Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.
REGEDIT4[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]"Anti-Virus"=-
@ECHO OFFsc stop COM+ Messagessc delete COM+ Messagessc stop nlcsc delete nlcexit
KillAll::Driver::COM+_MESSAGESMYWEBSEARCHSERVICECOM+ MessagesMyWebSearchServiceFile::C:\WINDOWS\SET64.tmpC:\WINDOWS\SET61.tmpC:\WINDOWS\SET70.tmpRegistry::[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]"AppInit_DLLs"=-
after the combofix restarted i got a mcafee waring about something called RemAdm-ProcLaunch!171 in folder c:\327882r2fwjfw\psexec.cfexedoes that mean anything to ya?
"C:\Program Files\Dell Support\bak\DSAgnt.exe""C:\Program Files\iTunes\bak\iTunesHelper.exe""C:\Program Files\QuickTime\bak\qttask.exe""C:\WINDOWS\SYSTEM32\bak\ctfmon.exe""C:\WINDOWS\SYSTEM32\bak\hkcmd.exe""C:\WINDOWS\SYSTEM32\bak\igfxpers.exe""C:\WINDOWS\SYSTEM32\bak\igfxtray.exe""C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe""C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe""C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe""C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe""C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe""C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe""C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe""C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe"
C:\PROGRA~1\DELLSU~1\BAKC:\PROGRA~1\ITUNES\BAKC:\PROGRA~1\MESSEN~1\BAKC:\PROGRA~1\QUICKT~1\BAKC:\WINDOWS\SYSTEM32\BAKC:\PROGRA~1\COMMON~1\WRUM\BAKC:\PROGRA~1\HP\HPCORE~1\BAKC:\PROGRA~1\INTEL\MODEME~1\BAKC:\WINDOWS\SYSTEM32\DLA\BAKC:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAKC:\PROGRA~1\COMMON~1\AOL\ACS\BAKC:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAKC:\PROGRA~1\GOOGLE\GOOGLE~2\121128~1.546\BAKC:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK
Comment:Folders to delete:C:\PROGRA~1\COMMON~1\AOL\ACS\BAK
Comment:Files to delete:C:\WINDOWS\SYSTEM32\discpci.exeC:\WINDOWS\SYSTEM32\smbt.exe
C:\WINDOWS\SYSTEM32\discpci.exe
Comment:Files to delete:C:\WINDOWS\SYSTEM32\discpci.exe