Jump to content

HIJACK.REGEDIT


donj

Recommended Posts

Malewarebytes scan detects and removes HIJACK.REGEDIT, however it keeps coming back. I also ran Combofix. The computer has an internet connection, but the browsers (IE, Firefox, Chrome) will not open a web page. I have included the log files.

Any help will be much appreciated!

Combofix must have fixed the registry error...I just ran a quick scan and their is 0 infections now. However, I still cannot connect to the internet.

Link to post
Share on other sites

Hi, donj :D

;)

Lets give it a try. Some programs may be compromised.

  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

http://forums.malwarebytes.org/index.php?act=ST&f=7&t=39848

Collect::
c:\windows\system32\aexarasug.exe
c:\windows\system32\accesse.exe
c:\windows\system32\ndismgr.sys

FCopy::
c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys | c:\windows\system32\drivers\tcpip.sys

File::
c:\program files\20484187.dat
c:\program files\20483640.dat
c:\program files\20459281.dat
c:\program files\20458718.dat
c:\program files\1475171.dat
c:\program files\1117984.dat
c:\program files\894875.dat
c:\program files\24539093.dat
c:\documents and settings\Don\Application Data\gaboln\hxmrsftav .exe

DirLook::
c:\documents and settings\Don\Application Data\gaboln
c:\documents and settings\Administrator\Local Settings\Application Data\dgakth
c:\documents and settings\Administrator\Local Settings\Application Data\fnlxtk
c:\documents and settings\Administrator\Local Settings\Application Data\ybchse
c:\documents and settings\Administrator\Local Settings\Application Data\rorqsx
c:\documents and settings\Administrator\Local Settings\Application Data\uquibp
c:\documents and settings\Administrator\Local Settings\Application Data\fvawxd
c:\documents and settings\Administrator\Local Settings\Application Data\fcaahi
c:\documents and settings\Administrator\Local Settings\Application Data\yivbrq
c:\documents and settings\Administrator\Local Settings\Application Data\rvlkrk
c:\documents and settings\Administrator\Local Settings\Application Data\dgyvei
c:\documents and settings\Administrator\Local Settings\Application Data\yfesmo
c:\documents and settings\Administrator\Local Settings\Application Data\dvmgkv
c:\documents and settings\Administrator\Application Data\uskiwa
c:\documents and settings\Administrator\Local Settings\Application Data\uskiwa
c:\documents and settings\Administrator\Local Settings\Application Data\kvtrff
c:\documents and settings\Administrator\Local Settings\Application Data\mfqqci
c:\documents and settings\Administrator\Local Settings\Application Data\hjahoq
c:\documents and settings\Administrator\Application Data\kfaesu
c:\documents and settings\Administrator\Local Settings\Application Data\kfaesu
c:\documents and settings\Administrator\Local Settings\Application Data\waegsd
c:\documents and settings\Administrator\Local Settings\Application Data\xmoqog
c:\documents and settings\Administrator\Local Settings\Application Data\csgjfq
c:\documents and settings\Administrator\Local Settings\Application Data\bfakvp
c:\documents and settings\Administrator\Local Settings\Application Data\scxmju
c:\documents and settings\Administrator\Local Settings\Application Data\efqqgh
c:\documents and settings\Administrator\Local Settings\Application Data\nylugr
c:\documents and settings\Administrator\Local Settings\Application Data\ueaerm
c:\documents and settings\Administrator\Local Settings\Application Data\dtxfhc
c:\documents and settings\Administrator\Local Settings\Application Data\rlvfse
c:\documents and settings\Administrator\Local Settings\Application Data\vwwvyy
c:\documents and settings\Administrator\Local Settings\Application Data\syageo
c:\documents and settings\Don\Local Settings\Application Data\abietk
c:\documents and settings\Don\Local Settings\Application Data\ufrtfs
c:\documents and settings\Don\Local Settings\Application Data\wvjbsh
c:\documents and settings\Don\Local Settings\Application Data\fmjtag
c:\documents and settings\Don\Local Settings\Application Data\iloebw
c:\documents and settings\Don\Local Settings\Application Data\sfkibg
c:\documents and settings\Don\Local Settings\Application Data\tvcpnu
c:\documents and settings\Don\Local Settings\Application Data\itddfo
c:\documents and settings\Don\Local Settings\Application Data\gfwhqa
c:\documents and settings\Administrator\Local Settings\Application Data\gkalbi
c:\documents and settings\Administrator\Local Settings\Application Data\cbsmjt
c:\documents and settings\Administrator\Local Settings\Application Data\yvtjiq
c:\documents and settings\Don\Local Settings\Application Data\hlwkjf
c:\documents and settings\Don\Local Settings\Application Data\jkkmib
c:\documents and settings\Don\Local Settings\Application Data\ubalar
c:\documents and settings\Don\Application Data\fbwefs
c:\documents and settings\Don\Local Settings\Application Data\fbwefs
c:\documents and settings\Don\Application Data\yomnfm
c:\documents and settings\Don\Local Settings\Application Data\yomnfm
c:\documents and settings\Don\Local Settings\Application Data\hrvqjo
c:\documents and settings\Don\Local Settings\Application Data\wufaqt
c:\documents and settings\Don\Local Settings\Application Data\bnsrrx
c:\documents and settings\Don\Local Settings\Application Data\vkgapu
c:\documents and settings\Don\Local Settings\Application Data\mlcxya
c:\documents and settings\Don\Local Settings\Application Data\fdkcow
c:\documents and settings\Don\Local Settings\Application Data\lllwyr
c:\documents and settings\Don\Local Settings\Application Data\pehutx
c:\documents and settings\Don\Application Data\kdhopu
c:\documents and settings\Don\Local Settings\Application Data\kdhopu
c:\documents and settings\Don\Local Settings\Application Data\rivwbq
c:\documents and settings\Administrator\Local Settings\Application Data\xonubk
c:\documents and settings\Administrator\Local Settings\Application Data\bwrapu
c:\documents and settings\Administrator\Local Settings\Application Data\nspvyv
c:\documents and settings\Administrator\Local Settings\Application Data\tbqpir
c:\documents and settings\Administrator\Local Settings\Application Data\urjwug
c:\documents and settings\Administrator\Local Settings\Application Data\pvsmho
c:\documents and settings\Administrator\Local Settings\Application Data\bggytm
c:\documents and settings\Administrator\Local Settings\Application Data\enqmtp
c:\documents and settings\Administrator\Local Settings\Application Data\iluhfh
c:\documents and settings\Administrator\Local Settings\Application Data\txntbr
c:\documents and settings\Administrator\Local Settings\Application Data\lukvov
c:\documents and settings\Administrator\Local Settings\Application Data\rjhxmd
c:\documents and settings\Administrator\Local Settings\Application Data\cirftf
c:\documents and settings\Administrator\Local Settings\Application Data\mcmjto
c:\documents and settings\Administrator\Local Settings\Application Data\usldbm
c:\documents and settings\Administrator\Local Settings\Application Data\djkvjl
c:\documents and settings\Administrator\Local Settings\Application Data\yelsii
c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
c:\documents and settings\Administrator\Local Settings\Application Data\feyrpu
c:\documents and settings\Administrator\Local Settings\Application Data\tjtmwa
c:\documents and settings\Administrator\Local Settings\Application Data\qhowqr
c:\documents and settings\Administrator\Local Settings\Application Data\kufgpl
c:\documents and settings\Administrator\Local Settings\Application Data\irksuq
c:\documents and settings\Administrator\Local Settings\Application Data\oylmel
c:\documents and settings\Administrator\Local Settings\Application Data\lmrcow
c:\documents and settings\Administrator\Local Settings\Application Data\wwfnbu
c:\documents and settings\HP_Administrator\Local Settings\Application Data\xdlqit
c:\documents and settings\Don\Local Settings\Application Data\kgbsoe
c:\documents and settings\Don\Local Settings\Application Data\tavwon
c:\documents and settings\Don\Local Settings\Application Data\puxunk
c:\documents and settings\Don\Local Settings\Application Data\gxnjmv
c:\documents and settings\Don\Local Settings\Application Data\hogqyk
c:\documents and settings\Don\Local Settings\Application Data\lxhkna
c:\documents and settings\Don\Local Settings\Application Data\togeuy
c:\documents and settings\Don\Local Settings\Application Data\eytphw
c:\documents and settings\Don\Local Settings\Application Data\xmkygq
c:\documents and settings\Administrator\Application Data\qrkfma
c:\documents and settings\Administrator\Local Settings\Application Data\qrkfma
c:\documents and settings\Administrator\Local Settings\Application Data\vissjh
c:\documents and settings\Don\Local Settings\Application Data\canyjj
c:\documents and settings\Don\Local Settings\Application Data\rbkwso
c:\documents and settings\Don\Local Settings\Application Data\cbhpxq
c:\documents and settings\Don\Local Settings\Application Data\nlbgbv
c:\documents and settings\Don\Local Settings\Application Data\taxiac
c:\documents and settings\Don\Local Settings\Application Data\aotkyj

RenV::
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Dell AIO Printer A960\dlbfbmgr .exe
c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08 .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\Norton Internet Security\urllstck .exe
c:\program files\Spyware Doctor\pctstray .exe
c:\windows\ehome\ehtray .exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sefjhf98jfoidsfoishgoiusgdgfgd]

CFScriptB-4.gif

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.

  • Ensure you are connected to the internet and click OK on the message box.

(This may not even happen in your condition.)

====================================================================

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
    :filefind
    ctfmon.exe
    rundll32.exe
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Link to post
Share on other sites

Hi, donj :D

;)

Lets give it a try. Some programs may be compromised.

  • Copy the entire contents of the Code Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

http://forums.malwarebytes.org/index.php?act=ST&f=7&t=39848

Collect::
c:\windows\system32\aexarasug.exe
c:\windows\system32\accesse.exe
c:\windows\system32\ndismgr.sys

FCopy::
c:\windows\$hf_mig$\KB951748\SP3QFE\tcpip.sys | c:\windows\system32\drivers\tcpip.sys

File::
c:\program files\20484187.dat
c:\program files\20483640.dat
c:\program files\20459281.dat
c:\program files\20458718.dat
c:\program files\1475171.dat
c:\program files\1117984.dat
c:\program files\894875.dat
c:\program files\24539093.dat
c:\documents and settings\Don\Application Data\gaboln\hxmrsftav .exe

DirLook::
c:\documents and settings\Don\Application Data\gaboln
c:\documents and settings\Administrator\Local Settings\Application Data\dgakth
c:\documents and settings\Administrator\Local Settings\Application Data\fnlxtk
c:\documents and settings\Administrator\Local Settings\Application Data\ybchse
c:\documents and settings\Administrator\Local Settings\Application Data\rorqsx
c:\documents and settings\Administrator\Local Settings\Application Data\uquibp
c:\documents and settings\Administrator\Local Settings\Application Data\fvawxd
c:\documents and settings\Administrator\Local Settings\Application Data\fcaahi
c:\documents and settings\Administrator\Local Settings\Application Data\yivbrq
c:\documents and settings\Administrator\Local Settings\Application Data\rvlkrk
c:\documents and settings\Administrator\Local Settings\Application Data\dgyvei
c:\documents and settings\Administrator\Local Settings\Application Data\yfesmo
c:\documents and settings\Administrator\Local Settings\Application Data\dvmgkv
c:\documents and settings\Administrator\Application Data\uskiwa
c:\documents and settings\Administrator\Local Settings\Application Data\uskiwa
c:\documents and settings\Administrator\Local Settings\Application Data\kvtrff
c:\documents and settings\Administrator\Local Settings\Application Data\mfqqci
c:\documents and settings\Administrator\Local Settings\Application Data\hjahoq
c:\documents and settings\Administrator\Application Data\kfaesu
c:\documents and settings\Administrator\Local Settings\Application Data\kfaesu
c:\documents and settings\Administrator\Local Settings\Application Data\waegsd
c:\documents and settings\Administrator\Local Settings\Application Data\xmoqog
c:\documents and settings\Administrator\Local Settings\Application Data\csgjfq
c:\documents and settings\Administrator\Local Settings\Application Data\bfakvp
c:\documents and settings\Administrator\Local Settings\Application Data\scxmju
c:\documents and settings\Administrator\Local Settings\Application Data\efqqgh
c:\documents and settings\Administrator\Local Settings\Application Data\nylugr
c:\documents and settings\Administrator\Local Settings\Application Data\ueaerm
c:\documents and settings\Administrator\Local Settings\Application Data\dtxfhc
c:\documents and settings\Administrator\Local Settings\Application Data\rlvfse
c:\documents and settings\Administrator\Local Settings\Application Data\vwwvyy
c:\documents and settings\Administrator\Local Settings\Application Data\syageo
c:\documents and settings\Don\Local Settings\Application Data\abietk
c:\documents and settings\Don\Local Settings\Application Data\ufrtfs
c:\documents and settings\Don\Local Settings\Application Data\wvjbsh
c:\documents and settings\Don\Local Settings\Application Data\fmjtag
c:\documents and settings\Don\Local Settings\Application Data\iloebw
c:\documents and settings\Don\Local Settings\Application Data\sfkibg
c:\documents and settings\Don\Local Settings\Application Data\tvcpnu
c:\documents and settings\Don\Local Settings\Application Data\itddfo
c:\documents and settings\Don\Local Settings\Application Data\gfwhqa
c:\documents and settings\Administrator\Local Settings\Application Data\gkalbi
c:\documents and settings\Administrator\Local Settings\Application Data\cbsmjt
c:\documents and settings\Administrator\Local Settings\Application Data\yvtjiq
c:\documents and settings\Don\Local Settings\Application Data\hlwkjf
c:\documents and settings\Don\Local Settings\Application Data\jkkmib
c:\documents and settings\Don\Local Settings\Application Data\ubalar
c:\documents and settings\Don\Application Data\fbwefs
c:\documents and settings\Don\Local Settings\Application Data\fbwefs
c:\documents and settings\Don\Application Data\yomnfm
c:\documents and settings\Don\Local Settings\Application Data\yomnfm
c:\documents and settings\Don\Local Settings\Application Data\hrvqjo
c:\documents and settings\Don\Local Settings\Application Data\wufaqt
c:\documents and settings\Don\Local Settings\Application Data\bnsrrx
c:\documents and settings\Don\Local Settings\Application Data\vkgapu
c:\documents and settings\Don\Local Settings\Application Data\mlcxya
c:\documents and settings\Don\Local Settings\Application Data\fdkcow
c:\documents and settings\Don\Local Settings\Application Data\lllwyr
c:\documents and settings\Don\Local Settings\Application Data\pehutx
c:\documents and settings\Don\Application Data\kdhopu
c:\documents and settings\Don\Local Settings\Application Data\kdhopu
c:\documents and settings\Don\Local Settings\Application Data\rivwbq
c:\documents and settings\Administrator\Local Settings\Application Data\xonubk
c:\documents and settings\Administrator\Local Settings\Application Data\bwrapu
c:\documents and settings\Administrator\Local Settings\Application Data\nspvyv
c:\documents and settings\Administrator\Local Settings\Application Data\tbqpir
c:\documents and settings\Administrator\Local Settings\Application Data\urjwug
c:\documents and settings\Administrator\Local Settings\Application Data\pvsmho
c:\documents and settings\Administrator\Local Settings\Application Data\bggytm
c:\documents and settings\Administrator\Local Settings\Application Data\enqmtp
c:\documents and settings\Administrator\Local Settings\Application Data\iluhfh
c:\documents and settings\Administrator\Local Settings\Application Data\txntbr
c:\documents and settings\Administrator\Local Settings\Application Data\lukvov
c:\documents and settings\Administrator\Local Settings\Application Data\rjhxmd
c:\documents and settings\Administrator\Local Settings\Application Data\cirftf
c:\documents and settings\Administrator\Local Settings\Application Data\mcmjto
c:\documents and settings\Administrator\Local Settings\Application Data\usldbm
c:\documents and settings\Administrator\Local Settings\Application Data\djkvjl
c:\documents and settings\Administrator\Local Settings\Application Data\yelsii
c:\documents and settings\Administrator\Local Settings\Application Data\Adobe
c:\documents and settings\Administrator\Local Settings\Application Data\feyrpu
c:\documents and settings\Administrator\Local Settings\Application Data\tjtmwa
c:\documents and settings\Administrator\Local Settings\Application Data\qhowqr
c:\documents and settings\Administrator\Local Settings\Application Data\kufgpl
c:\documents and settings\Administrator\Local Settings\Application Data\irksuq
c:\documents and settings\Administrator\Local Settings\Application Data\oylmel
c:\documents and settings\Administrator\Local Settings\Application Data\lmrcow
c:\documents and settings\Administrator\Local Settings\Application Data\wwfnbu
c:\documents and settings\HP_Administrator\Local Settings\Application Data\xdlqit
c:\documents and settings\Don\Local Settings\Application Data\kgbsoe
c:\documents and settings\Don\Local Settings\Application Data\tavwon
c:\documents and settings\Don\Local Settings\Application Data\puxunk
c:\documents and settings\Don\Local Settings\Application Data\gxnjmv
c:\documents and settings\Don\Local Settings\Application Data\hogqyk
c:\documents and settings\Don\Local Settings\Application Data\lxhkna
c:\documents and settings\Don\Local Settings\Application Data\togeuy
c:\documents and settings\Don\Local Settings\Application Data\eytphw
c:\documents and settings\Don\Local Settings\Application Data\xmkygq
c:\documents and settings\Administrator\Application Data\qrkfma
c:\documents and settings\Administrator\Local Settings\Application Data\qrkfma
c:\documents and settings\Administrator\Local Settings\Application Data\vissjh
c:\documents and settings\Don\Local Settings\Application Data\canyjj
c:\documents and settings\Don\Local Settings\Application Data\rbkwso
c:\documents and settings\Don\Local Settings\Application Data\cbhpxq
c:\documents and settings\Don\Local Settings\Application Data\nlbgbv
c:\documents and settings\Don\Local Settings\Application Data\taxiac
c:\documents and settings\Don\Local Settings\Application Data\aotkyj

RenV::
c:\program files\Adobe\Reader 9.0\Reader\reader_sl .exe
c:\program files\Common Files\Adobe\ARM\1.0\adobearm .exe
c:\program files\Common Files\Real\Update_OB\realsched .exe
c:\program files\Dell AIO Printer A960\dlbfbmgr .exe
c:\program files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08 .exe
c:\program files\iTunes\ituneshelper .exe
c:\program files\Malwarebytes' Anti-Malware\mbam .exe
c:\program files\Norton Internet Security\urllstck .exe
c:\program files\Spyware Doctor\pctstray .exe
c:\windows\ehome\ehtray .exe

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sefjhf98jfoidsfoishgoiusgdgfgd]

CFScriptB-4.gif

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.

  • Ensure you are connected to the internet and click OK on the message box.

(This may not even happen in your condition.)

====================================================================

Please download SystemLook from one of the links below and save it to your Desktop.

Download Mirror #1

Download Mirror #2

  • Double-click SystemLook.exe to run it.
  • Copy the content of the following codebox into the main textfield:
  • Click the Look button to start the scan.
  • When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.

Note: The log can also be found on your Desktop entitled SystemLook.txt

Thank you for your help and Sorry for the delay. Attached are the logs you requested.

log2.txt

SystemLook.txt

Link to post
Share on other sites

  1. Enter your Control Panel and double-click on Network Connections
  2. Then right click on your Default Connection
    • Usually Local Area Connection for Cable and DSL, or AOL Connection.

[*]Left click on Properties

[*]Double-Click on the Internet Protocol (TCP/IP) item

[*]Select the radio dial that says Obtain DNS Servers Automatically

[*]Press OK twice to get out of the properties screen

Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

netsh int ip reset C:\Resetlog.txt

netsh winsock reset catalog

ipconfig /flushdns (The space between g and / is needed)

Exit

Restart the computer.

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

Folder::

c:\documents and settings\Don\Application Data\gaboln

c:\documents and settings\Administrator\Local Settings\Application Data\dgakth

c:\documents and settings\Administrator\Local Settings\Application Data\fnlxtk

c:\documents and settings\Administrator\Local Settings\Application Data\ybchse

c:\documents and settings\Administrator\Local Settings\Application Data\rorqsx

c:\documents and settings\Administrator\Local Settings\Application Data\uquibp

c:\documents and settings\Administrator\Local Settings\Application Data\fvawxd

c:\documents and settings\Administrator\Local Settings\Application Data\fcaahi

c:\documents and settings\Administrator\Local Settings\Application Data\yivbrq

c:\documents and settings\Administrator\Local Settings\Application Data\rvlkrk

c:\documents and settings\Administrator\Local Settings\Application Data\dgyvei

c:\documents and settings\Administrator\Local Settings\Application Data\yfesmo

c:\documents and settings\Administrator\Local Settings\Application Data\dvmgkv

c:\documents and settings\Administrator\Application Data\uskiwa

c:\documents and settings\Administrator\Local Settings\Application Data\uskiwa

c:\documents and settings\Administrator\Local Settings\Application Data\kvtrff

c:\documents and settings\Administrator\Local Settings\Application Data\mfqqci

c:\documents and settings\Administrator\Local Settings\Application Data\hjahoq

c:\documents and settings\Administrator\Application Data\kfaesu

c:\documents and settings\Administrator\Local Settings\Application Data\kfaesu

c:\documents and settings\Administrator\Local Settings\Application Data\waegsd

c:\documents and settings\Administrator\Local Settings\Application Data\xmoqog

c:\documents and settings\Administrator\Local Settings\Application Data\csgjfq

c:\documents and settings\Administrator\Local Settings\Application Data\bfakvp

c:\documents and settings\Administrator\Local Settings\Application Data\scxmju

c:\documents and settings\Administrator\Local Settings\Application Data\efqqgh

c:\documents and settings\Administrator\Local Settings\Application Data\nylugr

c:\documents and settings\Administrator\Local Settings\Application Data\ueaerm

c:\documents and settings\Administrator\Local Settings\Application Data\dtxfhc

c:\documents and settings\Administrator\Local Settings\Application Data\rlvfse

c:\documents and settings\Administrator\Local Settings\Application Data\vwwvyy

c:\documents and settings\Administrator\Local Settings\Application Data\syageo

c:\documents and settings\Don\Local Settings\Application Data\abietk

c:\documents and settings\Don\Local Settings\Application Data\ufrtfs

c:\documents and settings\Don\Local Settings\Application Data\wvjbsh

c:\documents and settings\Don\Local Settings\Application Data\fmjtag

c:\documents and settings\Don\Local Settings\Application Data\iloebw

c:\documents and settings\Don\Local Settings\Application Data\sfkibg

c:\documents and settings\Don\Local Settings\Application Data\tvcpnu

c:\documents and settings\Don\Local Settings\Application Data\itddfo

c:\documents and settings\Don\Local Settings\Application Data\gfwhqa

c:\documents and settings\Administrator\Local Settings\Application Data\gkalbi

c:\documents and settings\Administrator\Local Settings\Application Data\cbsmjt

c:\documents and settings\Administrator\Local Settings\Application Data\yvtjiq

c:\documents and settings\Don\Local Settings\Application Data\hlwkjf

c:\documents and settings\Don\Local Settings\Application Data\jkkmib

c:\documents and settings\Don\Local Settings\Application Data\ubalar

c:\documents and settings\Don\Application Data\fbwefs

c:\documents and settings\Don\Local Settings\Application Data\fbwefs

c:\documents and settings\Don\Application Data\yomnfm

c:\documents and settings\Don\Local Settings\Application Data\yomnfm

c:\documents and settings\Don\Local Settings\Application Data\hrvqjo

c:\documents and settings\Don\Local Settings\Application Data\wufaqt

c:\documents and settings\Don\Local Settings\Application Data\bnsrrx

c:\documents and settings\Don\Local Settings\Application Data\vkgapu

c:\documents and settings\Don\Local Settings\Application Data\mlcxya

c:\documents and settings\Don\Local Settings\Application Data\fdkcow

c:\documents and settings\Don\Local Settings\Application Data\lllwyr

c:\documents and settings\Don\Local Settings\Application Data\pehutx

c:\documents and settings\Don\Application Data\kdhopu

c:\documents and settings\Don\Local Settings\Application Data\kdhopu

c:\documents and settings\Don\Local Settings\Application Data\rivwbq

c:\documents and settings\Administrator\Local Settings\Application Data\xonubk

c:\documents and settings\Administrator\Local Settings\Application Data\bwrapu

c:\documents and settings\Administrator\Local Settings\Application Data\nspvyv

c:\documents and settings\Administrator\Local Settings\Application Data\tbqpir

c:\documents and settings\Administrator\Local Settings\Application Data\urjwug

c:\documents and settings\Administrator\Local Settings\Application Data\pvsmho

c:\documents and settings\Administrator\Local Settings\Application Data\bggytm

c:\documents and settings\Administrator\Local Settings\Application Data\enqmtp

c:\documents and settings\Administrator\Local Settings\Application Data\iluhfh

c:\documents and settings\Administrator\Local Settings\Application Data\txntbr

c:\documents and settings\Administrator\Local Settings\Application Data\lukvov

c:\documents and settings\Administrator\Local Settings\Application Data\rjhxmd

c:\documents and settings\Administrator\Local Settings\Application Data\cirftf

c:\documents and settings\Administrator\Local Settings\Application Data\mcmjto

c:\documents and settings\Administrator\Local Settings\Application Data\usldbm

c:\documents and settings\Administrator\Local Settings\Application Data\djkvjl

c:\documents and settings\Administrator\Local Settings\Application Data\yelsii

c:\documents and settings\Administrator\Local Settings\Application Data\Adobe

c:\documents and settings\Administrator\Local Settings\Application Data\feyrpu

c:\documents and settings\Administrator\Local Settings\Application Data\tjtmwa

c:\documents and settings\Administrator\Local Settings\Application Data\qhowqr

c:\documents and settings\Administrator\Local Settings\Application Data\kufgpl

c:\documents and settings\Administrator\Local Settings\Application Data\irksuq

c:\documents and settings\Administrator\Local Settings\Application Data\oylmel

c:\documents and settings\Administrator\Local Settings\Application Data\lmrcow

c:\documents and settings\Administrator\Local Settings\Application Data\wwfnbu

c:\documents and settings\HP_Administrator\Local Settings\Application Data\xdlqit

c:\documents and settings\Don\Local Settings\Application Data\kgbsoe

c:\documents and settings\Don\Local Settings\Application Data\tavwon

c:\documents and settings\Don\Local Settings\Application Data\puxunk

c:\documents and settings\Don\Local Settings\Application Data\gxnjmv

c:\documents and settings\Don\Local Settings\Application Data\hogqyk

c:\documents and settings\Don\Local Settings\Application Data\lxhkna

c:\documents and settings\Don\Local Settings\Application Data\togeuy

c:\documents and settings\Don\Local Settings\Application Data\eytphw

c:\documents and settings\Don\Local Settings\Application Data\xmkygq

c:\documents and settings\Administrator\Application Data\qrkfma

c:\documents and settings\Administrator\Local Settings\Application Data\qrkfma

c:\documents and settings\Administrator\Local Settings\Application Data\vissjh

c:\documents and settings\Don\Local Settings\Application Data\canyjj

c:\documents and settings\Don\Local Settings\Application Data\rbkwso

c:\documents and settings\Don\Local Settings\Application Data\cbhpxq

c:\documents and settings\Don\Local Settings\Application Data\nlbgbv

c:\documents and settings\Don\Local Settings\Application Data\taxiac

c:\documents and settings\Don\Local Settings\Application Data\aotkyj

file::

c:\program files\42513593.dat

c:\program files\1966312.dat

CFScriptB-4.gif

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

Open the following file and post its contents:

ComboFix-quarantined-files.txt

Link to post
Share on other sites

I connect to a wireless network in my house. Everytime I restart the computer I have to go to 'services' to start 'wireless zero configuration' which controls my wireless usb adapter. After I do this I can see avilable wireless networks and I am connected to my network.

Link to post
Share on other sites

Something is producing lots of empty folders and files. Are you still unable to connect. The syntax is correct.

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

DeQuarantine::

C:\Qoobox\Quarantine\C\documents and settings\Administrator\Local Settings\Application Data\Adobe

Driver::

ImapiServiceSPBBCSvc

WmiClipSrv

ndismgr

Folder::

c:\documents and settings\Administrator\Local Settings\Application Data\jenfak

c:\documents and settings\Don\Local Settings\Application Data\tilheu

c:\documents and settings\Don\Local Settings\Application Data\lfjjqy

c:\documents and settings\Don\Local Settings\Application Data\huckal

c:\documents and settings\Don\Local Settings\Application Data\eeshru

c:\documents and settings\Don\Local Settings\Application Data\hybqlc

c:\documents and settings\Don\Local Settings\Application Data\nhckvw

c:\documents and settings\Don\Local Settings\Application Data\feamic

c:\documents and settings\Don\Application Data\kdwxjb

c:\documents and settings\Don\Local Settings\Application Data\kdwxjb

c:\documents and settings\Don\Local Settings\Application Data\cusjwb

c:\documents and settings\Don\Local Settings\Application Data\ydqcqb

c:\documents and settings\Don\Local Settings\Application Data\bxylki

c:\documents and settings\Don\Local Settings\Application Data\gvcgwa

c:\documents and settings\Don\Local Settings\Application Data\fllnpd

c:\documents and settings\Don\Local Settings\Application Data\wijpci

c:\documents and settings\Don\Local Settings\Application Data\pkvtvf

c:\documents and settings\Don\Application Data\dbbtki

c:\documents and settings\Don\Local Settings\Application Data\dbbtki

c:\documents and settings\Don\Local Settings\Application Data\iyfowa

c:\documents and settings\Don\Local Settings\Application Data\qnrwgx

c:\documents and settings\Administrator\Application Data\mwwedr

c:\documents and settings\Administrator\Local Settings\Application Data\mwwedr

c:\documents and settings\Administrator\Local Settings\Application Data\quaypj

c:\documents and settings\Don\Local Settings\Application Data\smfyft

c:\documents and settings\Don\Local Settings\Application Data\tfjqpi

c:\documents and settings\Don\Local Settings\Application Data\wxfplp

c:\documents and settings\Don\Local Settings\Application Data\rbgkfy

c:\documents and settings\Don\Local Settings\Application Data\mfobrh

c:\documents and settings\Don\Local Settings\Application Data\qdsvea

c:\documents and settings\Don\Local Settings\Application Data\awnbej

c:\documents and settings\Don\Local Settings\Application Data\hpyfji

c:\documents and settings\Don\Local Settings\Application Data\rlcusx

c:\documents and settings\Don\Local Settings\Application Data\ldhgaj

c:\documents and settings\Don\Local Settings\Application Data\okpnte

c:\documents and settings\Don\Local Settings\Application Data\lvjrfp

c:\documents and settings\Don\Local Settings\Application Data\wttymr

c:\documents and settings\Don\Local Settings\Application Data\gnodlb

c:\documents and settings\Don\Local Settings\Application Data\gyknya

c:\documents and settings\Don\Local Settings\Application Data\uqjmlb

c:\documents and settings\Don\Local Settings\Application Data\mngpxg

c:\documents and settings\Don\Application Data\cjuqqa

c:\documents and settings\Don\Local Settings\Application Data\cjuqqa

c:\documents and settings\Don\Local Settings\Application Data\guuhxu

c:\documents and settings\Don\Local Settings\Application Data\qfiskt

c:\documents and settings\Don\Local Settings\Application Data\dgoljg

c:\documents and settings\Don\Local Settings\Application Data\oltbft

c:\documents and settings\Don\Local Settings\Application Data\qsfofw

c:\documents and settings\Don\Local Settings\Application Data\vwtuvy

c:\documents and settings\Don\Local Settings\Application Data\lwtvko

c:\documents and settings\Don\Local Settings\Application Data\ekkfki

c:\documents and settings\Don\Local Settings\Application Data\rfogjq

c:\documents and settings\Don\Local Settings\Application Data\oqikvc

c:\documents and settings\Don\Local Settings\Application Data\wdyhmp

c:\documents and settings\Don\Local Settings\Application Data\idtxan

c:\documents and settings\Don\Local Settings\Application Data\qybnyx

c:\documents and settings\Don\Local Settings\Application Data\qmucns

c:\documents and settings\Don\Local Settings\Application Data\ntgjis

c:\documents and settings\Don\Local Settings\Application Data\karqds

c:\documents and settings\Don\Local Settings\Application Data\sfcaau

c:\documents and settings\Don\Local Settings\Application Data\tjqchm

c:\documents and settings\Don\Local Settings\Application Data\wqcpgp

c:\documents and settings\Don\Local Settings\Application Data\wevnec

c:\documents and settings\Don\Local Settings\Application Data\atvahx

c:\documents and settings\Don\Local Settings\Application Data\vowwgu

c:\documents and settings\Don\Local Settings\Application Data\aawnmp

c:\documents and settings\Don\Local Settings\Application Data\hplfwh

c:\documents and settings\Don\Local Settings\Application Data\jgeljv

c:\documents and settings\Don\Local Settings\Application Data\gpcbik

c:\documents and settings\Don\Local Settings\Application Data\iguiuy

c:\documents and settings\Don\Local Settings\Application Data\kngvuc

c:\documents and settings\Don\Local Settings\Application Data\qpysnm

c:\documents and settings\Don\Local Settings\Application Data\jdocnf

c:\documents and settings\Don\Local Settings\Application Data\diqeao

c:\documents and settings\Don\Local Settings\Application Data\hguymh

c:\documents and settings\Don\Local Settings\Application Data\huqlys

c:\documents and settings\Don\Local Settings\Application Data\cretvp

c:\documents and settings\Don\Local Settings\Application Data\ddoers

c:\documents and settings\Don\Local Settings\Application Data\ffakrk

c:\documents and settings\Don\Local Settings\Application Data\bprtbr

c:\documents and settings\Don\Local Settings\Application Data\gckbvt

c:\documents and settings\Don\Local Settings\Application Data\ijvovw

c:\documents and settings\Don\Local Settings\Application Data\xhdhex

c:\documents and settings\Don\Local Settings\Application Data\typybq

c:\documents and settings\Don\Local Settings\Application Data\wgbmbt

c:\documents and settings\Don\Local Settings\Application Data\dbycfr

c:\documents and settings\Don\Local Settings\Application Data\sjqiei

c:\documents and settings\Don\Local Settings\Application Data\flyqru

c:\documents and settings\Don\Local Settings\Application Data\gcrwej

c:\documents and settings\Don\Local Settings\Application Data\neqaoa

c:\documents and settings\Don\Local Settings\Application Data\courlp

c:\documents and settings\Don\Local Settings\Application Data\astoiq

c:\documents and settings\Don\Local Settings\Application Data\tgkxhj

c:\documents and settings\Don\Local Settings\Application Data\hlfsoo

c:\documents and settings\Don\Application Data\vrbnut

c:\documents and settings\Don\Local Settings\Application Data\vrbnut

c:\documents and settings\Don\Application Data\knloyf

c:\documents and settings\Don\Application Data\eyomay

c:\documents and settings\Don\Application Data\icegtf

c:\documents and settings\Don\Application Data\gsggwc

c:\documents and settings\Don\Application Data\dluswy

c:\documents and settings\Don\Application Data\cuclkk

c:\documents and settings\Don\Application Data\obqbai

c:\documents and settings\Don\Application Data\wetynd

c:\documents and settings\Don\Application Data\qvrfdi

c:\documents and settings\Don\Application Data\desfrg

c:\documents and settings\Don\Application Data\kjindc

c:\documents and settings\Don\Application Data\twikna

File::

c:\program files\1108296.dat

c:\program files\988484.dat

c:\program files\2062203.dat

c:\program files\1885031.dat

c:\program files\1110906.dat

c:\program files\1742984.dat

c:\program files\2696078.dat

c:\program files\3212046.dat

c:\program files\3212015.dat

c:\program files\3212171.dat

c:\program files\3120250.dat

c:\program files\3115921.dat

c:\program files\1688843.dat

c:\program files\1337156.dat

c:\program files\1962781.dat

c:\windows\system32\ndismgr.sys

c:\windows\system32\accesse.exe

c:\windows\system32\aexarasug.exe

CFScriptB-4.gif

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

Link to post
Share on other sites

They should stop soon.

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

Folder::

c:\documents and settings\Don\Local Settings\Application Data\wvqpcl

c:\documents and settings\Don\Local Settings\Application Data\ysvhqb

c:\documents and settings\Don\Local Settings\Application Data\gxlpcw

c:\documents and settings\Don\Local Settings\Application Data\buyxat

c:\documents and settings\Don\Local Settings\Application Data\cufeqa

c:\documents and settings\Don\Local Settings\Application Data\aeespn

c:\documents and settings\Don\Local Settings\Application Data\clohpr

c:\documents and settings\Don\Local Settings\Application Data\nvcscp

c:\documents and settings\Don\Local Settings\Application Data\smlfyv

c:\documents and settings\Don\Local Settings\Application Data\qehwqa

c:\documents and settings\Don\Local Settings\Application Data\ibeade

c:\documents and settings\Don\Local Settings\Application Data\fhphxf

c:\documents and settings\Don\Local Settings\Application Data\ncewyp

c:\documents and settings\Don\Local Settings\Application Data\rvyuuw

c:\documents and settings\Don\Local Settings\Application Data\yttvqg

c:\documents and settings\Don\Local Settings\Application Data\uqheod

c:\documents and settings\Don\Local Settings\Application Data\tbdocc

c:\documents and settings\Don\Local Settings\Application Data\ummyxf

c:\documents and settings\Don\Local Settings\Application Data\sxgdjq

c:\documents and settings\Don\Local Settings\Application Data\bogvqo

c:\documents and settings\Don\Local Settings\Application Data\sssgel

c:\documents and settings\Don\Local Settings\Application Data\alfkkk

c:\documents and settings\Don\Local Settings\Application Data\vjsshh

c:\documents and settings\Don\Local Settings\Application Data\lxlnlp

c:\documents and settings\Don\Local Settings\Application Data\flcwli

c:\documents and settings\Don\Local Settings\Application Data\npxlnk

c:\documents and settings\Don\Local Settings\Application Data\vlfblu

c:\documents and settings\Don\Local Settings\Application Data\ffafle

c:\documents and settings\Don\Local Settings\Application Data\mghrgo

c:\documents and settings\Don\Local Settings\Application Data\ofwrcb

c:\documents and settings\Don\Local Settings\Application Data\nvfyue

c:\documents and settings\Don\Local Settings\Application Data\qdqmuh

c:\documents and settings\Don\Local Settings\Application Data\bbbtcj

c:\documents and settings\Don\Local Settings\Application Data\vsgfiu

c:\documents and settings\Don\Local Settings\Application Data\yarsix

c:\documents and settings\Don\Local Settings\Application Data\kxcaoa

c:\documents and settings\Don\Local Settings\Application Data\xmaotw

c:\documents and settings\Don\Local Settings\Application Data\qapxtp

c:\documents and settings\Don\Local Settings\Application Data\nygrly

c:\documents and settings\Don\Local Settings\Application Data\nteblu

c:\documents and settings\Don\Local Settings\Application Data\esoowa

c:\documents and settings\Don\Local Settings\Application Data\rduxdb

c:\documents and settings\Don\Local Settings\Application Data\dvdojy

c:\documents and settings\Don\Local Settings\Application Data\symxre

c:\documents and settings\Don\Local Settings\Application Data\ntvkib

c:\documents and settings\Don\Local Settings\Application Data\crwxyu

c:\documents and settings\Don\Local Settings\Application Data\xduvlt

c:\documents and settings\Don\Local Settings\Application Data\lutvxv

c:\documents and settings\Don\Local Settings\Application Data\ssnwtf

c:\documents and settings\Don\Local Settings\Application Data\kkdcqy

c:\documents and settings\Don\Local Settings\Application Data\qyyepf

c:\documents and settings\Don\Local Settings\Application Data\rprkcu

c:\documents and settings\Don\Local Settings\Application Data\vxufeq

c:\documents and settings\Don\Local Settings\Application Data\lvcxlr

c:\documents and settings\Don\Local Settings\Application Data\bxrnkd

c:\documents and settings\Don\Local Settings\Application Data\jbulxy

c:\documents and settings\Don\Local Settings\Application Data\gobahk

c:\documents and settings\Don\Local Settings\Application Data\wwymwh

c:\documents and settings\Don\Local Settings\Application Data\xbopey

c:\documents and settings\Don\Local Settings\Application Data\ymvrut

c:\documents and settings\Don\Local Settings\Application Data\igqwte

c:\documents and settings\Don\Local Settings\Application Data\uqlnxj

c:\documents and settings\Don\Local Settings\Application Data\yjgmsp

c:\documents and settings\Don\Local Settings\Application Data\nrxsrg

c:\documents and settings\Don\Local Settings\Application Data\ainrjv

c:\documents and settings\Don\Local Settings\Application Data\iixiek

c:\documents and settings\Don\Local Settings\Application Data\bxbccd

c:\documents and settings\Don\Local Settings\Application Data\elnegy

c:\documents and settings\Don\Local Settings\Application Data\ttfkfp

c:\documents and settings\Don\Local Settings\Application Data\dwonjq

c:\documents and settings\Don\Local Settings\Application Data\laqlvm

c:\documents and settings\Don\Local Settings\Application Data\bbnkgr

c:\documents and settings\Don\Application Data\prspia

c:\documents and settings\Don\Local Settings\Application Data\prspia

c:\documents and settings\Don\Local Settings\Application Data\svoxgy

c:\documents and settings\Don\Local Settings\Application Data\ksmasd

c:\documents and settings\Don\Local Settings\Application Data\aoacmw

c:\documents and settings\Don\Local Settings\Application Data\cfaops

c:\documents and settings\Don\Local Settings\Application Data\hontxn

c:\documents and settings\Don\Local Settings\Application Data\fahxjy

c:\documents and settings\Don\Local Settings\Application Data\gqafvn

c:\documents and settings\Don\Local Settings\Application Data\nlxtbm

c:\documents and settings\Don\Local Settings\Application Data\xvmgnk

c:\documents and settings\Don\Local Settings\Application Data\ednawg

c:\documents and settings\Don\Local Settings\Application Data\ncaqeb

c:\documents and settings\Don\Local Settings\Application Data\igigqj

c:\documents and settings\Don\Local Settings\Application Data\huxvug

c:\documents and settings\Don\Local Settings\Application Data\akbqsa

c:\documents and settings\Don\Local Settings\Application Data\ssidci

c:\documents and settings\Don\Local Settings\Application Data\lscrgx

c:\documents and settings\Don\Local Settings\Application Data\njuxtm

c:\documents and settings\Don\Local Settings\Application Data\indogu

c:\documents and settings\Don\Local Settings\Application Data\twuhlj

c:\documents and settings\Don\Local Settings\Application Data\tjxmqg

c:\documents and settings\Don\Local Settings\Application Data\iothxk

c:\documents and settings\Don\Local Settings\Application Data\jfmoky

c:\documents and settings\Don\Local Settings\Application Data\ihyyia

c:\documents and settings\Don\Local Settings\Application Data\gatirl

File::

c:\program files\946234.dat

c:\program files\1591921.dat

c:\program files\927609.dat

c:\program files\927437.dat

c:\program files\924171.dat

c:\program files\1208046.dat

c:\program files\914968.dat

c:\program files\1153515.dat

c:\program files\943562.dat

c:\program files\1173921.dat

c:\program files\1960578.dat

CFScriptB-4.gif

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as Test.bat
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Once saved, double click on the Test.bat file and post its report.

@Echo off

cd /d %~dp0

ECHO Working....... Please wait

nbtstat -n >Report.txt

ipconfig /All >>Report.txt

Ping Yahoo.com >>Report.txt

Ping Google.com >>Report.txt

Net Start >>Report.txt

Notepad Report.txt

Del %0

Link to post
Share on other sites

Remove Comodo from your system.

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as CFScript.txt
  • Change the Save as Type to All Files
  • and Save it on the desktop

Folder::

c:\documents and settings\Don\Local Settings\Application Data\jhfvqo

c:\documents and settings\Don\Local Settings\Application Data\jmnsha

c:\documents and settings\Don\Local Settings\Application Data\flsaon

c:\documents and settings\Don\Local Settings\Application Data\ofnfnw

c:\documents and settings\Don\Local Settings\Application Data\gclhbc

c:\documents and settings\Don\Local Settings\Application Data\hseonq

c:\documents and settings\Don\Local Settings\Application Data\oxswym

c:\documents and settings\Don\Local Settings\Application Data\oafiwm

c:\documents and settings\Don\Local Settings\Application Data\lsttxi

c:\documents and settings\Don\Local Settings\Application Data\scmdfh

c:\documents and settings\Don\Local Settings\Application Data\tsfkrw

c:\documents and settings\Don\Local Settings\Application Data\vjxrfl

c:\documents and settings\Don\Local Settings\Application Data\fdsveu

c:\documents and settings\Don\Local Settings\Application Data\ahbmqd

c:\documents and settings\Don\Application Data\mihfpp

c:\documents and settings\Don\Local Settings\Application Data\mihfpp

c:\documents and settings\Don\Local Settings\Application Data\fvxopj

c:\documents and settings\Don\Local Settings\Application Data\hmqucx

c:\documents and settings\Don\Application Data\cqylog

c:\documents and settings\Don\Local Settings\Application Data\cqylog

c:\documents and settings\Don\Local Settings\Application Data\godgbx

c:\documents and settings\Don\Local Settings\Application Data\ryqrnw

c:\documents and settings\Don\Local Settings\Application Data\okkvyi

c:\documents and settings\Don\Local Settings\Application Data\dluswy

c:\documents and settings\Don\Local Settings\Application Data\vekuyg

c:\documents and settings\Don\Local Settings\Application Data\xucclu

c:\documents and settings\Don\Local Settings\Application Data\ugwgxg

c:\documents and settings\Don\Application Data\sjsewp

c:\documents and settings\Don\Local Settings\Application Data\sjsewp

c:\documents and settings\Don\Application Data\mwjnwj

c:\documents and settings\Don\Local Settings\Application Data\mwjnwj

c:\documents and settings\Don\Application Data\vqerws

c:\documents and settings\Don\Local Settings\Application Data\vqerws

c:\documents and settings\Don\Local Settings\Application Data\hbrejq

c:\documents and settings\Don\Local Settings\Application Data\pwythb

c:\documents and settings\Don\Local Settings\Application Data\xacrtv

c:\documents and settings\Don\Application Data\fxhono

c:\documents and settings\Don\Local Settings\Application Data\ymxxni

c:\documents and settings\Don\Local Settings\Application Data\slxrjf

c:\documents and settings\Don\Local Settings\Application Data\cfsvjo

c:\documents and settings\Don\Local Settings\Application Data\fxhono

c:\documents and settings\Don\Local Settings\Application Data\badtcw

c:\documents and settings\Don\Application Data\ehohba

c:\documents and settings\Don\Local Settings\Application Data\ehohba

c:\documents and settings\Don\Local Settings\Application Data\rnkchf

c:\documents and settings\Don\Local Settings\Application Data\nfkfqf

c:\documents and settings\Don\Local Settings\Application Data\wyfkqo

c:\documents and settings\Don\Local Settings\Application Data\dbxhky

c:\documents and settings\Don\Local Settings\Application Data\uxvjwd

c:\documents and settings\Don\Local Settings\Application Data\vooqjr

c:\documents and settings\Don\Local Settings\Application Data\pceajl

c:\documents and settings\Don\Local Settings\Application Data\ttnmgs

c:\documents and settings\Don\Local Settings\Application Data\senwik

c:\documents and settings\Don\Application Data\uqjahk

c:\documents and settings\Don\Local Settings\Application Data\uqjahk

c:\documents and settings\Don\Local Settings\Application Data\baecxu

c:\documents and settings\Don\Local Settings\Application Data\swceky

c:\documents and settings\Don\Local Settings\Application Data\ktygxe

c:\documents and settings\Don\Local Settings\Application Data\lfjqth

c:\documents and settings\Don\Local Settings\Application Data\dpdobp

c:\documents and settings\Don\Local Settings\Application Data\ymrwym

c:\documents and settings\Don\Local Settings\Application Data\wwxgdg

c:\documents and settings\Don\Local Settings\Application Data\pkopda

c:\documents and settings\Don\Local Settings\Application Data\huinki

c:\documents and settings\Don\Local Settings\Application Data\roeskr

c:\documents and settings\Don\Local Settings\Application Data\epkkjf

c:\documents and settings\Don\Local Settings\Application Data\qkjhfn

c:\documents and settings\Don\Local Settings\Application Data\buwsrm

c:\documents and settings\Don\Local Settings\Application Data\lorwrv

c:\documents and settings\Don\Local Settings\Application Data\gsanee

c:\documents and settings\Don\Local Settings\Application Data\fnrqns

c:\documents and settings\Don\Local Settings\Application Data\uqbbvx

c:\documents and settings\Don\Local Settings\Application Data\hvyolo

c:\documents and settings\Don\Local Settings\Application Data\rgmaxm

c:\documents and settings\Don\Local Settings\Application Data\bdtpvw

c:\documents and settings\Don\Local Settings\Application Data\lnhbiu

c:\documents and settings\Don\Local Settings\Application Data\tyxxyi

c:\documents and settings\Don\Local Settings\Application Data\lqndvc

c:\documents and settings\Don\Local Settings\Application Data\eedmuu

c:\documents and settings\Don\Local Settings\Application Data\bkotqv

c:\documents and settings\Don\Local Settings\Application Data\ruuroy

c:\documents and settings\Don\Local Settings\Application Data\pgovbk

c:\documents and settings\Don\Local Settings\Application Data\vbmlfj

c:\documents and settings\Don\Local Settings\Application Data\xrloam

c:\documents and settings\Don\Local Settings\Application Data\ksrhyy

c:\documents and settings\Don\Local Settings\Application Data\qhnjxg

c:\documents and settings\Don\Local Settings\Application Data\sqlivj

c:\documents and settings\Don\Local Settings\Application Data\yxncfe

c:\documents and settings\Don\Local Settings\Application Data\xsqcmc

c:\documents and settings\Don\Local Settings\Application Data\pmyxxc

c:\documents and settings\Don\Local Settings\Application Data\robpgu

c:\documents and settings\Don\Local Settings\Application Data\biwtge

c:\documents and settings\Don\Local Settings\Application Data\njdmfr

c:\documents and settings\Don\Local Settings\Application Data\pcqavl

c:\documents and settings\Don\Application Data\yvlevu

c:\documents and settings\Don\Application Data\rjcnuo

c:\documents and settings\Don\Local Settings\Application Data\yvlevu

c:\documents and settings\Don\Local Settings\Application Data\tauuid

c:\documents and settings\Don\Local Settings\Application Data\rjcnuo

c:\documents and settings\Don\Application Data\cdwsuy

c:\documents and settings\Don\Local Settings\Application Data\lwrwui

c:\documents and settings\Don\Local Settings\Application Data\cdwsuy

c:\documents and settings\Don\Application Data\xspsdk

File::

c:\program files\913859.dat

c:\program files\2408937.dat

c:\program files\1060687.dat

c:\program files\1187359.dat

CFScriptB-4.gif

Once saved, referring to the picture above, drag CFScript.txt into ComboFix.exe, and post back the resulting report.

Lets take a deeper look.

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • OTL should now start. Change the following settings
    • Change Drivers to All
    • Change Registry and Extra Registry to All
    • Under File Scans, change File age to 30

    [*]Under the Custom Scan box paste this in

    netsvcs

    %SYSTEMDRIVE%\*.exe

    /md5start

    eventlog.dll

    scecli.dll

    netlogon.dll

    cngaudit.dll

    sceclt.dll

    ntelogon.dll

    logevent.dll

    iaStor.sys

    nvstor.sys

    atapi.sys

    IdeChnDr.sys

    viasraid.sys

    AGP440.sys

    vaxscsi.sys

    nvatabus.sys

    viamraid.sys

    nvata.sys

    nvgts.sys

    iastorv.sys

    ViPrt.sys

    eNetHook.dll

    ahcix86.sys

    KR10N.sys

    nvstor32.sys

    ahcix86s.sys

    nvrd32.sys

    /md5stop

    %systemroot%\*. /mp /s

    CREATERESTOREPOINT

    %systemroot%\system32\*.dll /lockedfiles

    %systemroot%\Tasks\*.job /lockedfiles

    [*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please attach the contents of these files in your next reply.

gmer_zip.gif

Download GMER Rootkit Scanner from here or here.

  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe.
  • If it gives you a warning about rootkit activity and asks if you want to run a full scan...click on NO, then use the following settings for a more complete scan..
    GMER.png
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED ...
    • Sections
    • Processes
    • Threads
    • Libraries
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)

    [*] Then click the Scan button & wait for it to finish.

    [*] Once done click on the [save..] button, and in the File name area, type in "ark.txt"

    [*]Save it where you can easily find it, such as your desktop and post its contents in your next reply.

**Caution**

Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

I will check these report in the AM.

Link to post
Share on other sites

I uninstalled Comodo last week and I did a search. The only file that shows up is the quarantined one in combofix. Also, when I did the OTL scan I changed everything as you said, but when I started the scan it changed file age to 14, drivers to none and registry to none. I tried it again and it did the same thing. When I did the GMER scan the desktop went away and all that I see is the background. It has been like that for about 20 minutes. Is it still scanning? I will attach the logs from the previous two scans.

log6.txt

OTL.Txt

Extras.Txt

Link to post
Share on other sites

Hi, donj :)

The reports submitted provide no clue as to what is the problem. Perhaps we should take a look at the computer from an external source.

First, if you were unable to run GMER, follow these steps:

  1. Double click GMER.exe.
  2. No need to scan. Just wait until the initial scan is finished.
  3. Once done click on the Rootkit tab, then on the[save..] button, and in the File name area, type in "ark.txt"
  4. Change the Save as Type to All Files
  5. Save the log where you can easily find it, such as your desktop.
  6. Post it in your next reply

**Caution**

Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Please copy and paste the contents of that report in your next reply.

Now, back to the external source, you will need a flash drive to move information from the sick computer to a working computer, so we can see the progress of our actions. Save these instructions in your flash drive as a text file (use notepad) so you can have access to these while in an external environment (PE).

Here is what you need to do.

Two programs to download

First

Download ISOBurner. Click Here for ISOBurner Instructions. Install the program, and follow the next set of steps.

Second

  • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 276.7MB in size so it may take some time to download.
  • When downloaded double click and this will then open ISOBurner to burn the file to CD
  • Boot the Non working computer using the boot CD you just created.
  • In order to do so, the computer must be set to boot from the CD first
    Note : For information click here
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to All
    • Change Registry to All
    • Under the Custom Scan box paste this in


      %SYSTEMDRIVE%\*.*

      /md5start

      eventlog.dll

      scecli.dll

      netlogon.dll

      cngaudit.dll

      sceclt.dll

      ntelogon.dll

      logevent.dll

      iaStor.sys

      nvstor.sys

      atapi.sys

      IdeChnDr.sys

      viasraid.sys

      AGP440.sys

      vaxscsi.sys

      nvatabus.sys

      viamraid.sys

      nvata.sys

      nvgts.sys

      iastorv.sys

      ViPrt.sys

      eNetHook.dll

      ahcix86.sys

      KR10N.sys

      nvstor32.sys

      ahcix86s.sys

      nvrd32.sys

      /md5stop

      %systemroot%\*. /mp /s

      %systemroot%\System32\config\*.sav


    [*]Press Run Scan to start the scan.

    [*]When finished, the file will be saved in drive C:\OTL.txt

    [*]Copy this file to your USB drive.

    [*]Please post the contents of the C:\OTL.txt file in your reply.

Link to post
Share on other sites

Lets try another program.

Download OTS.exe by OldTimer to your Desktop.

  1. Close any open browsers.
  2. Double-click on OTS.exe to start the program.
  3. Leave all settings as they appear as default, except for the following:
    • Under Drivers, select "All".
    • Under Registry, select "All".
    • File age should be 30 days.
    • Under Additional Scans, click on the "Extras" button.

[*]Now click the Run Scan button on the toolbar.

[*]The program will be scanning huge amounts of data so depending on your system it could take a long time to complete. Let it run unhindered until it finishes.

[*]When the scan is complete Notepad will open with the report file loaded in it.

[*]Save that notepad file

Use the Reply button and attach the notepad file here (Do not copy and paste in a reply, rather attach it to it).

Link to post
Share on other sites

Lets try another program.

Download OTS.exe by OldTimer to your Desktop.

  1. Close any open browsers.
  2. Double-click on OTS.exe to start the program.
  3. Leave all settings as they appear as default, except for the following:
    • Under Drivers, select "All".
    • Under Registry, select "All".
    • File age should be 30 days.
    • Under Additional Scans, click on the "Extras" button.

[*]Now click the Run Scan button on the toolbar.

[*]The program will be scanning huge amounts of data so depending on your system it could take a long time to complete. Let it run unhindered until it finishes.

[*]When the scan is complete Notepad will open with the report file loaded in it.

[*]Save that notepad file

Use the Reply button and attach the notepad file here (Do not copy and paste in a reply, rather attach it to it).

file is attached

OTS.Txt

Link to post
Share on other sites

Start OTS. Copy/Paste the information in the Quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

[Kill All Processes]

[unregister Dlls]

[Win32 Services - Safe List]

YN -> (cmdAgent) COMODO Internet Security Helper Service [Disabled | Stopped] ->

[Driver Services - All]

YY -> (cmdGuard) COMODO Internet Security Sandbox Driver [File_System | System | Running] -> C:\WINDOWS\system32\drivers\cmdguard.sys

YY -> (Inspect) COMODO Internet Security Firewall Driver [Kernel | Boot | Running] -> C:\WINDOWS\System32\DRIVERS\inspect.sys

YY -> (cmdHlp) COMODO Internet Security Helper Driver [Kernel | System | Running] -> C:\WINDOWS\system32\drivers\cmdhlp.sys

[Registry - All]

< Trusted Sites Domains [HKEY_LOCAL_MACHINE\] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\

YN -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 2 domain(s) found.

YN -> buy-internetsecurity10.com .[http] -> Trusted sites

YN -> 1 domain(s) and sub-domain(s) not assigned to a zone. ->

< Trusted Sites Domains [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\

YN -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ -> [Key] 4 domain(s) found.

YN -> buy-internetsecurity10.com .[http] -> Trusted sites

YN -> is10-soft-download.com .[http] -> Trusted sites

YN -> is-software-download.com .[http] -> Trusted sites

YN -> is-software-download25.com .[http] -> Trusted sites

[Files/Folders - Created Within 30 Days]

NY -> lhashi -> C:\Documents and Settings\Don\Local Settings\Application Data\lhashi

NY -> ubvwhr -> C:\Documents and Settings\Don\Local Settings\Application Data\ubvwhr

NY -> xiglgu -> C:\Documents and Settings\Don\Local Settings\Application Data\xiglgu

NY -> hccpgf -> C:\Documents and Settings\Don\Local Settings\Application Data\hccpgf

NY -> jstwst -> C:\Documents and Settings\Don\Local Settings\Application Data\jstwst

NY -> cgkgsn -> C:\Documents and Settings\Don\Local Settings\Application Data\cgkgsn

NY -> tdiifr -> C:\Documents and Settings\Don\Local Settings\Application Data\tdiifr

NY -> hofulc -> C:\Documents and Settings\Don\Local Settings\Application Data\hofulc

NY -> jlyoei -> C:\Documents and Settings\Don\Local Settings\Application Data\jlyoei

NY -> eqifqq -> C:\Documents and Settings\Don\Local Settings\Application Data\eqifqq

NY -> tyyloh -> C:\Documents and Settings\Don\Local Settings\Application Data\tyyloh

NY -> aehoju -> C:\Documents and Settings\Don\Local Settings\Application Data\aehoju

NY -> jxdtjf -> C:\Documents and Settings\Don\Local Settings\Application Data\jxdtjf

NY -> bnbxfr -> C:\Documents and Settings\Don\Local Settings\Application Data\bnbxfr

NY -> jqdvrn -> C:\Documents and Settings\Don\Local Settings\Application Data\jqdvrn

NY -> lhvdec -> C:\Documents and Settings\Don\Local Settings\Application Data\lhvdec

NY -> kjindc -> C:\Documents and Settings\Don\Local Settings\Application Data\kjindc

NY -> utvapa -> C:\Documents and Settings\Don\Local Settings\Application Data\utvapa

NY -> desfrg -> C:\Documents and Settings\Don\Local Settings\Application Data\desfrg

NY -> qvrfdi -> C:\Documents and Settings\Don\Local Settings\Application Data\qvrfdi

NY -> labupq -> C:\Documents and Settings\Don\Local Settings\Application Data\labupq

NY -> cgfqpg -> C:\Documents and Settings\Don\Local Settings\Application Data\cgfqpg

NY -> dwxwcu -> C:\Documents and Settings\Don\Local Settings\Application Data\dwxwcu

NY -> pxepci -> C:\Documents and Settings\Don\Local Settings\Application Data\pxepci

NY -> wetynd -> C:\Documents and Settings\Don\Local Settings\Application Data\wetynd

NY -> twikna -> C:\Documents and Settings\Don\Local Settings\Application Data\twikna

NY -> eqdpnk -> C:\Documents and Settings\Don\Local Settings\Application Data\eqdpnk

NY -> birbog -> C:\Documents and Settings\Don\Local Settings\Application Data\birbog

NY -> nkxtnt -> C:\Documents and Settings\Don\Local Settings\Application Data\nkxtnt

NY -> mtgnbf -> C:\Documents and Settings\Don\Local Settings\Application Data\mtgnbf

NY -> obqbai -> C:\Documents and Settings\Don\Local Settings\Application Data\obqbai

NY -> ejihyy -> C:\Documents and Settings\Don\Local Settings\Application Data\ejihyy

NY -> dspbmk -> C:\Documents and Settings\Don\Local Settings\Application Data\dspbmk

NY -> gaboln -> C:\Documents and Settings\Don\Local Settings\Application Data\gaboln

NY -> bejfxv -> C:\Documents and Settings\Don\Local Settings\Application Data\bejfxv

NY -> ihmckq -> C:\Documents and Settings\Don\Local Settings\Application Data\ihmckq

NY -> kxfjxf -> C:\Documents and Settings\Don\Local Settings\Application Data\kxfjxf

NY -> cuclkk -> C:\Documents and Settings\Don\Local Settings\Application Data\cuclkk

NY -> fcnajn -> C:\Documents and Settings\Don\Local Settings\Application Data\fcnajn

NY -> wylcws -> C:\Documents and Settings\Don\Local Settings\Application Data\wylcws

NY -> gsggwc -> C:\Documents and Settings\Don\Local Settings\Application Data\gsggwc

NY -> stmyvo -> C:\Documents and Settings\Don\Local Settings\Application Data\stmyvo

NY -> rdtsja -> C:\Documents and Settings\Don\Local Settings\Application Data\rdtsja

NY -> ukfgie -> C:\Documents and Settings\Don\Local Settings\Application Data\ukfgie

NY -> vbxnus -> C:\Documents and Settings\Don\Local Settings\Application Data\vbxnus

NY -> mhciui -> C:\Documents and Settings\Don\Local Settings\Application Data\mhciui

NY -> eeakin -> C:\Documents and Settings\Don\Local Settings\Application Data\eeakin

NY -> oonwul -> C:\Documents and Settings\Don\Local Settings\Application Data\oonwul

NY -> fusruc -> C:\Documents and Settings\Don\Local Settings\Application Data\fusruc

NY -> yiibuv -> C:\Documents and Settings\Don\Local Settings\Application Data\yiibuv

NY -> icegtf -> C:\Documents and Settings\Don\Local Settings\Application Data\icegtf

NY -> jsvmht -> C:\Documents and Settings\Don\Local Settings\Application Data\jsvmht

NY -> bptoty -> C:\Documents and Settings\Don\Local Settings\Application Data\bptoty

NY -> tmrrhe -> C:\Documents and Settings\Don\Local Settings\Application Data\tmrrhe

NY -> dgmvgn -> C:\Documents and Settings\Don\Local Settings\Application Data\dgmvgn

NY -> qhqmox -> C:\Documents and Settings\Don\Local Settings\Application Data\qhqmox

NY -> rxitbm -> C:\Documents and Settings\Don\Local Settings\Application Data\rxitbm

NY -> tobbnb -> C:\Documents and Settings\Don\Local Settings\Application Data\tobbnb

NY -> mcrknt -> C:\Documents and Settings\Don\Local Settings\Application Data\mcrknt

NY -> llydaf -> C:\Documents and Settings\Don\Local Settings\Application Data\llydaf

NY -> eyomay -> C:\Documents and Settings\Don\Local Settings\Application Data\eyomay

NY -> oskqaj -> C:\Documents and Settings\Don\Local Settings\Application Data\oskqaj

NY -> xmfvas -> C:\Documents and Settings\Don\Local Settings\Application Data\xmfvas

NY -> gphtmn -> C:\Documents and Settings\Don\Local Settings\Application Data\gphtmn

NY -> hgaayc -> C:\Documents and Settings\Don\Local Settings\Application Data\hgaayc

NY -> knloyf -> C:\Documents and Settings\Don\Local Settings\Application Data\knloyf

NY -> frteln -> C:\Documents and Settings\Don\Local Settings\Application Data\frteln

NY -> olpjlx -> C:\Documents and Settings\Don\Local Settings\Application Data\olpjlx

NY -> tnrpch -> C:\Documents and Settings\Don\Local Settings\Application Data\tnrpch

NY -> xspsdk -> C:\Documents and Settings\Don\Local Settings\Application Data\xspsdk

NY -> lkospl -> C:\Documents and Settings\Don\Local Settings\Application Data\lkospl

NY -> gpxict -> C:\Documents and Settings\Don\Local Settings\Application Data\gpxict

NY -> thvinv -> C:\Documents and Settings\Don\Application Data\thvinv

NY -> thvinv -> C:\Documents and Settings\Don\Local Settings\Application Data\thvinv

NY -> olfxae -> C:\Documents and Settings\Don\Local Settings\Application Data\olfxae

NY -> rsqmyh -> C:\Documents and Settings\Don\Local Settings\Application Data\rsqmyh

NY -> sjitlv -> C:\Documents and Settings\Don\Local Settings\Application Data\sjitlv

NY -> uabayk -> C:\Documents and Settings\Don\Local Settings\Application Data\uabayk

NY -> etwfxt -> C:\Documents and Settings\Don\Local Settings\Application Data\etwfxt

NY -> aoxcwq -> C:\Documents and Settings\Don\Local Settings\Application Data\aoxcwq

NY -> gdtevw -> C:\Documents and Settings\Don\Local Settings\Application Data\gdtevw

NY -> bcoflq -> C:\Documents and Settings\Don\Local Settings\Application Data\bcoflq

NY -> bcoflq -> C:\Documents and Settings\Don\Application Data\bcoflq

NY -> djatlt -> C:\Documents and Settings\Don\Local Settings\Application Data\djatlt

NY -> otnfxs -> C:\Documents and Settings\Don\Local Settings\Application Data\otnfxs

NY -> xnijxc -> C:\Documents and Settings\Don\Local Settings\Application Data\xnijxc

NY -> koocwp -> C:\Documents and Settings\Don\Application Data\koocwp

NY -> ihdowl -> C:\Documents and Settings\Don\Local Settings\Application Data\ihdowl

NY -> koocwp -> C:\Documents and Settings\Don\Local Settings\Application Data\koocwp

NY -> mfhjje -> C:\Documents and Settings\Don\Local Settings\Application Data\mfhjje

NY -> ecflvi -> C:\Documents and Settings\Don\Local Settings\Application Data\ecflvi

NY -> bqlbgt -> C:\Documents and Settings\Don\Local Settings\Application Data\bqlbgt

NY -> vutrsc -> C:\Documents and Settings\Don\Local Settings\Application Data\vutrsc

NY -> viqmnf -> C:\Documents and Settings\Don\Local Settings\Application Data\viqmnf

NY -> gnvbjs -> C:\Documents and Settings\Don\Application Data\gnvbjs

NY -> gnvbjs -> C:\Documents and Settings\Don\Local Settings\Application Data\gnvbjs

NY -> ciwyip -> C:\Documents and Settings\Don\Application Data\ciwyip

NY -> ciwyip -> C:\Documents and Settings\Don\Local Settings\Application Data\ciwyip

NY -> tfubuu -> C:\Documents and Settings\Don\Application Data\tfubuu

NY -> tfubuu -> C:\Documents and Settings\Don\Local Settings\Application Data\tfubuu

NY -> mpoycd -> C:\Documents and Settings\Don\Local Settings\Application Data\mpoycd

NY -> wackob -> C:\Documents and Settings\Don\Local Settings\Application Data\wackob

NY -> mtpbbp -> C:\Documents and Settings\Don\Local Settings\Application Data\mtpbbp

NY -> vnkfba -> C:\Documents and Settings\Don\Local Settings\Application Data\vnkfba

NY -> wedmno -> C:\Documents and Settings\Don\Local Settings\Application Data\wedmno

NY -> hxxrnx -> C:\Documents and Settings\Don\Local Settings\Application Data\hxxrnx

NY -> sbqukl -> C:\Documents and Settings\Don\Local Settings\Application Data\sbqukl

NY -> dlegwj -> C:\Documents and Settings\Don\Local Settings\Application Data\dlegwj

NY -> dlegwj -> C:\Documents and Settings\Don\Application Data\dlegwj

NY -> nfalwt -> C:\Documents and Settings\Don\Local Settings\Application Data\nfalwt

NY -> cnqrvj -> C:\Documents and Settings\Don\Local Settings\Application Data\cnqrvj

NY -> ukotio -> C:\Documents and Settings\Don\Local Settings\Application Data\ukotio

NY -> bpddtj -> C:\Documents and Settings\Don\Local Settings\Application Data\bpddtj

NY -> xjuejf -> C:\Documents and Settings\Don\Local Settings\Application Data\xjuejf

NY -> aanlvt -> C:\Documents and Settings\Don\Local Settings\Application Data\aanlvt

NY -> dhxyvw -> C:\Documents and Settings\Don\Local Settings\Application Data\dhxyvw

NY -> nrmkiv -> C:\Documents and Settings\Don\Local Settings\Application Data\nrmkiv

NY -> wlscvv -> C:\Documents and Settings\Don\Local Settings\Application Data\wlscvv

NY -> gfnhvg -> C:\Documents and Settings\Don\Local Settings\Application Data\gfnhvg

NY -> tmunbk -> C:\Documents and Settings\Don\Local Settings\Application Data\tmunbk

NY -> cfcrrp -> C:\Documents and Settings\Don\Application Data\cfcrrp

NY -> cfcrrp -> C:\Documents and Settings\Don\Local Settings\Application Data\cfcrrp

NY -> wjkiex -> C:\Documents and Settings\Don\Local Settings\Application Data\wjkiex

NY -> xtihcb -> C:\Documents and Settings\Don\Local Settings\Application Data\xtihcb

NY -> lntrmd -> C:\Documents and Settings\Don\Local Settings\Application Data\lntrmd

NY -> xcvggt -> C:\Documents and Settings\Don\Local Settings\Application Data\xcvggt

NY -> fpanvg -> C:\Documents and Settings\Don\Application Data\fpanvg

NY -> fpanvg -> C:\Documents and Settings\Don\Local Settings\Application Data\fpanvg

NY -> nuucxi -> C:\Documents and Settings\Don\Local Settings\Application Data\nuucxi

NY -> rsywjb -> C:\Documents and Settings\Don\Local Settings\Application Data\rsywjb

NY -> emkhtc -> C:\Documents and Settings\Don\Local Settings\Application Data\emkhtc

NY -> wurtdk -> C:\Documents and Settings\Don\Local Settings\Application Data\wurtdk

NY -> kkpyyp -> C:\Documents and Settings\Don\Local Settings\Application Data\kkpyyp

NY -> gaiahb -> C:\Documents and Settings\Don\Local Settings\Application Data\gaiahb

NY -> wtkqcu -> C:\Documents and Settings\Don\Local Settings\Application Data\wtkqcu

NY -> wrnbpw -> C:\Documents and Settings\Don\Local Settings\Application Data\wrnbpw

NY -> yhnots -> C:\Documents and Settings\Don\Local Settings\Application Data\yhnots

NY -> axgugh -> C:\Documents and Settings\Don\Local Settings\Application Data\axgugh

NY -> krbagq -> C:\Documents and Settings\Don\Application Data\krbagq

NY -> krbagq -> C:\Documents and Settings\Don\Local Settings\Application Data\krbagq

NY -> tsxrls -> C:\Documents and Settings\Don\Local Settings\Application Data\tsxrls

NY -> vjqyxh -> C:\Documents and Settings\Don\Local Settings\Application Data\vjqyxh

NY -> yqcmwk -> C:\Documents and Settings\Don\Local Settings\Application Data\yqcmwk

NY -> lrifwx -> C:\Documents and Settings\Don\Local Settings\Application Data\lrifwx

NY -> gpxdis -> C:\Documents and Settings\Don\Local Settings\Application Data\gpxdis

NY -> hgqjui -> C:\Documents and Settings\Don\Local Settings\Application Data\hgqjui

NY -> thwcuu -> C:\Documents and Settings\Don\Local Settings\Application Data\thwcuu

NY -> qpuunu -> C:\Documents and Settings\Don\Local Settings\Application Data\qpuunu

NY -> hgcgsq -> C:\Documents and Settings\Don\Local Settings\Application Data\hgcgsq

NY -> pcjvqa -> C:\Documents and Settings\Don\Local Settings\Application Data\pcjvqa

NY -> xadwnk -> C:\Documents and Settings\Don\Local Settings\Application Data\xadwnk

NY -> htycmt -> C:\Documents and Settings\Don\Application Data\htycmt

NY -> htycmt -> C:\Documents and Settings\Don\Local Settings\Application Data\htycmt

NY -> utladn -> C:\Documents and Settings\Don\Local Settings\Application Data\utladn

NY -> nehluy -> C:\Documents and Settings\Don\Local Settings\Application Data\nehluy

NY -> tlifeu -> C:\Documents and Settings\Don\Local Settings\Application Data\tlifeu

NY -> qbnpur -> C:\Documents and Settings\Don\Local Settings\Application Data\qbnpur

NY -> camrvt -> C:\Documents and Settings\Don\Local Settings\Application Data\camrvt

NY -> xpfref -> C:\Documents and Settings\Don\Local Settings\Application Data\xpfref

NY -> hjaweo -> C:\Documents and Settings\Don\Application Data\hjaweo

NY -> hjaweo -> C:\Documents and Settings\Don\Local Settings\Application Data\hjaweo

NY -> bwqgei -> C:\Documents and Settings\Don\Local Settings\Application Data\bwqgei

NY -> aydqci -> C:\Documents and Settings\Don\Local Settings\Application Data\aydqci

NY -> ccfila -> C:\Documents and Settings\Don\Local Settings\Application Data\ccfila

NY -> wkmvbh -> C:\Documents and Settings\Don\Local Settings\Application Data\wkmvbh

NY -> arxjbk -> C:\Documents and Settings\Don\Local Settings\Application Data\arxjbk

NY -> fgtlyq -> C:\Documents and Settings\Don\Local Settings\Application Data\fgtlyq

NY -> xocxiy -> C:\Documents and Settings\Don\Local Settings\Application Data\xocxiy

NY -> efdmtu -> C:\Documents and Settings\Don\Local Settings\Application Data\efdmtu

NY -> rwcmfw -> C:\Documents and Settings\Don\Local Settings\Application Data\rwcmfw

NY -> dpdwvn -> C:\Documents and Settings\Don\Local Settings\Application Data\dpdwvn

NY -> woeqrk -> C:\Documents and Settings\Don\Local Settings\Application Data\woeqrk

NY -> ebxscm -> C:\Documents and Settings\Don\Local Settings\Application Data\ebxscm

NY -> rcelby -> C:\Documents and Settings\Don\Local Settings\Application Data\rcelby

NY -> wqanaf -> C:\Documents and Settings\Don\Application Data\wqanaf

NY -> wqanaf -> C:\Documents and Settings\Don\Local Settings\Application Data\wqanaf

NY -> xrdhqp -> C:\Documents and Settings\Don\Local Settings\Application Data\xrdhqp

NY -> sjisxb -> C:\Documents and Settings\Don\Local Settings\Application Data\sjisxb

NY -> vetacg -> C:\Documents and Settings\Don\Local Settings\Application Data\vetacg

NY -> omcnlo -> C:\Documents and Settings\Don\Local Settings\Application Data\omcnlo

NY -> xgwrlx -> C:\Documents and Settings\Don\Local Settings\Application Data\xgwrlx

NY -> rhjwfu -> C:\Documents and Settings\Don\Application Data\rhjwfu

NY -> rhjwfu -> C:\Documents and Settings\Don\Local Settings\Application Data\rhjwfu

NY -> cmolbi -> C:\Documents and Settings\Don\Local Settings\Application Data\cmolbi

NY -> tfrlrb -> C:\Documents and Settings\Don\Local Settings\Application Data\tfrlrb

NY -> fiituh -> C:\Documents and Settings\Don\Local Settings\Application Data\fiituh

NY -> ecpyvg -> C:\Documents and Settings\Don\Application Data\ecpyvg

NY -> tiuuvw -> C:\Documents and Settings\Don\Local Settings\Application Data\tiuuvw

NY -> ecpyvg -> C:\Documents and Settings\Don\Local Settings\Application Data\ecpyvg

NY -> sxdboa -> C:\Documents and Settings\Don\Local Settings\Application Data\sxdboa

NY -> anpbsc -> C:\Documents and Settings\Don\Local Settings\Application Data\anpbsc

NY -> dubosf -> C:\Documents and Settings\Don\Local Settings\Application Data\dubosf

NY -> pvhhrs -> C:\Documents and Settings\Don\Local Settings\Application Data\pvhhrs

NY -> guard32.dll -> C:\WINDOWS\System32\guard32.dll

NY -> cmdguard.sys -> C:\WINDOWS\System32\drivers\cmdguard.sys

NY -> inspect.sys -> C:\WINDOWS\System32\drivers\inspect.sys

NY -> cmdhlp.sys -> C:\WINDOWS\System32\drivers\cmdhlp.sys

NY -> utduii -> C:\Documents and Settings\Don\Application Data\utduii

NY -> nhseic -> C:\Documents and Settings\Don\Local Settings\Application Data\nhseic

NY -> utduii -> C:\Documents and Settings\Don\Local Settings\Application Data\utduii

NY -> ouhjyk -> C:\Documents and Settings\Don\Local Settings\Application Data\ouhjyk

NY -> ffhprk -> C:\Documents and Settings\Don\Local Settings\Application Data\ffhprk

NY -> ingljj -> C:\Documents and Settings\Don\Local Settings\Application Data\ingljj

NY -> xukfjx -> C:\Documents and Settings\Don\Local Settings\Application Data\xukfjx

NY -> fiou.exe -> C:\fiou.exe

NY -> 9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp

[Files/Folders - Modified Within 30 Days]

NY -> sfi.dat -> C:\WINDOWS\System32\drivers\sfi.dat

NY -> OTS.exe -> C:\Documents and Settings\Don\Desktop\OTS.exe

NY -> 21586562.dat -> C:\Program Files\21586562.dat

NY -> 21586312.dat -> C:\Program Files\21586312.dat

NY -> 21586140.dat -> C:\Program Files\21586140.dat

NY -> 21585890.dat -> C:\Program Files\21585890.dat

NY -> 21586046.dat -> C:\Program Files\21586046.dat

NY -> 21585515.dat -> C:\Program Files\21585515.dat

NY -> 21584578.dat -> C:\Program Files\21584578.dat

NY -> 21585421.dat -> C:\Program Files\21585421.dat

NY -> 21585296.dat -> C:\Program Files\21585296.dat

NY -> 21585218.dat -> C:\Program Files\21585218.dat

NY -> 21584234.dat -> C:\Program Files\21584234.dat

NY -> 21577656.dat -> C:\Program Files\21577656.dat

NY -> 21577343.dat -> C:\Program Files\21577343.dat

NY -> 21577171.dat -> C:\Program Files\21577171.dat

NY -> 21576718.dat -> C:\Program Files\21576718.dat

NY -> 1959984.dat -> C:\Program Files\1959984.dat

NY -> 1959546.dat -> C:\Program Files\1959546.dat

NY -> 1958359.dat -> C:\Program Files\1958359.dat

NY -> 1956953.dat -> C:\Program Files\1956953.dat

NY -> 1956281.dat -> C:\Program Files\1956281.dat

NY -> 1955343.dat -> C:\Program Files\1955343.dat

NY -> 1954171.dat -> C:\Program Files\1954171.dat

NY -> 1952328.dat -> C:\Program Files\1952328.dat

NY -> 1951828.dat -> C:\Program Files\1951828.dat

NY -> 1951234.dat -> C:\Program Files\1951234.dat

NY -> 1947828.dat -> C:\Program Files\1947828.dat

NY -> 1947015.dat -> C:\Program Files\1947015.dat

NY -> 1946484.dat -> C:\Program Files\1946484.dat

NY -> 1944937.dat -> C:\Program Files\1944937.dat

NY -> guard32.dll -> C:\WINDOWS\System32\guard32.dll

NY -> cmdguard.sys -> C:\WINDOWS\System32\drivers\cmdguard.sys

NY -> inspect.sys -> C:\WINDOWS\System32\drivers\inspect.sys

NY -> cmdhlp.sys -> C:\WINDOWS\System32\drivers\cmdhlp.sys

NY -> fiou.exe -> C:\fiou.exe

NY -> 9 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp

[Files - No Company Name]

NY -> 21586562.dat -> C:\Program Files\21586562.dat

NY -> 21586312.dat -> C:\Program Files\21586312.dat

NY -> 21586140.dat -> C:\Program Files\21586140.dat

NY -> 21585890.dat -> C:\Program Files\21585890.dat

NY -> 21586046.dat -> C:\Program Files\21586046.dat

NY -> 21585515.dat -> C:\Program Files\21585515.dat

NY -> 21584578.dat -> C:\Program Files\21584578.dat

NY -> 21585421.dat -> C:\Program Files\21585421.dat

NY -> 21585296.dat -> C:\Program Files\21585296.dat

NY -> 21585218.dat -> C:\Program Files\21585218.dat

NY -> 21584234.dat -> C:\Program Files\21584234.dat

NY -> 21577656.dat -> C:\Program Files\21577656.dat

NY -> 21577343.dat -> C:\Program Files\21577343.dat

NY -> 21577171.dat -> C:\Program Files\21577171.dat

NY -> 21576718.dat -> C:\Program Files\21576718.dat

NY -> 1959984.dat -> C:\Program Files\1959984.dat

NY -> 1959546.dat -> C:\Program Files\1959546.dat

NY -> 1958359.dat -> C:\Program Files\1958359.dat

NY -> 1956953.dat -> C:\Program Files\1956953.dat

NY -> 1956281.dat -> C:\Program Files\1956281.dat

NY -> 1955343.dat -> C:\Program Files\1955343.dat

NY -> 1954171.dat -> C:\Program Files\1954171.dat

NY -> 1952328.dat -> C:\Program Files\1952328.dat

NY -> 1951828.dat -> C:\Program Files\1951828.dat

NY -> 1951234.dat -> C:\Program Files\1951234.dat

NY -> 1947828.dat -> C:\Program Files\1947828.dat

NY -> 1947015.dat -> C:\Program Files\1947015.dat

NY -> 1946484.dat -> C:\Program Files\1946484.dat

NY -> 1944937.dat -> C:\Program Files\1944937.dat

NY -> sfi.dat -> C:\WINDOWS\System32\drivers\sfi.dat

[Empty Temp Folders]

[start Explorer]

[Reboot]

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTS scan log. This time select a file age of 60 days.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

Link to post
Share on other sites

Start OTS. Copy/Paste the information in the Quotebox below into the pane where it says "Paste fix here" and then click the Run Fix button.

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. CLick the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here along with a new OTS scan log. This time select a file age of 60 days.

I will review the information when it comes back in.

Also let me know of any problems you encountered performing the steps above or any continuing problems you are still having with the computer.

As soon as I hit 'Fix' the desktop icons go away, the cursor is an hourglass in the OTS window and on the bottom of OTS it says: 'Fixing Service /driver:YY-> (cmdGuard) COMODO Internet Security Sandbox Driver [File System | System | Running] -> C:\Windows\'

It has been stuck like that for a few minutes. Is it still working?

Link to post
Share on other sites

If it still hanging, follow these steps:

  • Copy the entire contents of the Quote Box below to Notepad.
  • Name the file as fix.bat
  • Change the Save as Type to All Files
  • and Save it on the desktop
  • Once saved, double click on the fix.bat file.

SC stop cmdGuard

SC Delete cmdGuard

SC stop Inspect

SC Delete Inspect

SC stop cmdHlp

SC Delete cmdHlp

Del %0

Attempt to run the fix again.

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.