OK here we go. I will need this next log as well to be sure it got everything.
RegSweep and RegCure are rouge security programs and we will get them with this fix.
Delete these files/folders, as follows:
1. Go to
Start >
Run > type
Notepad.exe and click
OK to open Notepad.
It
must be Notepad, not Wordpad.
2. Copy the text in the below code box by highlighting all the text and pressing
Ctrl+CKillAll::
FCopy::
c:\windows\ServicePackFiles\i386\userinit.exe | c:\windows\SYSTEM32\userinit.exe
c:\windows\ServicePackFiles\i386\userinit.exe | c:\windows\SYSTEM32\DLLCACHE\userinit.exe
Folder::
c:\program files\RegSweep
c:\documents and settings\Bob\Application Data\RegSweep
c:\program files\RegCure
File::
c:\windows\ikoqurihikicil.dll
c:\windows\Tasks\RegCure Program Check.job
c:\program files\RegCure\RegCure.exe
c:\windows\Tasks\RegCure.job
c:\windows\Tasks\RegSweep Scheduled Scan.job
c:\program files\RegSweep\RegSweep.exe
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RegSweep"=-
"Vwagux"=-
3. Go to the Notepad window and click
Edit >
Paste4. Then click
File >
Save5. Name the file
CFScript.txt - Save the file to your Desktop
6. Then drag the
CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below.
Important: Perform this instruction carefully!
ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.Note:
Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze