CCG.EXE and warning message stuck in infinite loop

ok, I understand.
I am uploading it, and after 1 download (which I assume will be by essexboy) I get it down

Got it

ok, I am waiting for your verdict! ;D
I think that after yesterday’s scans, the system is clean, but let’s hear and a second opinion :slight_smile:

Run OTL

[*]Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL [2010/10/07 03:30:10 | 000,054,016 | ---- | M] () -- C:\Windows\System32\drivers\cpmafv.sys

:Files
ipconfig /flushdns /c

:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]

[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

[*]Double click on ComboFix.exe & follow the prompts.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

oook…, but first tell me why I need to do these?
you found something?

C:\Windows\System32\drivers\cpmafv.sys

This is an unknown file in your system drivers and is less than 24 hours old

ok, I’ll do the scans, don’t leave me :slight_smile:

EDIT: can you explain me in a nutshell what these commands will do? Will I lose personal data?
I am waiting for a reply before I execute the commands :slight_smile:

ipconfig /flushdns /c flushes the dns settings and resets

[purity]Clears any purity infections it may find

[resethosts]Resets hosts to default

[emptytemp]Empties all system temp files

[EMPTYFLASH]Empties flash cookies

[CREATERESTOREPOINT]Create a new restore point

[Reboot]Reboot the computer

ok, done.
Before ComboFix rebooted the pc, I got a message that a registry thing , something about Hard Drive and the name BCD (or something like that) was not found and it asked me to restore it.

Also, sorry, but I forgot to do an OTL quick scan after it had restarted the pc, so I did it after ComboFix had finished doing its thing.

I attach the 3 logs (OTL’s after executing the commands, ComboFixe’s after finishing, and OTL’s quick scan log, done after C.F. )

Once you get them tell me, to take them down.
and thanks for helping!

P.S all startup processes (e.g the mousepad driver, or avast and zonealarm (these 2 I manually restarted them)) are killed right now, after C.F. finished. they will be ok after a reboot, right?

P.S.2 OTL has created some folders under the C directory, that contain some files. what should I do with these?

OK they look good - all gone. Any problems outstanding ?

All tools I have used will be removed once you are happy

everything seems fine. just the start up programs that are killed right now (check my previous post). they will be ok after I do a restart, right?

I want to uninstall ComboFix and OTL, but they have not been ‘installed’ . Do I just delete them?

Also what about the new folders they created in the C\ directory? what do I do with these?
and thanks again!

If you could reboot your computer and let me know if all is OK - I will then command the tools to remove themselves and tidy up behind

I have rebooted at least 2 times since yesterday, everything is working like a clock again :smiley:
I’ll be waiting for instructions on how to remove said tools (OTL and ComboFix, that is)and the folders they created.

I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Click Start > Run and copy/paste the following bolded text into the Run box and click OK:

ComboFix /Uninstall

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep

We will now confirm that your hidden files are set to that, as some of the tools I use will change that

[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[
]Click OK.

SPRING CLEAN

Download and run Puran Disc Defragmenter

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
[*]SpywareBlaster to help prevent spyware from installing in the first place.

http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Run weekly to keep your system clean

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To keep your operating system up to date visit
[*]Microsoft Windows Update

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe :wave:

Nice, thank you very much Essexboy!

One last thing though. in the C:\ directory, there are still 3 files left ,that were created by OTL and combofix.
These are the files and their sub directories:

~C:\Config.Msi , which has some .rbf items in it
~C:\Device\HardDiskVolume1\Boot, which has an item named BCD in it
~C:\Recovery which is empty.

What do I do with these, is it ok if I delete them ?
I know that just letting them be wouldn’t do any harm, but since they were not there before running the scan tools, I’d like to give them the boot if it’s ok ;D

I’m waiting for a reply!

Cheers mate!

Essexboy working his magic again! This lad does a sterling job!

Keep it up!!!

Config and recovery can go but it might be advisable to keep BCD

is it too much if I ask you to explain me what purpose each of these 3 folders serves / why they were created?

Config msi just keeps the temporary files for msi style installers while installing

Recovery is a just in case folder ;D

BCD enables you to manipulate your MBR - this is needed by Combofix in case it needed to work there