1. Please open Notepad- Click Start , then Run
- Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
Code:
File::
c:\windows\system32\4041241291.dat
c:\windows\winstart.bat
c:\windows\system32\drivers\Partizan.sys
c:\windows\system32\Partizan.exe
c:\windows\system32\drivers\lhllpn.sys
c:\windows\system32\drivers\chlixoxc.sys
c:\windows\system32\drivers\wwzbgb.sys
c:\windows\system32\Drivers\Winkq62.sys
c:\windows\system32\drivers\d1d76351.sys
c:\windows\system32\drivers\e43d787d.sys
c:\docume~1\ADMINI~1\LOCALS~1\Temp\MUXRXROEG.exe
c:\windows\system32\drivers\Partizan.sys
c:\docume~1\ADMINI~1\LOCALS~1\Temp\FJL.exe
C:\sccfg.sys
Folder::
C:\FOUND.060
C:\FOUND.059
C:\FOUND.058
C:\FOUND.057
C:\FOUND.056
C:\FOUND.055
C:\FOUND.054
C:\FOUND.053
C:\FOUND.052
C:\FOUND.051
C:\FOUND.050
C:\FOUND.049
Driver::
abp470n5
dfzIw
kxzkm
Winkq62
Yla19
d1d76351
e43d787d
muxrxroeg
partizan
fjl
Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=-
"DisableRegistryTools"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Winkq62.sys]
RegLockDel::
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:- Combofix.txt
- A new HijackThis log.