And I stand to face some blame, or how you say.
I have for years used a selective start to speed things up, preventing seldom-used applications to auto-start. Having gone back to a complete start-up I now have Internet access and perhaps some more.
Enclosed the latest Farbar log (FSS[4]) (the numeration is mine).
Immediately on startup I now get the error message as in dump_120122_1.png. Which I just close down.
Some icons are still missing from the desktop.
From the start-meny (where also things are missing), choosing all programs, I mainly get an “empty” on cursor-over in the list.
(It’s not my language, I only use it - as Victor Borge said.)
Hope you have some more good ideas as we now have come on-line.
This next one will produce the necessary shortcut links which you can cut and paste into the start menu folder
Download the repair.vbs file to your destop
Run the repair.vbs
It will ask for a folder name call it recovery
The tool will let you know when it is finished
On the desktop will be a recovery folder
Open the folder
Cut and Paste the links that you want to C:\documents and settings[i]your name[/i]\start menu
Haven’t run any cleaners, about back up I don’t know…
Enclose OTL (quick scan, no customs)
I can’t of course read such things, but still a little surprised of the lack of folders/files created on Jan 18, if you would compare with my two search-dumps earlier. The folder Administrator with sub folders and files were created in connection with the mayhem. Have seven more PNG:s with things created on that date.
The additional ones that you have found are probably the ones modified to set the hidden flag - which Roguekiller subsequently removed
Did you use IE or Firefox to download the reset programmes ?
Lets clear that popup now
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
If you have Malwarebytes 1.6 or better installed please disable it for the duration of this run
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL
O4 - HKLM..\Run: [UIWWFDnoJEOaR.exe] C:\Documents and Settings\All Users\Application Data\UIWWFDnoJEOaR.exe File not found
:Files
ipconfig /flushdns /c
:Commands
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
You are the authoroty here, absolutely no question about that, and I may have done things I shouldn’t.
Still, just to clarify. I ran that search yesterday, searching for folders and files in C that were created on Jan 18, so it seem to me they are pretty much present. To persist, I enclose two more screens from the search and would be very grateful for another comment.
About the programmes, I used IE on my new computer and then moved them over in a stick. As Normal mode gave no or very little functionality, I used the Secure mode, logging in as Adminitrator, the user created by the Evil One. As I had no Net-connection the programme which wanted to look for an update didn’t get one.
Also yesterday Avast got hold of a Trojan and I thought it was a new attack, but apparently it was the bad guy which one of your programmes had quarantined last week.
I think I’ll sit still for a bit till you’ve had a chance to read this.
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
Are the folders still empty ? Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now
/quote]
Oh,
Ran Combo Fix, told me “will take about 10 min, or longer if badly infected”
Then froze, time stopped, I waited for ten minutes.