on each instance of
oihapgof.dll and
EQMini.dll once and then click the
kill button.
After you have killed all of the
oihapgof.dll's and
EQMini.dll's under winlogon click
OK.
Next In the top section of the Process Exlporer screen again , double click on
explorer.exe and again click once on each instance of
oihapgof.dll and
EQMini.dll then click the
kill button.
Once you have done that click
OK again.
Next run
HijackThis and place a check beside each of the following:
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: - {EBDEBB0C-814D-493E-8E12-8002EDBAF246} - C:\WINDOWS\lbbho.dll (file missing)
O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) -
http://www.adsserve.com/WildApp.cab
O20 - AppInit_DLLs: oihapgof.dll,EQMini.dll
Then do a search for these two file on youre pc:
oihapgof.dll and
EQMini.dll
And write down there location.
For example:
C:\WINDOWS\system32\oihapgof.dll
C:\WINDOWS\system32\EQMini.dll
Start Killbox and place a tick next to [x]delete on reboot.
And press the "all files" button. (just above the yellow triangle)
Then copy the filepath plus names you just looked up to the windows clipboard:
For example:
C:\WINDOWS\system32\oihapgof.dll
C:\WINDOWS\system32\EQMini.dll
Back in Killbox go > file > paste from clipboard,
Click the
red highlighted X button and say yes to the prompt, then click OK.
Exit Killbox and restart your PC.
Also it seems you have no firewall installed , have a look in our download section for some free firewalls if you want.
When done , please post a new
hjt log , and could you also post the log from the Ewido scan you did?