We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

trojan downloader help

13

Comments

  • jinky67
    jinky67 Posts: 47,812 Forumite
    ComboFix 09-06-26.02 - jinky 27/06/2009 20:54.4 - NTFSx86
    Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.955.135 [GMT 1:00]
    Running from: c:\users\jinky\Downloads\ComboFix.exe
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
    .

    ((((((((((((((((((((((((( Files Created from 2009-05-27 to 2009-06-27 )))))))))))))))))))))))))))))))
    .

    2009-06-27 19:39 . 2009-06-27 20:00
    d
    w- c:\users\jinky\AppData\Local\temp
    2009-06-22 15:53 . 2009-06-22 15:54
    d
    w- c:\users\jinky\AppData\Roaming\Any Video Converter
    2009-06-22 15:53 . 2009-06-22 15:54
    d
    w- c:\program files\Any Video Converter
    2009-06-18 13:23 . 2009-06-18 13:23
    d
    w- c:\users\jinky\AppData\Roaming\live-player
    2009-06-18 13:23 . 2009-06-18 13:23
    d
    w- c:\program files\Live-Player
    2009-06-13 19:12 . 2009-04-30 12:37 428544 ----a-w- c:\windows\system32\EncDec.dll
    2009-06-13 19:12 . 2009-04-30 12:37 293376 ----a-w- c:\windows\system32\psisdecd.dll
    2009-06-10 18:29 . 2009-04-21 11:55 2033152 ----a-w- c:\windows\system32\win32k.sys
    2009-06-09 22:24 . 2009-06-25 17:25
    d
    w- c:\users\jinky\AppData\Roaming\Spotify
    2009-06-09 22:24 . 2009-06-09 22:24
    d
    w- c:\users\jinky\AppData\Local\Spotify
    2009-06-09 22:24 . 2009-06-09 22:24
    d
    w- c:\program files\Spotify
    2009-06-05 16:45 . 2009-06-05 16:49
    d
    w- c:\users\jinky\AppData\Roaming\Dropbox
    2009-06-04 18:08 . 2009-06-04 18:10
    d
    w- c:\program files\QuickTime
    2009-06-04 18:08 . 2009-06-04 18:08
    d
    w- c:\programdata\Apple Computer
    2009-06-02 13:27 . 2009-06-02 13:27
    d
    w- c:\users\jinky\AppData\Local\WinZip
    2009-06-02 13:26 . 2009-06-02 13:27
    d
    w- c:\programdata\WinZip
    2009-06-01 13:14 . 2009-06-01 13:14 782664 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
    2009-05-29 07:39 . 2009-05-29 07:39
    d
    w- c:\users\jinky\AppData\Local\Apple Computer
    2009-05-29 07:35 . 2009-05-29 07:35
    d
    w- c:\users\jinky\AppData\Local\Apple
    2009-05-29 07:35 . 2009-05-29 07:35
    d
    w- c:\program files\Apple Software Update
    2009-05-29 07:35 . 2009-05-29 07:35
    d
    w- c:\programdata\Apple

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-06-27 15:22 . 2008-08-07 16:54
    d
    w- c:\program files\Common Files\Wise Installation Wizard
    2009-06-26 19:31 . 2009-01-27 13:46
    d
    w- c:\program files\Malwarebytes' Anti-Malware
    2009-06-25 17:54 . 2009-03-26 18:43
    d
    w- c:\program files\Mozilla Firefox 3.1 Beta 3
    2009-06-25 17:33 . 2009-05-07 12:52 1 ----a-w- c:\users\jinky\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
    2009-06-17 10:27 . 2009-04-20 12:06 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2009-06-17 10:27 . 2009-04-20 12:06 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
    2009-06-12 16:15 . 2009-01-28 09:00 1356 ----a-w- c:\users\jinky\AppData\Local\d3d9caps.dat
    2009-06-10 21:34 . 2008-08-07 17:00
    d
    w- c:\program files\Microsoft Works
    2009-06-10 21:33 . 2008-08-07 16:58
    d
    w- c:\programdata\Microsoft Help
    2009-06-04 18:00 . 2009-05-28 18:30
    d
    w- c:\program files\DivX
    2009-06-04 17:59 . 2009-05-28 18:30
    d
    w- c:\program files\Common Files\DivX Shared
    2009-06-01 12:14 . 2009-01-02 23:40 410984 ----a-w- c:\windows\system32\deploytk.dll
    2009-05-30 21:14 . 2009-05-28 19:41
    d
    w- c:\users\jinky\AppData\Roaming\DivX
    2009-05-28 18:31 . 2009-05-28 18:31
    d
    w- c:\program files\Common Files\PX Storage Engine
    2009-05-27 19:42 . 2009-05-27 19:42
    d
    w- c:\programdata\WindowsSearch
    2009-05-13 09:14 . 2006-11-02 11:18
    d
    w- c:\program files\Windows Mail
    2009-05-07 12:51 . 2009-05-07 12:51
    d
    w- c:\users\jinky\AppData\Roaming\OpenOffice.org
    2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
    2009-05-01 21:02 . 2009-05-01 21:02 823296 ----a-w- c:\windows\system32\divx_xx07.dll
    2009-05-01 21:02 . 2009-05-01 21:02 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
    2009-05-01 21:02 . 2009-05-01 21:02 811008 ----a-w- c:\windows\system32\divx_xx16.dll
    2009-05-01 21:02 . 2009-05-01 21:02 802816 ----a-w- c:\windows\system32\divx_xx11.dll
    2009-05-01 21:02 . 2009-05-01 21:02 685056 ----a-w- c:\windows\system32\DivX.dll
    2009-05-01 18:30 . 2009-05-01 18:30 3366912 ----a-w- c:\windows\system32\GPhotos.scr
    2009-04-24 16:05 . 2009-06-10 18:28 827904 ----a-w- c:\windows\system32\wininet.dll
    2009-04-24 16:02 . 2009-06-10 18:28 78336 ----a-w- c:\windows\system32\ieencode.dll
    2009-04-24 13:44 . 2009-06-10 18:28 26624 ----a-w- c:\windows\system32\ieUnatt.exe
    2009-04-23 12:43 . 2009-06-10 18:28 784896 ----a-w- c:\windows\system32\rpcrt4.dll
    2009-04-23 12:42 . 2009-06-10 18:28 636928 ----a-w- c:\windows\system32\localspl.dll
    2009-03-25 00:31 . 2009-03-25 00:31 122880 ----a-w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
    2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
    2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
    .

    ((((((((((((((((((((((((((((( SnapShot_2009-06-27_15.31.15 )))))))))))))))))))))))))))))))))))))))))
    .
    + 2006-11-02 13:05 . 2009-06-27 19:47 74968 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
    + 2008-11-27 12:23 . 2009-06-27 19:47 11584 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-870120329-3058545315-4065139281-1000_UserData.bin
    + 2008-11-27 12:18 . 2009-06-27 19:43 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    - 2008-11-27 12:18 . 2009-06-27 15:11 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
    + 2008-11-27 12:18 . 2009-06-27 19:43 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    - 2008-11-27 12:18 . 2009-06-27 15:11 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
    + 2008-11-27 12:18 . 2009-06-27 19:43 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2008-11-27 12:18 . 2009-06-27 15:11 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
    - 2009-06-27 15:11 . 2009-06-27 15:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2009-06-27 15:11 . 2009-06-27 19:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
    + 2009-06-27 15:11 . 2009-06-27 19:42 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    - 2009-06-27 15:11 . 2009-06-27 15:11 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe" [2008-04-24 430080]
    "MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-02-06 3885408]
    "filehippo.com"="c:\program files\filehippo.com\UpdateChecker.exe" [2008-12-31 146432]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-14 1348904]
    "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-03-25 30192]
    "Google EULA Launcher"="c:\program files\Google\Google EULA\GoogleEULALauncher.exe" [2008-05-28 20480]
    "Toshiba TEMPO"="c:\program files\Toshiba TEMPRO\Toshiba.Tempo.UI.TrayApplication.exe" [2008-04-24 103824]
    "topi"="c:\program files\TOSHIBA\Toshiba Online Product Information\topi.exe" [2007-07-10 581632]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-06-25 150040]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-06-25 170520]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2008-06-25 145944]
    "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2008-01-17 431456]
    "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2008-06-24 509816]
    "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2008-05-09 716800]
    "Toshiba Registration"="c:\program files\Toshiba\Registration\ToshibaRegistration.exe" [2008-01-11 574864]
    "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
    "Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
    "fssui"="c:\program files\Windows Live\Family Safety\fsui.exe" [2009-02-06 454000]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
    "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-06-01 148888]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
    "NDSTray.exe"="NDSTray.exe" [BU]
    "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2008-04-08 6037504]
    "Skytel"="Skytel.exe" - c:\windows\SkyTel.exe [2007-11-20 1826816]

    c:\users\jinky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-9-12 384000]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-5-11 525640]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux"=wdmaud.drv

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{43597A08-21ED-471C-AE18-6998A0F6D651}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "{3BA6AD5F-B5C4-4A70-9B1E-DA764E2474B9}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
    "TCP Query User{96CA63A0-F8AA-4E47-B4FE-550B6F339306}c:\\users\\jinky\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\xdn869rm\\housecall66[1].exe"= UDP:c:\users\jinky\appdata\local\microsoft\windows\temporary internet files\content.ie5\xdn869rm\housecall66[1].exe:housecall66[1].exe
    "UDP Query User{EEC6CC16-EB4E-4DC7-870A-3C904ECFCEC5}c:\\users\\jinky\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\xdn869rm\\housecall66[1].exe"= TCP:c:\users\jinky\appdata\local\microsoft\windows\temporary internet files\content.ie5\xdn869rm\housecall66[1].exe:housecall66[1].exe
    "{FE6BA825-D158-40DD-8868-79101F23E0F8}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
    "{26F66326-08FF-47EF-A069-36CF7C6A5F9A}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
    "{6991FC5A-4799-416D-A2AA-603411194143}"= UDP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
    "{132AACF6-9E35-430F-963D-CF879E042C08}"= TCP:c:\program files\Virgin Broadband Wireless\Wireless Manager.exe:Wireless Manager
    "{5D85B81E-8A67-480C-8A48-917A9CB8B415}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync
    "TCP Query User{9CAE2C58-4310-47D8-AB9D-CFDA4841A0D9}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "UDP Query User{198EC51B-2544-4B8E-8CCC-B32803D3549A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
    "TCP Query User{C49605CD-F65D-4F4D-95F1-829F2E398DA1}c:\\program files\\spotify\\spotify.exe"= UDP:c:\program files\spotify\spotify.exe:Spotify
    "UDP Query User{8299B871-AE05-4EED-A0AE-6D7D335A1C14}c:\\program files\\spotify\\spotify.exe"= TCP:c:\program files\spotify\spotify.exe:Spotify

    R1 aswSP;avast! Self Protection;c:\windows\System32\drivers\aswSP.sys [07/01/2009 21:59 114768]
    R1 RtlProt;Realtke RtlProt WLAN Utility Protocol Driver;c:\windows\System32\drivers\RtlProt.sys [27/11/2008 13:26 25896]
    R2 aswFsBlk;aswFsBlk;c:\windows\System32\drivers\aswFsBlk.sys [07/01/2009 21:59 20560]
    R2 aswMonFlt;aswMonFlt;c:\windows\System32\drivers\aswMonFlt.sys [07/01/2009 21:58 51792]
    R2 ConfigFree Service;ConfigFree Service;c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe [17/04/2008 00:19 40960]
    R2 fssfltr;FssFltr;c:\windows\System32\drivers\fssfltr.sys [11/02/2009 03:42 55264]
    R2 fsssvc;Windows Live Family Safety;c:\program files\Windows Live\Family Safety\fsssvc.exe [06/02/2009 19:08 533360]
    R2 TempoMonitoringService;Notebook Performance Tuning Service ;c:\program files\Toshiba TEMPRO\TempoSVC.exe [24/04/2008 10:21 99720]
    R2 TOSHIBA SMART Log Service;TOSHIBA SMART Log Service;c:\program files\TOSHIBA\SMARTLogService\TosIPCSrv.exe [06/02/2008 15:12 126976]
    R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [07/08/2008 17:24 7168]
    R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;c:\windows\System32\drivers\RTL8187B.sys [24/10/2008 12:43 342016]
    S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [07/08/2008 17:54 30192]
    .
    Contents of the 'Scheduled Tasks' folder

    2009-06-27 c:\windows\Tasks\User_Feed_Synchronization-{097E59B4-E338-4467-A135-E88C3842F328}.job
    - c:\windows\system32\msfeedssync.exe [2008-01-21 02:24]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://www.google.co.uk/
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=TSEA&bmod=TSEA
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: &Search
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
    IE: {{76577871-04EC-495E-A12B-91F7C3600AFA} - http://rover.ebay.com/rover/1/710-44557-9400-3/4
    IE: {{8A918C1D-E123-4E36-B562-5C1519E434CE} - http://www.amazon.co.uk/exec/obidos/redirect-home?!!!!!Toshibaukbholink-21&site=home
    DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} - hxxp://prerelease.trendmicro-europe.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
    FF - ProfilePath - c:\users\jinky\AppData\Roaming\Mozilla\Firefox\Profiles\j7p0uvx1.default\
    FF - prefs.js: browser.search.selectedEngine - MyWebSearch
    FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/
    FF - prefs.js: keyword.URL - hxxp://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=FomE3P9NvsszOwGr0I0ZUg&st=kwd&o=kwd&url=http://edits.mywebsearch.com/toolbaredits/barsearch.jhtml&searchfor=
    FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
    FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npdivx32.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npDivxPlayerPlugin.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npnul32.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin2.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin3.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin4.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin5.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin6.dll
    FF - plugin: c:\program files\Mozilla Firefox 3.1 Beta 3\plugins\npqtplugin7.dll
    FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
    FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}

    ---- FIREFOX POLICIES ----
    FF - user.js: yahoo.homepage.dontask - true.

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-06-27 20:59
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    TOSCDSPD = c:\program files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe?/i???????5`?u??P?#?x?#???#???#??

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    LOCKED REGISTRY KEYS

    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    "MSCurrentCountry"=dword:000000b5
    .
    Completion time: 2009-06-27 21:02
    ComboFix-quarantined-files.txt 2009-06-27 20:02
    ComboFix2.txt 2009-06-27 15:33
    ComboFix3.txt 2009-04-20 16:23

    Pre-Run: 46,630,621,184 bytes free
    Post-Run: 46,597,971,968 bytes free

    218 --- E O F --- 2009-06-26 06:23
    :heartpulsOnce a Flylady, always a Flylady:heartpuls
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    You copy and paste the info I gave in RED and save it as "CFScript"

    You drag that notepad file into combofix (Nothing to do with combofix.txt)
    :idea:
  • jinky67
    jinky67 Posts: 47,812 Forumite
    I did save it as that

    And did it again

    Is that log wrong then?
    :heartpulsOnce a Flylady, always a Flylady:heartpuls
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Must be the wrong log. If the notepad file (CFScript) had worked it would say so at the top of the log (Which it doesnt)

    Im not sure what your doing but the complete file should read 'CFScript.txt' and you simply left click and DRAG it ONTO combofix
    :idea:
  • jinky67
    jinky67 Posts: 47,812 Forumite
    right i opened combofix again and tried to drag the file it wouldnt let me keep showing as

    one of these AccessDenied.jpg
    :heartpulsOnce a Flylady, always a Flylady:heartpuls
  • jinky67
    jinky67 Posts: 47,812 Forumite
    Kapersky scan finished

    found nothing
    :heartpulsOnce a Flylady, always a Flylady:heartpuls
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Whats the file show as (the complete name?)
    :idea:
  • jinky67
    jinky67 Posts: 47,812 Forumite
    I dont know what you mean:cool:
    :heartpulsOnce a Flylady, always a Flylady:heartpuls
  • jinky67
    jinky67 Posts: 47,812 Forumite
    Just bumping again :D
    :heartpulsOnce a Flylady, always a Flylady:heartpuls
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    For now you may as well leave it and see how it goes
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.6K Banking & Borrowing
  • 254.2K Reduce Debt & Boost Income
  • 455.1K Spending & Discounts
  • 246.7K Work, Benefits & Business
  • 603.1K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.7K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.