Hi there whilst Oldman is busy elsewhere I will give you a hand :wink: By the way you have the latest rogue antispy

  1. Please open Notepad
    [*] Click Start , then Run[*]Type notepad .exe in the Run Box.

  2. Now copy/paste the entire content of the codebox below into the Notepad window:


File::
C:\WINDOWS\system32\CSpool\lass.exe
C:\WINDOWS\system32\filsnat.bmp
C:\WINDOWS\system32\iporqtsr.bmp
C:\WINDOWS\system32\bahsnadkrqh.bmp
C:\WINDOWS\system32\tcnadojqpcnmd.bmp
C:\WINDOWS\system32\nalcb.bmp
C:\WINDOWS\system32\jmdonelkfml.bmp
C:\WINDOWS\system32\dsbilsjap.bmp
C:\WINDOWS\system32\pkfadkfqpsf.bmp
C:\WINDOWS\system32\mdsfqlsj.bmp
C:\WINDOWS\system32\cfqdkfitcn.bmp
C:\WINDOWS\system32\etonmpsrapobmt.bmp
C:\WINDOWS\system32\cbipgbel.bmp
C:\WINDOWS\system32\qlkfap.bmp
C:\WINDOWS\system32\dcnmh.bmp
C:\WINDOWS\system32\nidgfatknql.bmp
C:\WINDOWS\system32\nmpcredcned.bmp
C:\WINDOWS\system32\ojalgjmpcn.bmp
C:\WINDOWS\system32\tcbatkn.bmp
C:\WINDOWS\system32\elkfmdknal.bmp
C:\WINDOWS\system32\qhgjmdgfatkr.bmp
C:\WINDOWS\system32\nilcrmhsfedon.bmp
C:\WINDOWS\system32\ipcbqtgbapknmd.bmp
C:\WINDOWS\system32\mdgnmlsjmhgjqt.bmp
C:\WINDOWS\system32\horilsfqhonid.bmp
C:\WINDOWS\system32\pkjqpsnmp.bmp
C:\WINDOWS\system32\kbelonel.bmp
C:\WINDOWS\system32\gbehknat.bmp
C:\WINDOWS\system32\fetgfihon.bmp
C:\WINDOWS\system32\lkralsf.bmp
C:\WINDOWS\system32\hgnelgridkfid.bmp
C:\WINDOWS\system32\dgrelcb.bmp
C:\WINDOWS\system32\balgfqd.bmp
C:\WINDOWS\system32\cjadofmt.bmp
C:\WINDOWS\system32\rqhof.bmp
C:\WINDOWS\system32\tobqdgbed.bmp
C:\WINDOWS\system32\sfqpgbah.bmp
C:\WINDOWS\system32\filsfilofqdsb.bmp
C:\WINDOWS\system32\tonmpcfmpkn.bmp
C:\Documents and Settings\doben\Application Data\Anti-Virus-Pro.com
C:\WINDOWS\system32\snmpkbidobeh.bmp
C:\WINDOWS\system32\yv12vfw.dll
C:\WINDOWS\system32\x.264.exe

Folder::
C:\Program Files\AntiVirusPro

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41596d7a-2d43-11db-a551-000d87356e88}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a13cc520-ac39-11dc-9015-000d87356e88}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e27abc60-337b-11db-a560-000d87356e88}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ecb80a3b-9611-11db-a6e0-000d87356e88}]

  1. Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES

  2. Save the above as CFScript.txt

  3. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif

  1. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
    [*]Combofix.txt [*]A new HijackThis log.