We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!
The Forum now has a brand new text editor, adding a bunch of handy features to use when creating posts. Read more in our how-to guide

Computer infected. Help please

13»

Comments

  • more777
    more777 Posts: 112 Forumite
    Part of the Furniture 10 Posts Name Dropper Combo Breaker
    That hitman link doesnt work. Am still trying combofix, not working for me at the moment. keeps rebooting then nothing. will keep trying though.
  • dogmaryxx
    dogmaryxx Posts: 2,446 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    save Hitman Pro to your Desktop(32bit) or

    For 64bit , click here

    Once saved, hold down the Ctrl key situated on the left of the keyboard whilst double clicking on the Hitman Pro .exe file in order to start the program. Then follow the simple instructions.
  • more777
    more777 Posts: 112 Forumite
    Part of the Furniture 10 Posts Name Dropper Combo Breaker
    Combofix log below. Finally after about fifty reboots...:mad:


    ComboFix 10-12-31.02 - Monica 01/01/2011 17:31:40.1.2 - x86
    Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.1916.1250 [GMT 0:00]
    Running from: c:\users\Monica\Desktop\ComboFix.exe
    SP: Spyware Doctor *Disabled/Updated* {94076BB2-F3DA-227F-9A1E-F060FF73600F}
    SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    c:\users\Monica\AppData\Roaming\.#
    c:\windows\Downloaded Program Files\f3initialsetup1.0.1.0.inf
    .
    [URL="file://\\.\PhysicalDrive0"]\\.\PhysicalDrive0[/URL] - Bootkit TDL4 was found and disinfected
    .
    ((((((((((((((((((((((((( Files Created from 2010-12-01 to 2011-01-01 )))))))))))))))))))))))))))))))
    .
    2011-01-01 17:45 . 2011-01-01 17:45
    d
    w- c:\users\Default\AppData\Local\temp
    2011-01-01 17:45 . 2011-01-01 17:45
    d
    w- c:\users\Administrator\AppData\Local\temp
    2010-12-29 22:46 . 2010-12-29 22:46 472808 ----a-w- c:\windows\system32\deployJava1.dll
    2010-12-29 13:40 . 2010-07-16 14:59 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
    2010-12-29 13:40 . 2010-07-16 14:59 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
    2010-12-29 13:40 . 2010-11-17 10:19 249616 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
    2010-12-29 13:40 . 2010-11-17 10:19 102184 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
    2010-12-29 13:40 . 2010-11-25 10:53 160448 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
    2010-12-29 13:40 . 2010-11-25 10:43 239168 ----a-w- c:\windows\system32\drivers\PCTCore.sys
    2010-12-29 13:40 . 2010-11-25 10:42 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
    2010-12-29 13:40 . 2010-12-29 14:45
    d
    w- c:\program files\PC Tools Security
    2010-12-29 13:40 . 2010-12-29 13:42
    d
    w- c:\program files\Common Files\PC Tools
    2010-12-29 13:40 . 2010-12-29 13:40
    d
    w- c:\users\Monica\AppData\Roaming\PC Tools
    2010-12-29 13:33 . 2010-12-29 13:40
    d
    w- c:\programdata\PC Tools
    2010-12-27 20:42 . 2010-12-27 20:42
    d
    w- c:\windows\Sun
    2010-12-22 21:03 . 2010-11-10 04:33 6273872 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{33CA9FAB-8A18-4D94-A384-5A0FC9FB1B62}\mpengine.dll
    2010-12-15 20:31 . 2010-12-15 20:31
    d
    w- c:\program files\iPod
    2010-12-15 20:31 . 2010-12-15 20:33
    d
    w- c:\program files\iTunes
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin7.dll
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin6.dll
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin5.dll
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin4.dll
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin3.dll
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin2.dll
    2010-12-15 20:22 . 2010-12-15 20:22 159744 ----a-w- c:\program files\Internet Explorer\Plugins\npqtplugin.dll
    2010-12-15 20:22 . 2010-12-15 20:22
    d
    w- c:\program files\QuickTime
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-12-20 18:09 . 2010-04-06 09:50 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-12-20 18:08 . 2010-04-06 09:50 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-11-29 17:38 . 2010-11-29 17:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
    2010-11-29 17:38 . 2010-11-29 17:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
    2010-10-19 10:41 . 2009-10-02 20:41 222080
    w- c:\windows\system32\MpSigStub.exe
    2010-10-07 12:23 . 2010-10-07 12:23 91424 ----a-w- c:\windows\system32\dnssd.dll
    2010-10-07 12:23 . 2010-10-07 12:23 107808 ----a-w- c:\windows\system32\dns-sd.exe
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
    "{a24f3f59-1021-4e02-856c-99d9b4a03d83}"= "c:\program files\SoccerInferno\bar\1.bin\j2SrcAs.dll" [2010-09-28 49152]
    [HKEY_CLASSES_ROOT\clsid\{a24f3f59-1021-4e02-856c-99d9b4a03d83}]
    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{285028f8-201e-4f8f-827b-7381fc181c3e}]
    2010-09-28 17:41 643072 ----a-w- c:\progra~1\SOCCER~2\bar\1.bin\j2bar.dll
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{c5a318c1-d1d9-41f0-85fe-41cc9fb25e75}"= "c:\program files\SoccerInferno\bar\1.bin\j2bar.dll" [2010-09-28 643072]
    [HKEY_CLASSES_ROOT\clsid\{c5a318c1-d1d9-41f0-85fe-41cc9fb25e75}]
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
    "Google Update"="c:\users\Monica\AppData\Local\Google\Update\GoogleUpdate.exe" [2009-04-17 133104]
    "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-10-08 47904]
    "Windows Mobile-based device management"="c:\windows\WindowsMobile\wmdSync.exe" [2006-11-02 215552]
    "4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
    "Wireless Manager"="c:\program files\Virgin Broadband Wireless\Wireless Manager.exe" [2008-05-26 585728]
    "RtHDVCpl"="RtHDVCpl.exe" [2007-08-09 4702208]
    "Skytel"="Skytel.exe" [2007-08-03 1826816]
    "BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2010-03-10 648536]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
    "Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
    "WorksFUD"="c:\program files\Microsoft Works\wkfud.exe" [2001-10-05 24576]
    "Microsoft Works Portfolio"="c:\program files\Microsoft Works\WksSb.exe" [2007-06-20 1099104]
    "Microsoft Works Update Detection"="c:\program files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2001-08-16 28738]
    "SoccerInferno Browser Plugin Loader"="c:\progra~1\SOCCER~2\bar\1.bin\j2brmon.exe" [2010-09-28 20480]
    "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-10-14 49152]
    "hpqSRMon"="c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2007-08-22 80896]
    "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
    "Malwarebytes' Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2010-12-20 963976]
    c:\users\Monica\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
    OpenOffice.org 3.0.lnk - c:\program files\OpenOffice.org 3\program\quickstart.exe [2008-12-15 384000]
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Clearblue.lnk - c:\windows\Installer\{D99F7568-803E-4C13-80DD-9403CD34F5F3}\_F015326B9D6121FF10D37F.exe [2010-8-17 370070]
    Exif Launcher S.lnk - c:\program files\FinePixViewerS\QuickDCF2.exe [2010-5-12 303104]
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
    Microsoft Works Calendar Reminders.lnk - c:\program files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe [2001-8-7 24633]
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle"= 0 (0x0)
    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Ralink Wireless Utility.lnk]
    path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Ralink Wireless Utility.lnk
    backup=c:\windows\pss\Ralink Wireless Utility.lnk.CommonStartup
    backupExtension=.CommonStartup
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
    %ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\0fbcd8c792b884b81f0abba2d29485a0]
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    2010-12-13 17:16 421160 ----a-w- c:\program files\iTunes\iTunesHelper.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSD]
    2007-08-28 13:36 671801 ----a-w- c:\program files\C&E\OSD\osd.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    2010-11-29 17:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
    2007-08-09 18:26 4702208 ----a-w- c:\windows\RtHDVCpl.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
    2009-04-11 06:28 1233920 ----a-w- c:\program files\Windows Sidebar\sidebar.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
    2007-08-03 12:22 1826816 ----a-w- c:\windows\SkyTel.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
    2008-06-10 03:27 144784 ----a-w- c:\program files\Java\jre1.6.0_07\bin\jusched.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GShortCut]
    2007-07-26 21:07 202024 ----a-w- c:\program files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
    2008-01-19 07:33 202240 ----a-w- c:\program files\Windows Media Player\wmpnscfg.exe
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001
    R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
    R3 netr73;RT73 USB Wireless LAN Card Driver for Vista;c:\windows\system32\DRIVERS\netr73.sys [2009-05-24 501248]
    R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [2010-03-15 366840]
    R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
    S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-11-25 239168]
    S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2010-07-16 338880]
    S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2010-07-16 656320]
    S2 SoccerInfernoService;SoccerInferno Service;c:\progra~1\SOCCER~2\bar\1.bin\j2barsvc.exe [2010-09-28 28766]
    S3 SiS6350;SiS6350;c:\windows\system32\DRIVERS\SISGRKMD.sys [2007-08-24 452096]
    S3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSGB6.sys [2007-01-22 46592]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    WindowsMobile REG_MULTI_SZ wcescomm rapimgr
    LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
    LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
    .
    Contents of the 'Scheduled Tasks' folder
    2010-12-31 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302638823-2613102858-2234620615-1000Core.job
    - c:\users\Monica\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-17 19:54]
    2011-01-01 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1302638823-2613102858-2234620615-1000UA.job
    - c:\users\Monica\AppData\Local\Google\Update\GoogleUpdate.exe [2009-04-17 19:54]
    2011-01-01 c:\windows\Tasks\User_Feed_Synchronization-{DBA79BC4-47FC-4C17-BC95-CBC9F6D144FF}.job
    - c:\windows\system32\msfeedssync.exe [2010-12-14 04:25]
    .
    .
    Supplementary Scan
    .
    uStart Page = hxxp://uk.yahoo.com/
    uInternet Settings,ProxyOverride = *.local
    LSP: c:\program files\Common Files\PC Tools\Lsp\PCTLsp.dll
    .
    - - - - ORPHANS REMOVED - - - -
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    MSConfigStartUp-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe
    MSConfigStartUp-AppleSyncNotifier - c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
    MSConfigStartUp-AVG8_TRAY - c:\progra~1\AVG\AVG8\avgtray.exe
    MSConfigStartUp-ccApp - c:\program files\Common Files\Symantec Shared\ccApp.exe
    MSConfigStartUp-My Web Search Bar Search Scope Monitor - c:\progra~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
    MSConfigStartUp-MyWebSearch Email Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    MSConfigStartUp-MyWebSearch Plugin - c:\progra~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL
    MSConfigStartUp-NapsterShell - c:\program files\Napster\napster.exe
    MSConfigStartUp-osCheck - c:\program files\Norton Internet Security\osCheck.exe
    MSConfigStartUp-SiSTray - %ProgramFiles%\SiS VGA Utilities\SiSTray.exe
    MSConfigStartUp-Symantec PIF AlertEng - c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
    MSConfigStartUp-Veoh - c:\program files\Veoh Networks\Veoh\VeohClient.exe

    **************************************************************************
    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2011-01-01 17:46
    Windows 6.0.6002 Service Pack 2 NTFS
    scanning hidden processes ...
    scanning hidden autostart entries ...
    scanning hidden files ...
    scan completed successfully
    hidden files: 0
    **************************************************************************
    Stealth MBR rootkit/Mebroot/Sinowal/TDL4 detector 0.4.2 by Gmer, http://www.gmer.net
    Windows 6.0.6002 Disk: Hitachi_HTS541612J9SA00 rev.SBDOC70P -> Harddisk0\DR0 -> \Device\Ide\IdePort1 P1T0L0-1
    device: opened successfully
    user: MBR read successfully
    Disk trace:
    called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys PCTCore.sys acpi.sys hal.dll >>UNKNOWN [0x85F8E555]<<
    c:\windows\system32\drivers\PCTCore.sys PC Tools Kernel Driver Suite
    _asm { PUSH EBP; MOV EBP, ESP; PUSH ECX; MOV EAX, [EBP+0x8]; CMP EAX, [0x85f947b0]; MOV EAX, [0x85f9482c]; PUSH EBX; PUSH ESI; MOV ESI, [EBP+0xc]; MOV EBX, [ESI+0x60]; PUSH EDI; JNZ 0x20; MOV [EBP+0x8], EAX; }
    1 ntkrnlpa!IofCallDriver[0x8227A962] -> \Device\Harddisk0\DR0[0x85AF4640]
    3 CLASSPNP[0x87FC48B3] -> ntkrnlpa!IofCallDriver[0x8227A962] -> [0x85AF4E40]
    5 PCTCore[0x805D3099] -> ntkrnlpa!IofCallDriver[0x8227A962] -> [0x85110918]
    7 acpi[0x806C86BC] -> ntkrnlpa!IofCallDriver[0x8227A962] -> [0x847A65A8]
    \Driver\atapi[0x85F6F360] -> IRP_MJ_CREATE -> 0x85F8E555
    kernel: MBR read successfully
    _asm { XOR AX, AX; MOV SS, AX; MOV SP, 0x7c00; MOV ES, AX; MOV DS, AX; MOV SI, 0x7c00; MOV DI, 0x600; MOV CX, 0x200; CLD ; REP MOVSB ; PUSH AX; PUSH 0x61c; RETF ; STI ; PUSHA ; MOV CX, 0x132; MOV BP, 0x62a; ROR BYTE [BP+0x0], CL; INC BP; }
    detected disk devices:
    \Device\Ide\IdeDeviceP1T0L0-1 -> \??\IDE#DiskHitachi_HTS541612J9SA00_________________SBDOC70P#5&18c0e30f&0&0.0.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
    detected hooks:
    user != kernel MBR !!!
    sectors 234441646 (+255): user != kernel
    Warning: possible TDL4 rootkit infection !
    TDL4 rootkit infection detected ! Use: "mbr.exe -f" to fix.
    **************************************************************************
    .
    LOCKED REGISTRY KEYS
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    Completion time: 2011-01-01 17:50:31
    ComboFix-quarantined-files.txt 2011-01-01 17:50
    Pre-Run: 53,884,170,240 bytes free
    Post-Run: 55,442,960,384 bytes free
    - - End Of File - - 48563C9594921307844E04E922D48DF9
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    At this stage id recommend formatting the drive and reinstalling windows
    :idea:
  • more777
    more777 Posts: 112 Forumite
    Part of the Furniture 10 Posts Name Dropper Combo Breaker
    which means???????????
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    It means you have a very nasty rootkit attached to your hardrive.
    You need an operating system disc to format the hard drive (completely wipe it), and reinstall windows (back to bare bones)
    :idea:
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 353.5K Banking & Borrowing
  • 254.1K Reduce Debt & Boost Income
  • 455K Spending & Discounts
  • 246.6K Work, Benefits & Business
  • 602.9K Mortgages, Homes & Bills
  • 178.1K Life & Family
  • 260.6K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.