
Hi Cooley,
Thanks for those, yes you definitely still have some malware mucking about in your PC. Please download Shoot the Messenger, SpySweeper (14 day free trial), and RegSupremePro from my signature. Also, please download
SDBOTGUI. Please save them to your desktop, update SpySweeper, and RegSupremePro.
You will want to do this fix in Safe Mode, so you will probably want to print these instructions.
Before booting into Safe Mode, please make sure that your System Restore is disabled. Then boot into Safe Mode.
Run the cleaner you used in the PreWork instructions previously, (or you could use CCleaner from my signature, my personal favorite).
First run the SDBOTGUI, click Go, and let it remove the worm.
Next run SpySweeper, make sure that all options are selected in the Custom Sweep section of the Sweep page under Options. Run a full system scan, and allow it to fix everything that it finds. Please save a log, and post that back here with your
HJT log at the end.
Then run Shoot the Messenger, it is a small application that will disable your Windows Messenger, an unnecessary utility that leaves you vulnerable to PopUp attacks.
Next run HijackThis, and fix the following if they are still there:
O4 - HKLM\..\Run: [mlibsysmc] sysozguk.exe
O4 - HKLM\..\RunServices: [mlibsysmc] sysozguk.exe
O4 - HKCU\..\Run: [ymmsddlop] C:\WINDOWS\system32\vssmnptc.exe
O4 - HKCU\..\Run: [jmlcv4m] C:\WINDOWS\system32\sdmvdlxe.exe
O4 - HKCU\..\Run: [cwingllib] C:\WINDOWS\system32\atllsimm.exe
My suggestion is that you also uninstall StarDock, it has been known to cause problems, and until you have everything fixed, it is one less to worry about.
Now boot back into Normal Mode. Run the cleaner again, then run RegSupremePro, it will want to make a backup of your cache, let it. Click on the Registry Cleaner tab, and select Aggressive. When it has finished, click on Select, choose All. Click on Fix, and let it fix everything it finds.
Reboot yoru PC, and run
HJT one more time to generate a log, and post it back here.
Looking forward to your reply,
TTFN
LGW