Download the
Pocket KillboxUNZIP it to a folder of your choice
Download and Install this small program
to help clean your temp folders,cookies,prefetch folder, etc...
Windows CleanupInstall for now, don't run a scan yet
Please save these instructions to a Notepad file and save it to your Desktop
and then Disconnect from the Internet
Run Pocket KillBox
In the
Full Path of File to Delete box, copy and paste the entire line directly below in bold, do not type this in
C:\WINDOWS\System32\mdbo.dllSelect the radio button to
Delete on RebootClick The Red circle and a white X
When prompted to Replace on Reboot, click YES
If prompted to Reboot Now, Click NO
Do the same for this file name
C:\DOCUME~1\Wendy\LOCALS~1\Temp\se.dllBut this time allow the computer to Reboot
or Restart anyways
Please try and restart your computer into safe mode
You can do this by tapping the F8 key as the system is booting up on restart
In safe mode
Do another scan with Hijackthis and put a check next to these entries:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Wendy\LOCALS~1\Temp\se.dll/sp.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\DOCUME~1\Wendy\LOCALS~1\Temp\se.dll/sp.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {AC4809AF-C17A-4482-B5EC-4AB2CC5F82E4} - C:\WINDOWS\System32\mdbo.dll
O18 - Filter: text/html - {8B8BE643-A523-4881-B2E5-FB78D9B4550A} - C:\WINDOWS\System32\mdbo.dll
O18 - Filter: text/plain - {8B8BE643-A523-4881-B2E5-FB78D9B4550A} - C:\WINDOWS\System32\mdbo.dllAfter you have ticked the above entries, close
All other open windows, including this one
Leave Hijackthis open and click FIX CHECKED
OK the prompt and exit Hijackthis
Open Windows CleanUp!>>START>>All programs>>Cleanup!
Click on the CleanUp button, let it finish scanning for files, when it's done
Restart back to Normal mode
Don't open a browser yet, instead access Internet Options via Control Panel
Under the Programs tab "Reset Web Settings"
Under the General tab---Reset home page
Post back a fresh Hijackthis log afterwards