My mcafee subscription expired, and I decided not to renew, but to go with CA Internet Security Suite. I had installation issues, so before I could fully install I was infected. It was the AntiVirus Pro 2010 virus. I managed to get CA installed and clean up most everything. I am not sure what my computer has now stems from that or something else. Two days ago, I was getting browser hijacked. I tried more cleaning, but I was locked out of regedit, locked out of system restore, and safe mode gives BSOD. I managed to research and fix the regedit issue and the system restore issue (although there are no restore points available before all of this). I still get Blue screened on the safe mode. Here are all the logs as requested by your site. Any help much appreciated!
Ben
HiJack This Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:05:43 AM, on 10/23/2009 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16915) Boot mode: Normal
DDS (Ver_09-10-13.01) - NTFSx86 Run by Ben at 5:28:24.92 on Fri 10/23/2009 Internet Explorer: 7.0.5730.11 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.3070.2205 [GMT -5:00]
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} FW: CA Personal Firewall *disabled* {14CB4B80-8E52-45EA-905E-67C1267B4160}
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-10-13.01)
Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume2 Install Date: 8/1/2006 9:42:03 PM System Uptime: 10/23/2009 5:22:05 AM (0 hours ago)
Motherboard: Dell Inc. | | 0HJ054 Processor: Intel(R) Pentium(R) D CPU 3.20GHz | Microprocessor | 3192/800mhz Processor: Intel(R) Pentium(R) D CPU 3.20GHz | Microprocessor | 3192/800mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 228 GiB total, 111.964 GiB free. D: is CDROM () E: is CDROM () G: is FIXED (NTFS) - 932 GiB total, 614.687 GiB free. H: is Removable
==== Disabled Device Manager Items =============
==== System Restore Points ===================
RP1: 10/21/2009 10:14:47 PM - System Checkpoint RP2: 10/22/2009 6:32:20 AM - Cleaned registry with Windows Live OneCare safety scanner
==== Installed Programs ======================
Adobe Acrobat - Reader 6.0.2 Update Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Reader 6.0.1 Advanced Playlist Builder 1.00 Andrea VoiceCenter AnswerWorks 5.0 English Runtime AOLIcon Apple Mobile Device Support Apple Software Update Applian FLV Player ATI Control Panel ATI Display Driver ATI Parental Control Atomic PDF Password Recovery 1.90 Bonjour BUM CA Anti-Spyware CA Anti-Virus CA Internet Security Suite CA Personal Firewall CA Pest Patrol Realtime Protection Canon Camera Access Library Canon Camera Support Core Library Canon Camera WIA Driver Canon G.726 WMP-Decoder Canon IXY 320, PowerShot S230, IXUS v3 WIA Driver Canon MovieEdit Task for ZoomBrowser EX Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon Utilities CameraWindow Canon Utilities CameraWindow DC Canon Utilities CameraWindow DC_DV 5 for ZoomBrowser EX Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX Canon Utilities EOS Utility Canon Utilities FileViewerUtility 1.0 Canon Utilities MyCamera Canon Utilities MyCamera DC Canon Utilities PhotoStitch Canon Utilities RemoteCapture 2.6 Canon Utilities RemoteCapture DC Canon Utilities RemoteCapture Task for ZoomBrowser EX Canon Utilities ZoomBrowser EX Canon ZoomBrowser EX Memory Card Utility CCleaner (remove only) CCScore CDBurnerXP Pro 3 Creative Software AutoUpdate Creative System Information Critical Update for Windows Media Player 11 (KB959772) Dell CinePlayer Dell Digital Jukebox Driver Dell Driver Reset Tool Dell Game Console Dell System Restore DellConnect DellSupport Digital Content Portal DNA Documentation & Support Launcher Dropbox DV Network Software Easy CD-DA Extractor 10 EducateU ELIcon EPSON Printer Software EPSON Scan EPSON Stylus CX6000 Scanner Driver Update ESPNMotion ESSBrwr ESSCDBK ESScore ESSgui ESSini ESSPCD ESSPDock ESSTOOLS essvatgt ExplorerXP (remove only) ffdshow [rev 1723] [2007-12-24] FileViewerUtility 1.0 Folder Size for Windows GameTap GDR 4053 for SQL Server Database Services 2005 ENU (KB970892) GDR 4053 for SQL Server Tools and Workstation Components 2005 ENU (KB970892) Google Chrome Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB896256) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB906569) Hotfix for Windows XP (KB908673) Hotfix for Windows XP (KB912024) Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915800) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB945060-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) HSH Home Buyer's Calculator Suite, 2.2.05 HyperCD Intel(R) PRO Network Connections Drivers Intel(R) PROSet for Wired Connections iTunes KODAK EASYSHARE Gallery Easy Upload, v2.1 KODAK EASYSHARE Gallery Upload ActiveX Control Kodak EasyShare software Learn2 Player (Uninstall Only) Linksys EasyLink Advisor Logitech Desktop Messenger Logitech Harmony Remote Software 7 Logitech QuickCam Logitech QuickCam Driver Package Malwarebytes' Anti-Malware MCU Microsoft .NET Compact Framework 1.0 SP3 Developer Microsoft .NET Compact Framework 2.0 Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.0 Hotfix (KB930494) Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Device Emulator version 1.0 - ENU Microsoft Document Explorer 2005 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Ultimate 2007 Microsoft Office Word MUI (English) 2007 Microsoft Office XP Professional with FrontPage Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Silverlight Microsoft Software Update for Web Folders (English) 12 Microsoft SQL Server 2005 Microsoft SQL Server 2005 Express Edition (SQLEXPRESS) Microsoft SQL Server 2005 Mobile [ENU] Developer Tools Microsoft SQL Server 2005 Tools Express Edition Microsoft SQL Server Management Studio Express Microsoft SQL Server Native Client Microsoft SQL Server Setup Support Files (English) Microsoft SQL Server VSS Writer Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual J# 2.0 Redistributable Package Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU Microsoft Visual Studio 2005 Tools for Office Runtime Move Networks Player for Internet Explorer Mozilla Firefox (3.5.3) MSDN Library for Visual Studio 2005 MSXML 4.0 SP2 (KB925672) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 6 Service Pack 2 (KB954459) Musicmatch for Windows Media Player Musicmatch® Jukebox Nation Recipes netbrdg OfotoXMI Otto PartyPokerNet PayPal Plug-In Pinnacle Hollywood FX 5 Pinnacle Instant PhotoAlbum Polar Golfer Pure Networks Platform Quicken 2009 Quicken WillMaker Plus 2007 QuickTime RealArcade RealPlayer Basic Remote Control USB Driver RemoteCapture 2.6 Roxio DLA Roxio MyDVD LE Roxio RecordNow Audio Roxio RecordNow Copy Roxio RecordNow Data Safari Seagate Manager Installer Search Assist Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB969679) Security Update for CAPICOM (KB931906) Security Update for Microsoft Office Excel 2007 (KB969682) Security Update for Microsoft Office Outlook 2007 (KB972363) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office Publisher 2007 (KB969693) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Security Update for Microsoft Office Word 2007 (KB969604) Security Update for Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU (KB925674) Security Update for Microsoft Visual Studio 2005 Team Edition for Software Developers - ENU (KB937060) Security Update for Windows Internet Explorer 7 (KB929969) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Internet Explorer 7 (KB956390) Security Update for Windows Internet Explorer 7 (KB958215) Security Update for Windows Internet Explorer 7 (KB960714) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937894) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB971032) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) SFR SHASTA SigmaTel Audio skin0001 SKINXSDK Skype™ 3.8 SmartSound Quicktracks Plugin Sonic Activation Module Sonic Advanced Decoder Sonic Encoders Sonic Update Manager Sony Image Data Suite Sony Picture Utility Sound Blaster Audigy Sound Blaster Audigy ADVANCED MB Sound Blaster Audigy ADVANCED MB Product Registration staticcr Studio 9 Studio 9.4 Patch TaskSwitchXP tooltips TVersity Codec Pack 1.2 TVersity Media Server 1.0.0.10 RC6 TVersity Media Server Pro 1.5a Beta UDPixel.exe Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Outlook 2007 Junk Email Filter (KB974810) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB925720) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB932823-v3) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB951072-v2) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB973815) Update Rollup 2 for Windows XP Media Center Edition 2005 Viewpoint Media Player VPN Client VPRINTOL WebEx Support Manager for Internet Explorer WebFldrs XP WildTangent Web Driver Windows Desktop Search 3.0 Windows Genuine Advantage Notifications (KB905474) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 10 Hotfix - KB895316 Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows Media Player Firefox Plugin Windows PowerShell(TM) 1.0 Windows Presentation Foundation Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB885884 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB889673 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890927 Windows XP Hotfix - KB891781 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 WinRAR archiver WIRELESS WordPerfect Office 12 XML Paper Specification Shared Components Pack 1.0 Yahoo! Install Manager Yahoo! Photos Easy Upload Tool Yahoo! Photos Print-at-Home Tool Yahoo! Toolbar Yahoo! Toolbar for Internet Explorer Yahoo! Widgets Yahtzee Download Edition
==== Event Viewer Messages From Past Week ========
10/21/2009 9:35:02 PM, error: SideBySide [59] - Generate Activation Context failed for C:\DOCUME~1\Ben\LOCALS~1\Temp\wscsvc32.exe. Reference error message: The operation completed successfully. . 10/21/2009 9:35:02 PM, error: SideBySide [58] - Syntax error in manifest or policy file "C:\DOCUME~1\Ben\LOCALS~1\Temp\wscsvc32.exe" on line 0. 10/21/2009 9:32:37 PM, error: Service Control Manager [7034] - The Folder Size service terminated unexpectedly. It has done this 1 time(s). 10/21/2009 8:48:28 PM, error: Service Control Manager [7023] - The Computer Browser service terminated with the following error: This operation returned because the timeout period expired. 10/21/2009 8:27:29 PM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 10/18/2009 9:41:56 PM, error: W32Time [17] - Time Provider NtpClient: An error occurred during DNS lookup of the manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup again in 15 minutes. The error was: A socket operation was attempted to an unreachable host. (0x80072751) 10/18/2009 3:52:58 AM, error: Service Control Manager [7034] - The Linksys Updater service terminated unexpectedly. It has done this 1 time(s). 10/16/2009 3:50:21 AM, error: Service Control Manager [7034] - The TVersityMediaServer service terminated unexpectedly. It has done this 1 time(s).
Double-click on the combofix icon found on your desktop.
Please note, that once you start combofix you should not click anywhere on the combofix window as it can cause the program to stall. In fact, when combofix is running, do not touch your computer at all and just take a break as it may take a while for it to complete.
When finished, it will produce a logfile located at C:\combofix.txt.
Post the contents of that log in your next reply
The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.
Thanks for your response. I was researching combofix when I came across some other things I wanted to try first. I made an ultimate bootable CD with a bunch of malware removers preloaded. I booted off of that and ran Super Anti Spyware, Avira Antivir, DrWeb CureIt, and HijackThis without my OS running. This seemed to cure 99% of the viruses, hijacks, and spyware I was seeing.
That is all good news. The only thing that didn't seem to be fixed is the safe mode blue screen. After booting to normal windows and seeing that everything was OK I tried safe mode and get the same blue screen.
I tried combofix to see if that would do anything, but it hasn't seemed to load and run correctly. I turned off all AV and Real Time protection. It starts and it backed up the registry and also installed the recovery console. It gets to the point where it says it could take 10 minutes if not double that on really infected system. I let it run for 5 hours and nothing worked. The CPU always seems to be going, but in the task manager I don't see any IO reads/writes or anything going on by any of the processes. The PEV.cfxxe is the process that was running for hours. I tried it two more times after that (I forgot to shut off AV for one and had to abort) and let the other one run for 3-4 hours and the same thing.
Should I even be trying combofix? Will that do anything for my blue screen? And how should I clean up after the partial combofix run. There are 3 directories in the root of C, that when I click on them makes it look like I clicked on my computer. I go to a command window and they just look like normal directories. One has 7MB, one has 20MB and the other 24MB. Can I delete these?
I ran the safereboot repair and all looks well. The log is below. I have one more question - how do I clean up the stuff that combofix created? There is a directory called blahblah (I renamed combofix.exe just to make sure that no AV or protection would say anything.). blahblah8674b, blahblah18460b, and qoobox. The only reason I am apprehensive is that in Windows when I click on the blahblah dirs, it is like I clicked on My Computer, like it is some kind of alias. In a DOS window it all looks like a normal directory. I have never seen that before.
Thanks again for all of your help. I would still be battling this if it wasn't for you. Or I would have reformatted and started over.
Ben
Reg export of SafeBoot key after repair: ========================
Currently it is Saturday, November 21, 2009 4:32 PM (GMT +1) There are a total of 73.034 posts in 17.116 threads. In the last 3 days there were 14 new threads and 71 reply posts. View Active Threads
Who's Online
This forum has 30334 registered members. Please welcome our newest member, sushil. 31 Guest(s), 0 Registered Member(s) are currently online. Details