Hello,Tinker & Welcome
First thing i need for you to do is move HijackThis from the Desktop
to a folder in C:\Drive like so
C:\HJT
Download the LOP uninstaller from here:
http://lop.com/new_uninstall.exe
or here:
http://www.thespykiller.co.uk/files/lopremover.exe
When its done,re-start your computer.
Press control-alt-delete to get into the task manager and end the follow processes if they exist:
media.exe
nvrtbr.exe
hecklicense.ex e
If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. if it is uncheck it and try again.
Check the following items in HijackThis.
Close all windows except HijackThis and click Fix checked:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.jkhmfeehiqwcjfppldkeyjlns...Hph8wFXEpIaCKM SP5wPrKJT7i0BO.cgi
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.xrdnljpuogaqy.com/aE0odAO...EFT611Ec0.html
O2 - BHO: (no name) - {0B3BD32F-1D0D-339C-EE2A-288C3756718A} - C:\DOCUME~1\craig\APPLIC~1\MATHST~1\Frag Scr.exe
O2 - BHO: (no name) - {50F82689-80D3-37C4-B813-336AF383E946} - C:\DOCUME~1\craig\APPLIC~1\MATHST~1\Frag Scr.exe
O2 - BHO: C:\WINDOWS\lbbho.dll - {55C5123A-1760-417D-9279-A5607ED27121} - C:\WINDOWS\lbbho.dll
O2 - BHO: - {7E573506-7EFF-4C98-9D24-AE8FCB1672EA} - C:\WINDOWS\lbbho.dll
O2 - BHO: C:\WINDOWS\lbbho.dll - {92D0E778-DC38-48B8-846A-43224A25A2FA} - C:\WINDOWS\lbbho.dll
O2 - BHO: - {CA0A8449-481F-4EBB-9E5D-3ED55E5FA26F} - C:\WINDOWS\lbbho.dll
O2 - BHO: - {DD90FD60-F054-4BF5-9FE3-B2BAD2FB6188} - C:\WINDOWS\lbbho.dll
O2 - BHO: - {EBF812C9-DF94-4E5B-BE69-A59D92A07819} - C:\WINDOWS\lbbho.dll
O2 - BHO: - {F84AF90D-B446-49CD-BC75-4CF877CF1F57} - C:\WINDOWS\lbbho.dll
O2 - BHO: - {FFAD0D76-C9F3-41A7-BBBC-178D61B85C7C} - C:\WINDOWS\lbbho.dll
O4 - HKLM\..\Run: [Extra Roam Vga Bike] C:\Documents and Settings\All Users\Application Data\Remote user extra roam\logo media.exe
O4 - HKCU\..\Run: [nvrtbr] C:\WINDOWS\System32\nvrtbr.exe
O4 - HKCU\..\Run: [LIES RDR] C:\DOCUME~1\craig\APPLIC~1\THEDEN~1\hecklicense.ex e
O8 - Extra context menu item: &Search -
http://bar.mywebsearch.com/menusearc...p=ZNxdm41447US
O16 - DPF: {4D7F48C0-CB49-4EA6-97D4-04F4EACC2F3B} (InstallShield Setup Player 2K2) -
http://sib1.od2.com/common/Member/Cl.../OCI/setup.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/26dee30d...p/RdxIE601.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) -
http://kr.pristontale.com/nprotect/nprotect/npx.cab
O20 - Winlogon Notify: hobbix - hobbix.dll (file missing)
Make sure you can view hidden and system files: Instructions
here
Then Boot to safe mode: Instructions
here
Delete the following files\folders IF still present:
C:\Documents and Settings\All Users\Application Data\
Remote user extra roam\<--This folder
C:\WINDOWS\System32\
nvrtbr.exe<---This file
C:\DOCUME~1\craig\APPLIC~1\
THEDEN~1\<--This folder the name maybe longer then this
C:\WINDOWS\
lbbho.dll<---This file
Still in Safe Mode do a file Search for this file if found delete it
hobbix.dll
Then do a reboot till us how it is running & show us new logfile.
HGD