Yet ANOTHER problem.

1246

Comments

  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Hi Rik.

    Thanks for that.

    Removed the offending Asquared entry.

    Problem I have now is that whilst trying to run Combofix in regular mode I am getting 'SOME FILES COULD NOT BE CREATED - PLEASE CLOSE ALL APPLICATIONS, REBOOT AND RESTART THIS APPLICATION' Message.

    Tried rebooting and same thing happens even though no other applications are apparantly running.
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Tried a fresh combofix download?

    Tried a registry clean up using ccleaner?
    :idea:
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Did a reg clean and tried downloadsing Combofix but it locked up.

    i note that Combofix isnt in the uninstall list.


    Should I somehow uninstall Combofix before downloading a fresh copy?
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Combofix doesnt install. It just runs when clicked
    :idea:
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Well, Believe it or not and after all that, Combo still complained that Asquared was running yet I remover the reg entry using the prog you suggested.

    Would it be unsafe if I manually removed every Asquared file in the registry using another program?



    Anyway, Combo left me a big file.

    Here it is.


    ComboFix 10-09-14.04 - Terry 15/09/2010 16:17:50.5.2 - x86
    Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2038.1657 [GMT 1:00]
    Running from: g:\downloads\ComboFix.exe
    Command switches used :: c:\documents and settings\Terry\Desktop\CFScript.txt
    AV: a-squared Anti-Malware *On-access scanning enabled* (Updated) {0F8591BB-342B-4493-91C3-4E948ED21255}
    AV: avast! Antivirus *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
    FW: COMODO Firewall *disabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B}
    FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
    FILE ::
    "c:\documents and settings\Terry\Application Data\System2583.Data.DB.dat"
    "c:\windows\cadkasdeinst01e.exe"
    "c:\windows\Sys6519.Data DB.dat"
    "c:\windows\system32\edacded0.dat"
    "c:\windows\system32\epmntdrv.sys"
    "c:\windows\system32\EuEpmGdi.dll"
    "c:\windows\system32\EuGdiDrv.sys"
    "c:\windows\system32\setupempdrv03.exe"
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    ---- Previous Run
    .
    c:\documents and settings\All Users\Start Menu\Programs\Startup\.lnk
    c:\documents and settings\Terry\Application Data\System2583.Data.DB.dat
    c:\windows\cadkasdeinst01e.exe
    c:\windows\Sys6519.Data DB.dat
    c:\windows\system32\edacded0.dat
    c:\windows\system32\epmntdrv.sys
    c:\windows\system32\EuEpmGdi.dll
    c:\windows\system32\EuGdiDrv.sys
    c:\windows\system32\setupempdrv03.exe
    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    \Legacy_epmntdrv
    \Legacy_EuGdiDrv
    \Service_epmntdrv
    \Service_EuGdiDrv

    ((((((((((((((((((((((((( Files Created from 2010-08-15 to 2010-09-15 )))))))))))))))))))))))))))))))
    .
    2010-09-15 15:05 . 2010-09-15 15:05
    d
    w- c:\windows\LastGood
    2010-09-15 10:53 . 2010-09-15 10:53
    d
    w- c:\documents and settings\Terry\Local Settings\Application Data\Stardock_Corporation
    2010-09-15 10:18 . 2010-09-15 11:05
    d
    w- C:\32788R22FWJFW.1.tmp
    2010-09-14 17:26 . 2010-09-14 17:26
    d
    w- c:\documents and settings\Terry\Application Data\Stardock
    2010-09-14 17:26 . 2010-09-14 17:26
    dc-h--w- c:\documents and settings\All Users\Application Data\{56FC2B0D-3D08-45E7-B370-9A9DACA17E2F}
    2010-09-14 17:26 . 2009-02-10 16:35 2681648 -c--a-w- c:\documents and settings\All Users\Application Data\{56FC2B0D-3D08-45E7-B370-9A9DACA17E2F}\SoundPackager_setup.exe
    2010-09-13 16:33 . 2010-09-13 16:33 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
    2010-09-13 16:06 . 2010-09-13 16:12
    d
    w- C:\divx
    2010-09-13 16:02 . 2010-09-13 16:27
    d
    w- c:\documents and settings\Terry\Application Data\Clip Extractor
    2010-09-13 12:53 . 2010-09-13 12:53
    d
    w- c:\documents and settings\Terry\Application Data\Toolbar4
    2010-09-13 12:53 . 2010-09-13 12:53
    d
    w- c:\program files\Microsoft.NET
    2010-09-13 09:50 . 2010-09-13 09:50 389120 ----a-w- c:\windows\system32\CF10921.exe
    2010-09-12 19:06 . 2010-09-12 19:06
    d
    w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
    2010-09-12 17:56 . 2010-09-12 17:56
    d
    w- c:\windows\system32\wbem\Repository
    2010-09-11 21:31 . 2010-09-12 16:26
    d
    w- C:\RECYCLER(2)
    2010-09-08 17:23 . 2010-09-08 17:23
    d
    w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google
    2010-09-08 17:18 . 2010-09-08 17:18
    d
    w- c:\documents and settings\Terry\Local Settings\Application Data\Temp
    2010-09-08 17:18 . 2010-09-08 17:18
    d
    w- c:\documents and settings\LocalService\Local Settings\Application Data\Google
    2010-09-08 16:08 . 2010-07-11 05:54 57344 ----a-w- c:\windows\system32\CleanMem.exe
    2010-09-08 16:08 . 2008-09-19 16:37 121856 ----a-w- c:\windows\system32\schtasks.exe
    2010-09-08 16:08 . 2010-09-08 16:08
    d
    w- c:\windows\CleanMem
    2010-09-08 11:36 . 2010-09-08 11:36
    d
    w- c:\program files\FamilySearch
    2010-09-06 16:49 . 2010-09-06 16:49
    d
    w- c:\documents and settings\Terry\Local Settings\Application Data\Amazon
    2010-09-06 16:49 . 2010-09-06 16:49
    d
    w- c:\program files\Amazon
    2010-09-05 18:00 . 2010-05-21 13:14 221568
    w- c:\windows\system32\MpSigStub.exe
    2010-09-05 17:59 . 2010-09-05 17:59
    d
    w- c:\program files\Windows Defender
    2010-09-02 12:19 . 2010-07-27 17:42 1774720 ----a-w- c:\windows\system32\BootMan.exe
    2010-09-01 18:51 . 2010-09-01 18:51
    d
    w- c:\documents and settings\All Users\Application Data\UAB
    2010-09-01 18:51 . 2010-09-01 19:14
    d
    w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters Inc
    2010-09-01 18:51 . 2010-09-01 18:51
    d
    w- c:\documents and settings\Terry\Local Settings\Application Data\PC_Drivers_Headquarters
    2010-09-01 18:49 . 2010-09-01 18:49
    d
    w- c:\documents and settings\Terry\Application Data\GetRightToGo
    2010-09-01 17:48 . 2010-09-01 17:49
    d
    w- c:\program files\jv16 PowerTools
    2010-09-01 09:22 . 2010-09-14 14:55
    d---a-w- c:\documents and settings\All Users\Application Data\TEMP
    2010-08-30 11:52 . 2010-08-30 11:52
    d
    w- c:\documents and settings\Terry\Application Data\VSRevoGroup
    2010-08-28 13:09 . 2010-08-28 13:09
    d
    w- c:\program files\Coupon Printer
    2010-08-28 13:01 . 2010-08-28 13:01
    d
    w- c:\program files\ACD Systems
    2010-08-28 13:00 . 2010-08-28 13:00
    d
    w- c:\program files\Hide Wizard
    2010-08-28 11:17 . 2004-08-04 10:00 753236 -c--a-w- c:\windows\system32\dllcache\rvseres.dll
    2010-08-28 11:16 . 2010-06-18 13:36 3558912 -c--a-w- c:\windows\system32\dllcache\moviemk.exe
    2010-08-28 11:16 . 2008-04-14 00:12 7680 -c--a-w- c:\windows\system32\dllcache\wmm2ext.dll
    2010-08-28 11:16 . 2008-04-14 00:12 5632 -c--a-w- c:\windows\system32\dllcache\wmm2res2.dll
    2010-08-28 11:16 . 2008-04-14 00:12 502272 -c--a-w- c:\windows\system32\dllcache\wmm2fxa.dll
    2010-08-28 11:16 . 2008-04-14 00:12 4256768 -c--a-w- c:\windows\system32\dllcache\wmm2res.dll
    2010-08-28 11:16 . 2008-04-14 00:12 4096 -c--a-w- c:\windows\system32\dllcache\wmm2eres.dll
    2010-08-28 11:16 . 2008-04-14 00:12 402432 -c--a-w- c:\windows\system32\dllcache\wmm2filt.dll
    2010-08-28 11:16 . 2008-04-14 00:12 325632 -c--a-w- c:\windows\system32\dllcache\wmm2fxb.dll
    2010-08-28 11:16 . 2008-04-14 00:12 167936 -c--a-w- c:\windows\system32\dllcache\wmm2ae.dll
    2010-08-28 11:07 . 2008-04-14 00:12 102400 -c--a-w- c:\windows\system32\dllcache\msjro.dll
    2010-08-28 11:05 . 2010-08-28 11:05
    d
    w- c:\program files\Stardock
    2010-08-28 11:05 . 2010-08-28 11:05
    d
    w- c:\program files\PC Tools Firewall Plus
    2010-08-28 11:04 . 2010-08-28 11:04
    d
    w- c:\program files\Everything
    2010-08-28 11:04 . 2010-08-28 11:04
    d
    w- c:\program files\AlienGUIse
    2010-08-27 14:02 . 2010-08-27 14:02
    d
    w- c:\documents and settings\Terry\Local Settings\Application Data\https://www.dvbportal.de
    2010-08-26 13:21 . 2010-08-26 13:21
    d
    w- c:\program files\Ashampoo
    2010-08-23 15:38 . 2010-08-23 15:38 65536 ----a-w- c:\windows\IFinst27.exe
    2010-08-23 13:10 . 2010-08-23 13:10 2944904 ----a-w- c:\documents and settings\Terry\Application Data\Mozilla\Firefox\Profiles\hcc9h5r6.default\extensions\toolbar@ask.com\chrome\temp\askToolbar.exe
    2010-08-23 10:17 . 2010-08-30 09:44
    d
    w- C:\ks360
    2010-08-23 08:20 . 2010-08-20 07:03 100280 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMLauncher.exe
    2010-08-22 22:34 . 2010-08-22 22:34
    d
    w- c:\program files\DIFX
    2010-08-22 22:34 . 2010-08-22 22:34
    d
    w- c:\program files\infineon
    2010-08-22 22:34 . 2009-05-12 14:53 16896 ----a-w- c:\windows\system32\drivers\FlashUsb.sys
    2010-08-22 22:22 . 2010-08-22 22:22
    d
    w- c:\program files\LG Electronics
    2010-08-22 17:36 . 2010-08-23 05:41 329656 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
    2010-08-22 17:36 . 2010-08-23 04:21 1071032 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGUserCSTool.exe
    2010-08-22 17:36 . 2010-08-20 07:03 100280 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\LGMLauncher.exe
    2010-08-22 17:36 . 2010-08-20 06:14 524288 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMUpgradeDL.dll
    2010-08-22 17:36 . 2010-08-19 08:49 106496 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMobileDL.dll
    2010-08-22 17:36 . 2010-05-20 05:49 206784 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CAppUninstall.exe
    2010-08-22 17:36 . 2010-03-16 07:31 24576 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\LGMobileDLRapi.dll
    2010-08-22 17:36 . 2006-05-04 07:33 53248 ----a-w- c:\windows\system32\CommonDL.dll
    2010-08-22 17:35 . 2010-08-23 02:39
    d
    w- c:\documents and settings\All Users\Application Data\LGMOBILEAX
    2010-08-17 22:51 . 2010-08-17 22:51 80090 ----a-w- c:\documents and settings\Terry\Application Data\SMBIOSSP.exe
    2010-08-17 22:18 . 2010-08-29 12:07
    d
    w- c:\documents and settings\Terry\Local Settings\Application Data\Deployment
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-09-15 12:55 . 2008-08-04 17:04
    d
    w- c:\documents and settings\Terry\Application Data\Canon
    2010-09-15 10:42 . 2009-10-28 09:09
    d
    w- c:\documents and settings\Terry\Application Data\GoodSync
    2010-09-13 16:33 . 2010-07-06 18:40
    d
    w- c:\documents and settings\All Users\Application Data\DivX
    2010-09-13 12:52 . 2010-06-16 21:05
    d
    w- c:\documents and settings\All Users\Application Data\OnlineArmor
    2010-09-13 11:50 . 2008-09-12 18:28
    d
    w- c:\program files\Panda Security
    2010-09-12 16:28 . 2009-09-20 08:30
    d
    w- c:\program files\Microsoft Silverlight
    2010-09-12 16:26 . 2010-08-02 16:49
    d
    w- c:\program files\Ask.com
    2010-09-12 12:24 . 2008-08-05 15:59
    d
    w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-09-08 17:17 . 2008-08-05 12:09
    d
    w- c:\program files\Google
    2010-09-07 15:12 . 2010-07-02 16:57 38848 ----a-w- c:\windows\avastSS.scr
    2010-09-07 15:11 . 2008-08-04 22:01 167592 ----a-w- c:\windows\system32\aswBoot.exe
    2010-09-01 19:14 . 2009-02-04 16:24
    d
    w- c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
    2010-09-01 09:32 . 2008-08-05 16:09
    d
    w- c:\documents and settings\Terry\Application Data\Media Player Classic
    2010-08-30 09:46 . 2009-03-20 09:15
    d
    w- c:\documents and settings\Terry\Application Data\NetStat Agent
    2010-08-30 09:44 . 2010-04-15 21:42
    d
    w- c:\program files\Palm
    2010-08-30 09:44 . 2009-10-27 10:44
    d
    w- c:\program files\Canon
    2010-08-30 09:44 . 2009-02-06 12:48
    d
    w- c:\program files\Microsoft Works
    2010-08-30 09:44 . 2008-08-05 09:47
    d
    w- c:\documents and settings\All Users\Application Data\comodo
    2010-08-29 20:00 . 2010-08-15 17:48
    d
    w- c:\documents and settings\Terry\Application Data\Spotify
    2010-08-29 15:32 . 2008-12-20 10:09
    d
    w- c:\documents and settings\Terry\Application Data\Amazon
    2010-08-28 13:04 . 2009-10-28 09:09
    d
    w- c:\program files\Siber Systems
    2010-08-28 11:05 . 2008-08-04 15:15
    d--h--w- c:\program files\InstallShield Installation Information
    2010-08-28 09:45 . 2008-12-14 20:17
    d
    w- c:\documents and settings\Terry\Application Data\Azureus
    2010-08-27 14:51 . 2008-10-01 10:07
    d
    w- c:\program files\MPlayer for Windows
    2010-08-27 09:19 . 2008-12-14 20:15
    d
    w- c:\program files\Vuze
    2010-08-26 13:24 . 2010-06-08 08:41
    d
    w- c:\documents and settings\Terry\Application Data\Ashampoo
    2010-08-15 17:48 . 2010-08-15 17:48 655360 ----a-w- c:\documents and settings\Terry\Application Data\Spotify\Gracenote\gnsdk_sdkmanager.dll
    2010-08-15 17:48 . 2010-08-15 17:48 282624 ----a-w- c:\documents and settings\Terry\Application Data\Spotify\Gracenote\gnsdk_musicid_file.dll
    2010-08-15 17:48 . 2010-08-15 17:48 208896 ----a-w- c:\documents and settings\Terry\Application Data\Spotify\Gracenote\gnsdk_dsp.dll
    2010-08-05 10:07 . 2009-05-29 14:34
    d
    w- c:\program files\StarBurn
    2010-08-04 09:27 . 2008-08-04 15:09 88608 ----a-w- c:\documents and settings\Terry\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-07-22 19:41 . 2010-07-24 17:18 153600 ----a-w- c:\windows\system32\AI_ContextMenu.dll
    2010-07-11 23:21 . 2010-07-06 23:05 57344 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.dll
    2010-07-11 22:52 . 2010-07-11 22:52 56765 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXPlusShortcuts\Uninstaller.exe
    2010-07-11 22:52 . 2010-07-11 22:52 57715 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Player\Uninstaller.exe
    2010-07-11 22:40 . 2010-07-11 22:40 84054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TransferWizard\Uninstaller.exe
    2010-07-11 22:40 . 2010-07-11 22:40 54153 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DFXPlugin\Uninstaller.exe
    2010-07-11 22:16 . 2010-07-06 20:37 1062184 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\Resource.dll
    2010-07-11 22:16 . 2010-07-06 20:37 895256 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Setup\DivXSetup.exe
    2010-07-06 20:37 . 2010-07-06 20:37 56997 ----a-w- c:\documents and settings\All Users\Application Data\DivX\WebPlayer\Uninstaller.exe
    2010-07-06 20:37 . 2010-07-06 20:37 53600 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Update\Uninstaller.exe
    2010-07-06 20:26 . 2010-07-06 20:26 57054 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSDesktopComponents\Uninstaller.exe
    2010-07-06 20:26 . 2010-07-06 20:26 54166 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAVCDecoder\Uninstaller.exe
    2010-07-06 20:05 . 2010-07-06 20:05 57532 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSASPDecoder\Uninstaller.exe
    2010-07-06 20:05 . 2010-07-06 20:05 56458 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DivXDecoderShortcut\Uninstaller.exe
    2010-07-06 20:05 . 2010-07-06 20:05 54174 ----a-w- c:\documents and settings\All Users\Application Data\DivX\DSAACDecoder\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 54128 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Converter\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 54644 ----a-w- c:\documents and settings\All Users\Application Data\DivX\TranscodeEngine\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 57409 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ControlPanel\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 54101 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MPEG2Plugin\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 52963 ----a-w- c:\documents and settings\All Users\Application Data\DivX\MSVC80CRTRedist\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 54073 ----a-w- c:\documents and settings\All Users\Application Data\DivX\Qt4.5\Uninstaller.exe
    2010-07-06 19:03 . 2010-07-06 19:03 56969 ----a-w- c:\documents and settings\All Users\Application Data\DivX\ASPEncoder\Uninstaller.exe
    2010-06-30 12:31 . 2004-08-04 10:00 149504 ----a-w- c:\windows\system32\schannel.dll
    2010-06-28 20:37 . 2008-08-04 22:01 46672 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2010-06-28 20:37 . 2008-08-04 22:01 165456 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2010-06-28 20:33 . 2008-08-04 22:01 23376 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2010-06-28 20:32 . 2008-08-04 22:01 100176 ----a-w- c:\windows\system32\drivers\aswmon2.sys
    2010-06-28 20:32 . 2008-08-04 22:01 94544 ----a-w- c:\windows\system32\drivers\aswmon.sys
    2010-06-28 20:32 . 2008-08-04 22:01 17744 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2010-06-28 20:32 . 2008-08-04 22:01 28880 ----a-w- c:\windows\system32\drivers\aavmker4.sys
    2010-06-24 12:22 . 2006-03-04 03:33 916480 ----a-w- c:\windows\system32\wininet.dll
    2010-06-23 13:44 . 2004-08-04 10:00 1851904 ----a-w- c:\windows\system32\win32k.sys
    2010-06-21 21:00 . 2010-06-21 21:00 63488 ----a-w- c:\documents and settings\Terry\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
    2010-06-21 21:00 . 2010-01-10 00:03 117760 ----a-w- c:\documents and settings\Terry\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
    2010-06-21 15:27 . 2004-08-04 10:00 354304 ----a-w- c:\windows\system32\drivers\srv.sys
    2006-05-03 09:06 . 2008-11-20 09:47 163328 --sh--r- c:\windows\system32\flvDX.dll
    2007-02-21 10:47 . 2008-11-20 09:47 31232 --sh--r- c:\windows\system32\msfDX.dll
    2008-03-16 12:30 . 2008-11-20 09:47 216064 --sh--r- c:\windows\system32\nbDX.dll
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Persistence"="c:\windows\system32\igfxpers.exe" [2006-07-21 81920]
    "avast5"="c:\program files\Alwil Software\Avast5\avastUI.exe" [2010-06-28 2837864]
    "@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2010-04-20 6678008]
    "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-04 186904]
    "SigmatelSysTrayApp"="stsystra.exe" [2006-03-20 282624]
    "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
    c:\documents and settings\Terry\Start Menu\Programs\Startup\
    Alienware Dock.lnk - f:\program files\AlienGUIse\AlienwareDock\ObjectDock.exe [2008-9-17 2074360]
    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-2-17 65588]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveTrack"= 1 (0x1)
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
    "NoResolveTrack"= 1 (0x1)
    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
    "DisallowRun"= 1 (0x1)
    [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
    "1"= firefox.exe
    "2"= opera.exe
    "3"= chrome.exe
    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{1214FBE7-4464-4A7E-9958-B5851A7A30A3}"= "d:\program files\RecentX\RecentX\RXShell.dll" [2008-06-12 77824]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "g:\superantispyware\SASSEH.DLL" [2008-05-13 77824]
    "{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2010-04-20 925688]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "UIHost"="c:\documents and settings\All Users\Application Data\TuneUp Software\TuneUp Utilities\WinStyler\tu_logonui.exe"
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2010-05-02 11:53 548352 ----a-w- g:\superantispyware\SASWINLO.DLL
    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
    BootExecute REG_MULTI_SZ autocheck autochk *\0sasnative32
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
    @="Service"
    [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Calendar Magic.lnk]
    backup=c:\windows\pss\Calendar Magic.lnkCommon Startup
    [HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^.lnk]
    backup=c:\windows\pss\.lnkStartup
    [HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^RecentX.lnk]
    backup=c:\windows\pss\RecentX.lnkStartup
    [HKLM\~\startupfolder\C:^Documents and Settings^Terry^Start Menu^Programs^Startup^Secunia PSI.lnk]
    backup=c:\windows\pss\Secunia PSI.lnkStartup
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
    2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Advanced SystemCare 3]
    2010-08-10 14:10 2349776 ----a-w- g:\advanced systemcare 3\AWC.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AudioHQ]
    2000-05-11 00:00 205312 ----a-w- c:\program files\Creative\SBLive\AudioHQ\ahqtb.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avastUI.exe]
    2010-06-28 20:57 2837864
    w- c:\program files\Alwil Software\Avast5\AvastUI.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\B2C_AGENT]
    2010-08-23 05:41 329656 ----a-w- c:\documents and settings\All Users\Application Data\LGMOBILEAX\B2C_Client\B2CNotiAgent.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
    2006-11-16 19:04 139264 ----a-w- c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\captrue.exe]
    2008-09-05 16:55 673280
    w- j:\captrue\captrue.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
    2010-06-03 00:50 1144104 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
    2006-07-21 17:48 98304 ----a-w- c:\windows\system32\igfxtray.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntegryDESK]
    2005-03-22 12:45 618496 ----a-w- i:\integrydesk\IntegryDESK.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
    2008-04-14 00:12 1695232 ----a-w- c:\program files\Messenger\msmsgs.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
    2006-01-12 15:40 155648 ----a-w- c:\program files\Common Files\Ahead\Lib\NeroCheck.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\pb_scheduler_agent]
    2007-04-19 10:37 44544 ----a-w- g:\premium booster\scheduler.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoboForm]
    2010-09-04 21:58 160328 ----a-w- d:\roboform\robotaskbaricon.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
    2009-03-05 15:07 2260480 --sha-r- i:\spybot - search & destroy\Spybot - Search & Destroy\TeaTimer.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2009-06-23 21:06 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
    2010-08-27 11:11 2424560 ----a-w- g:\superantispyware\SUPERANTISPYWARE.EXE
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
    2008-08-22 11:21 68856 ----a-w- c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ThreatFire]
    2008-11-17 13:04 263456 ----a-w- g:\threatfire\TFTray.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
    2010-04-15 22:45 151597 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
    "ThreatFire"=2 (0x2)
    "ioloSystemService"=2 (0x2)
    "ioloFileInfoList"=2 (0x2)
    "NBService"=3 (0x3)
    "WMPNetworkSvc"=3 (0x3)
    "WLSetupSvc"=3 (0x3)
    "usnjsvc"=3 (0x3)
    "gusvc"=3 (0x3)
    "Lavasoft Ad-Aware Service"=2 (0x2)
    "cmdAgent"=2 (0x2)
    "TeamViewer4"=2 (0x2)
    "idsvc"=3 (0x3)
    "NetBurnerService"=3 (0x3)
    "IAANTMON"=2 (0x2)
    "AntiVirSchedulerService"=2 (0x2)
    "SvcOnlineArmor"=2 (0x2)
    "RapportMgmtService"=2 (0x2)
    "OAcat"=2 (0x2)
    "JavaQuickStarterService"=2 (0x2)
    "ACDaemon"=2 (0x2)
    "a2free"=2 (0x2)
    "a2AntiMalware"=3 (0x3)
    "NanoServiceMain"=2 (0x2)
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-disabled]
    "HotKeysCmds"=c:\windows\system32\hkcmd.exe
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    "ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "e:\\Spotify\\spotify.exe"=
    "c:\\Program Files\\Vuze\\Azureus.exe"=
    "c:\\Program Files\\Opera\\opera.exe"=
    R0 hotcore3;hc3ServiceName;c:\windows\system32\drivers\hotcore3.sys [29/04/2009 22:56 40560]
    R0 TfFsMon;TfFsMon;c:\windows\system32\drivers\TfFsMon.sys [25/12/2008 12:41 51488]
    R0 TfSysMon;TfSysMon;c:\windows\system32\drivers\TfSysMon.sys [25/12/2008 12:41 39200]
    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [04/08/2008 23:01 165456]
    R1 cmdGuard;COMODO Firewall Pro Sandbox Driver;c:\windows\system32\drivers\cmdguard.sys [05/08/2008 10:47 133064]
    R1 cmdHlp;COMODO Firewall Pro Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [05/08/2008 10:47 25160]
    R1 NetBurn;Paragon NetBurning Driver;c:\windows\system32\drivers\NetBurn.sys [13/12/2008 14:48 84488]
    R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [16/06/2010 22:04 228216]
    R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [16/06/2010 22:04 24440]
    R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [16/06/2010 22:04 29560]
    R1 SASDIFSV;SASDIFSV;g:\superantispyware\SASDIFSV.SYS [28/07/2009 10:53 12872]
    R1 SASKUTIL;SASKUTIL;g:\superantispyware\SASKUTIL.SYS [28/07/2009 10:53 67656]
    R1 StarPortLite;StarPort Storage Controller (Lite);c:\windows\system32\drivers\StarPortLite.sys [05/08/2008 09:42 95592]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [04/08/2008 23:01 17744]
    R2 dvdmmg;dvdmmg;c:\windows\system32\drivers\dvdmmg.sys [06/09/2007 11:15 5504]
    R2 OAcat;Online Armor Helper Service;c:\program files\Tall Emu\Online Armor\oacat.exe [16/06/2010 22:04 1284600]
    R2 VDDriver;Virtual Disk Driver;d:\virtual disk\VDDriver.sys [22/05/2009 13:39 40952]
    R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [03/11/2006 19:19 13592]
    R3 ArcCD;ArcCD Filter Driver Service;c:\windows\system32\drivers\ArcCD.sys [15/05/2010 18:24 36224]
    R3 WsAudio_DeviceS(1);WsAudio_DeviceS(1);c:\windows\system32\drivers\WsAudio_DeviceS(1).sys [14/05/2009 12:05 16640]
    S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys --> c:\windows\system32\DRIVERS\Lbd.sys [?]
    S1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [08/06/2010 19:01 0]
    S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [08/06/2010 19:01 0]
    S2 SCRCAMHRDRV;ScreenCamera HR;c:\windows\system32\drivers\SCRCAMHRDRV.sys [09/12/2009 10:48 234304]
    S2 SvcOnlineArmor;Online Armor;c:\program files\Tall Emu\Online Armor\oasrv.exe [16/06/2010 22:04 3364856]
    S3 BCASPROT;Advanced System Protector;c:\program files\Systweak\Advanced System Protector\sasprot32.sys [04/05/2009 17:42 6656]
    S3 FlashUSB;FlashUSB;c:\windows\system32\drivers\FlashUsb.sys [22/08/2010 23:34 16896]
    S3 PSI;PSI;c:\windows\system32\drivers\psi_mf.sys [24/03/2009 12:03 7808]
    S3 SASENUM;SASENUM;g:\superantispyware\SASENUM.SYS [28/07/2009 10:53 12872]
    S3 se_filter;System Explorer Filter Driver;c:\windows\system32\drivers\SE_Filter.sys [02/01/2009 12:18 9216]
    S3 TfNetMon;TfNetMon;c:\windows\system32\drivers\TfNetMon.sys [25/12/2008 12:41 33056]
    S4 ArcUdfs;ArcUdfs FileSystem Driver Service;c:\windows\system32\drivers\ArcUdfs.sys [15/05/2010 18:24 134912]
    S4 NetBurnerService;Net Burner iSCSI Service;g:\drive back-up\Net Burner Service\NetBurnerService.exe [13/12/2008 14:48 222984]
    S4 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [15/03/2010 14:47 779496]
    S4 sptd;sptd;c:\windows\system32\drivers\sptd.sys [05/08/2008 09:42 721904]
    S4 TeamViewer4;TeamViewer 4;c:\program files\TeamViewer\Version4\TeamViewer_Service.exe [27/05/2009 13:38 185640]
    S4 ThreatFire;ThreatFire;g:\threatfire\TFService.exe service --> g:\threatfire\TFService.exe service [?]
    --- Other Services/Drivers In Memory ---
    *Deregistered* - ArcRec
    .
    Contents of the 'Scheduled Tasks' folder
    2010-09-15 c:\windows\Tasks\Clean System Memory.job
    - c:\windows\system32\CleanMem.exe [2010-09-08 05:54]
    2010-09-15 c:\windows\Tasks\GlaryInitialize.job
    - g:\glary utilities\initialize.exe [2009-01-12 10:21]
    2010-09-15 c:\windows\Tasks\MP Scheduled Scan.job
    - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 18:20]
    2010-09-15 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job
    - c:\program files\Ask.com\UpdateTask.exe [2010-08-28 14:23]
    2010-09-14 c:\windows\Tasks\User_Feed_Synchronization-{8ED07C76-0A78-4661-870E-CF91F4A2F154}.job
    - c:\windows\system32\msfeedssync.exe [2007-08-13 03:31]
    2009-03-27 c:\windows\Tasks\Wise Registry Cleaner 4.job
    - g:\wise registry cleaner\WiseRegistryCleaner.exe [2009-03-27 21:27]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://by150w.bay150.mail.live.com/default.aspx
    mStart Page = hxxp://www.bigseekpro.com/clipextractor/{A9E3981F-6A11-4EF1-A702-3819AB03CE4F}
    uInternet Connection Wizard,ShellNext = iexplore
    uInternet Settings,ProxyOverride = <local>
    IE: Customize Menu - [URL="file:///d:/roboform/RoboFormComCustomizeIEMenu.html"]file://d:\roboform\RoboFormComCustomizeIEMenu.html[/URL]
    IE: Fill Forms - [URL="file:///d:/roboform/RoboFormComFillForms.html"]file://d:\roboform\RoboFormComFillForms.html[/URL]
    IE: Identities Editor - [URL="file:///d:/roboform/RoboFormComEditIdent.html"]file://d:\roboform\RoboFormComEditIdent.html[/URL]
    IE: Locate Spot on Map by GPS - f:\iexif 2.3\IExifMap.htm
    IE: Password Generator - [URL="file:///d:/roboform/RoboFormComPasswordGenerator.html"]file://d:\roboform\RoboFormComPasswordGenerator.html[/URL]
    IE: RoboForm Toolbar - [URL="file:///d:/roboform/RoboFormComShowToolbar.html"]file://d:\roboform\RoboFormComShowToolbar.html[/URL]
    IE: Save Forms - [URL="file:///d:/roboform/RoboFormComSavePass.html"]file://d:\roboform\RoboFormComSavePass.html[/URL]
    IE: Sothink SWF Catcher - c:\program files\Common Files\SourceTec\SWF Catcher\InternetExplorer.htm
    IE: View Exif/GPS/IPTC with IExif - f:\iexif 2.3\IExifCom.htm
    IE: Zoom &in
    IE: Zoom &out
    Trusted Zone: google.com\maps
    DPF: {0A43D7AC-D6C1-4622-B309-BF975F427C0E} - hxxps://internetbankingplus2.firstdirect.com/ibplus/frontdoorFD.cab
    .
    - - - - ORPHANS REMOVED - - - -
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    AddRemove-Photo-Colorizer 2 - c:\windows\cadkasdeinst01e.exe

    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-09-15 16:23
    Windows 5.1.2600 Service Pack 3 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    .
    LOCKED REGISTRY KEYS
    [HKEY_USERS\S-1-5-21-746137067-606747145-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Explorer\CLSID]
    @Denied: (Full) (LocalSystem)
    [HKEY_USERS\S-1-5-21-746137067-606747145-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{63B97F04-9032-2D21-7BE0-EA7F7AE7EE4B}*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    "nanhidfkkcpkpahaeliapjmohhon"=hex:6a,61,65,67,68,69,66,68,66,65,6b,6d,6d,63,
    68,6f,65,68,6b,70,00,0c
    "madhoahnjofkbbmejiepajomch"=hex:6a,61,65,67,68,69,66,68,66,65,6b,6d,6d,63,68,
    6f,65,68,6b,70,00,56
    "abbaoepgoddjdfkamchgkahkhkddfmehpc"=hex:61,62,6b,68,62,64,67,68,65,6c,67,67,
    64,67,6c,6a,64,62,6a,64,63,6d,70,67,70,6a,70,6e,61,6e,6a,63,62,66,00,77
    "maoppejgogbliogaieoebfhdhf"=hex:64,62,64,68,6d,66,65,66,6b,65,6e,68,6a,68,6a,
    63,64,63,66,69,61,62,70,63,61,68,6c,70,6a,61,6d,68,62,65,69,6a,69,64,6c,6b,\
    [HKEY_USERS\S-1-5-21-746137067-606747145-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8AA92D77-C3A3-884A-7EA8-1CD3D0BBD18D}*]
    @Allowed: (Read) (RestrictedCode)
    @Allowed: (Read) (RestrictedCode)
    [HKEY_LOCAL_MACHINE\software\Microsoft\EncryptionInterface*]
    "l_encryption_d"="585A4A574A5F"
    .
    DLLs Loaded Under Running Processes
    - - - - - - - > 'winlogon.exe'(524)
    g:\superantispyware\SASWINLO.DLL
    c:\windows\system32\WININET.dll
    - - - - - - - > 'explorer.exe'(2880)
    c:\windows\system32\WININET.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\mshtml.dll
    c:\windows\system32\msls31.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    Completion time: 2010-09-15 16:25:53
    ComboFix-quarantined-files.txt 2010-09-15 15:25
    ComboFix2.txt 2010-09-11 20:49
    ComboFix3.txt 2010-06-21 18:05
    ComboFix4.txt 2009-07-29 09:48
    Pre-Run: 25,528,594,432 bytes free
    Post-Run: 25,494,241,280 bytes free
    - - End Of File - - 0528760ED0F5804993C7C7D4B4460559
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    What would be the program, and how would it differ from manually removing using the program I gave you?
    :idea:
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Oh. It's gone now.:)

    I was going to use Wise Registry Cleaner Pro v4 but the registry entry has disappeared now.

    Your prog did it.

    Has the Combofix log shown up anything?
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Use the malwarebytes tool to destroy this ~
    C:\32788R22FWJFW.1.tmp

    ..........................................................................

    Open notepad and copy/paste the text in RED below

    File::
    c:\windows\system32\CF10921.exe
    c:\windows\system32\BootMan.exe
    c:\windows\IFinst27.exe


    Save this as "CFScript" (FULL file will be 'CFScript.txt' EXACTLY as shown)

    Then drag the CFScript into ComboFix.exe as you see in the screenshot below.

    CFScript.gif


    This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply
    (If SNAPSHOT is stupidly large, leave that part out)

    Combofix should never take more that 30 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.

    ...................................................................................

    Download GLARY UTILITIES
    http://www.glaryutilities.com/download/gusetup_slim.exe
    REBOOT then run the ONE CLICK scan
    Goto MODULES / SYSTEM TOOLS / WINDOWS STANDARD TOOLS / then run SYSTEM FILE CHECKER

    ....................................................................................

    I feel another run of an av is needed

    Download and run the FREE version of DR WEB
    http://www.freedrweb.com/download+cureit/gr/
    Turn your anti virus OFF
    Click CANCEL to the 'Would you like to read purchase terms now?' message
    Click START click OK
    It will auto QUICK scan
    After that set to scan the WHOLE computer and press the 'play' icon

    ***DO NOT UPGRADE TO FULL VERSION***

    Logs can be found in one of these places ~
    C:\Program Files\DrWeb
    C:\Users\username\DoctorWeb
    All im interested in, is anything it removes (Usually right at the bottom)
    :idea:
  • rizla01
    rizla01 Posts: 7,260 Forumite
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    Hi RiK.

    I'm having difficulty with the 1st instruction.

    I assume that you mean the Assassin tool. C:\32788R22FWJFW.1.tmp is a folder and all that happens with Assassin is that it opens the folder so I don't know how to get it to 'Destroy ' it.

    (I did run Malwarebytes in case I got it wrong and that did nothing)
    "Unhappiness is not knowing what we want, and killing ourselves to get it."
    Post Count: 4,111 Thanked 3,111 Times in 1,111 Posts (Actual figures as they once were))
    Women and cats will do as they please, and men and dogs should relax and get used to the idea.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 350.2K Banking & Borrowing
  • 252.8K Reduce Debt & Boost Income
  • 453.2K Spending & Discounts
  • 243.2K Work, Benefits & Business
  • 597.6K Mortgages, Homes & Bills
  • 176.6K Life & Family
  • 256.2K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.