OK then. Let's wait with new AV program installation until we're done with Combofix.
Just make sure, your firewall is up.
1. Please open Notepad- Click Start , then Run
- Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
Code:
File::
c:\windows\system32\mbciae.exe
c:\windows\system32\mdgvrr.exe
c:\windows\system32\dsibm.exe
c:\windows\system32\jwxrmta.exe
C:\up2.exe
c:\windows\system32\drivers\dobelbez.sys
c:\windows\system32\drivers\hwvkknrf.sys
c:\documents and settings\Menendez\qmtwvh.exe
c:\windows\system32\drivers\ndisvvan.sys
Folder::
c:\documents and settings\Menendez\Application Data\AVG7
c:\documents and settings\LocalService.NT AUTHORITY\Application Data\AVG7
c:\documents and settings\All Users.WINDOWS\Application Data\avg7
C:\$AVG8.VAULT$
c:\windows\system32\drivers\Avg(2)
c:\program files\AVG(2)
c:\documents and settings\All Users.WINDOWS\Application Data\avg8(2)
C:\AVGTemp
c:\documents and settings\Menendez\Application Data\AVG8
c:\documents and settings\Menendez\Application Data\Panda Security
c:\documents and settings\All Users.WINDOWS\Application Data\Panda Security
Driver::
dobelbez
hwvkknrf
Registry::
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"restorer32_a"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"restorer32_a"=-
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\dobelbez.sys]
[HKLM\~\services\sharedaccess\parameters\firewallpo licy\standardprofile\AuthorizedApplications\List]
"poxy4.exe"=-
"skp66.exe"=-
"ud32.exe"=-
"c:\\WINDOWS\\system32\\jwxrmta.exe"=-
"c:\\WINDOWS\\system32\\dsibm.exe"=-
"c:\\WINDOWS\\system32\\mdgvrr.exe"=-
RegLockDel::
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:- Combofix.txt
- A new HijackThis log.