Hello stevetry,
Please do not attach logs unless requested. It's much quicker and easier for us if you copy/paste the contents of reports directly into the reply box.
Please copy this page to
Notepad and save to your desktop for reference as you will not have any browsers open while you are carrying out portions of these instructions.
It's IMPORTANT to carry out the instructions in the sequence listed below.
***************************************************
Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
---------------------------------------------------------------------
Open
notepad and copy/paste the text in the code box below into it:
Quote:
FileLook::
c:\windows\system32\xa1291171.exe
Registry::
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"= -
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11be73bc-e22b-11dc-95ee-000ae6db53d5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e49dfce-d7d4-11dc-95b9-000ae6db53d5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{3128ec99-f53f-11dc-96b7-000ae6db53d5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41029123-9c47-11dd-a863-001601784c70}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{43cae7c0-c8f4-11dc-956f-000ae6db53d5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{592bc468-3387-11dd-a66b-000ae6db53d5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{66efa8d7-c9ac-11dc-9574-000ae6db53d5}]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b026c3fb-d570-11dc-95b0-000ae6db53d5}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ceb95934-a280-11dd-a89e-000ae6db53d5}]
|
Save this as
"CFScript.txt", and as Type: All Files (*.*)
in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at
C:\ComboFix.txt.
Please post the contents of that report in your next reply along with an update on system behavior.
__________________
Member of ASAP since 2005
Member of UNITE since 2006
"It is one life whether we spend it laughing or weeping." "Take the time to laugh--it is the music of the soul."