We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Spoof Paypal e.mail. Am I infected??

2»

Comments

  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Whats this 'Birdstep Technology' all about?

    Open notepad and copy/paste the text in RED below

    File::
    c:\windows\system32\drivers\Msft_User_WpdFs_01_00_ 00.Wdf



    Save this as "CFScript"

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.



    then run a KASPERSKY ONLINE SCAN (click to scan 'MY COMPUTER')
    http://www.kaspersky.co.uk/virusscanner
    Please post the complete log it creates
    :idea:
  • Tatty_
    Tatty_ Posts: 1,788 Forumite
    Part of the Furniture Combo Breaker
    Birdstep technology is to do with the 3 connect software, I access the internet through a dongle.

    I didn't save the Combofix to my desktop. Can I not just run it again from my downloads folder? Does it not look right or have I done something wrong? Why have I got to run it again?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Because this file needs removing ~
    c:\windows\system32\drivers\Msft_User_WpdFs_01_00_ 00.Wdf
    :idea:
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Scratch the above. (leave it for now)

    Im not 100% on what the file is
    :idea:
  • Tatty_
    Tatty_ Posts: 1,788 Forumite
    Part of the Furniture Combo Breaker
    Ooooo I had already tried to do it but it wouldn't let me. It said CFScript appeared to be incorrectly spelt. Just as well then :-)

    Should I run Kapersky or leave things as they are?

    k
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Id run kaspersky as a precaution personally (Though im still thinking that file is dodgy whatever the outcome)
    :idea:
  • Tatty_
    Tatty_ Posts: 1,788 Forumite
    Part of the Furniture Combo Breaker
    Which file? The original google file that I blocked?

    Ok, I'll run Kaspersky

    k
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    I ment the one you nearly removed ~

    "Because this file needs removing ~
    c:\windows\system32\drivers\Msft_User_WpdFs_01_00_ 00.Wdf"
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.5K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.5K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.4K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.