Joined
·
26,408 Posts
Open NOTEPAD and copy/paste the text in the quotebox below into it:
Save this as "CFScript"
Referring to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.
--------
In your next post, tell us what type of antivirus program you currently have installed on the machine
Code:
Folder::
c:\WINDOWS\[email protected]
File::
c:\windows\system32\A1A6BC2E.cfg
c:\windows\system32\VACFix.exe
c:\windows\system32\o4Patch.exe
c:\windows\system32\IEDFix.C.exe
c:\windows\system32\404Fix.exe
c:\windows\system32\D9C002DD.cfg
c:\windows\system32\FFAE967F.cfg
c:\windows\system32\E1D19FCC.cfg
c:\windows\system32\d435fd4.sys
c:\windows\system32\B8E83D3C.cfg
c:\windows\system32\f35ee9e.sys
c:\windows\system32\de8296f.sys
c:\windows\system32\C8FFD223.cfg
c:\windows\system32\F2CBFAC4.cfg
c:\windows\system32\E5D39975.cfg
c:\windows\system32\F8E07BB2.cfg
c:\windows\system32\windg.exe
c:\windows\system32\d435fd4.sys
c:\windows\system32\de8296f.sys
c:\windows\system32\f35ee9e.sys
driver::
d435fd4
de8296f
f35ee9e
Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\image file execution options\Client.exe]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\[email protected]\\iexplorer.exe"=-
"c:\\Documents and Settings\\demo\\My Documents\\uTorrent.exe"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
"5353:TCP"=-
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1c21fc2e-582f-11dc-bfa0-0013ce46134d}]

Referring to the picture above, drag CFScript.txt into ComboFix.exe
When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.
--------
In your next post, tell us what type of antivirus program you currently have installed on the machine