Hi there whilst Oldman is busy elsewhere I will give you a hand
By the way you have the latest rogue antispy
-
Please open Notepad
[*] Click Start , then Run[*]Type notepad .exe in the Run Box.
-
Now copy/paste the entire content of the codebox below into the Notepad window:
File::
C:\WINDOWS\system32\CSpool\lass.exe
C:\WINDOWS\system32\filsnat.bmp
C:\WINDOWS\system32\iporqtsr.bmp
C:\WINDOWS\system32\bahsnadkrqh.bmp
C:\WINDOWS\system32\tcnadojqpcnmd.bmp
C:\WINDOWS\system32\nalcb.bmp
C:\WINDOWS\system32\jmdonelkfml.bmp
C:\WINDOWS\system32\dsbilsjap.bmp
C:\WINDOWS\system32\pkfadkfqpsf.bmp
C:\WINDOWS\system32\mdsfqlsj.bmp
C:\WINDOWS\system32\cfqdkfitcn.bmp
C:\WINDOWS\system32\etonmpsrapobmt.bmp
C:\WINDOWS\system32\cbipgbel.bmp
C:\WINDOWS\system32\qlkfap.bmp
C:\WINDOWS\system32\dcnmh.bmp
C:\WINDOWS\system32\nidgfatknql.bmp
C:\WINDOWS\system32\nmpcredcned.bmp
C:\WINDOWS\system32\ojalgjmpcn.bmp
C:\WINDOWS\system32\tcbatkn.bmp
C:\WINDOWS\system32\elkfmdknal.bmp
C:\WINDOWS\system32\qhgjmdgfatkr.bmp
C:\WINDOWS\system32\nilcrmhsfedon.bmp
C:\WINDOWS\system32\ipcbqtgbapknmd.bmp
C:\WINDOWS\system32\mdgnmlsjmhgjqt.bmp
C:\WINDOWS\system32\horilsfqhonid.bmp
C:\WINDOWS\system32\pkjqpsnmp.bmp
C:\WINDOWS\system32\kbelonel.bmp
C:\WINDOWS\system32\gbehknat.bmp
C:\WINDOWS\system32\fetgfihon.bmp
C:\WINDOWS\system32\lkralsf.bmp
C:\WINDOWS\system32\hgnelgridkfid.bmp
C:\WINDOWS\system32\dgrelcb.bmp
C:\WINDOWS\system32\balgfqd.bmp
C:\WINDOWS\system32\cjadofmt.bmp
C:\WINDOWS\system32\rqhof.bmp
C:\WINDOWS\system32\tobqdgbed.bmp
C:\WINDOWS\system32\sfqpgbah.bmp
C:\WINDOWS\system32\filsfilofqdsb.bmp
C:\WINDOWS\system32\tonmpcfmpkn.bmp
C:\Documents and Settings\doben\Application Data\Anti-Virus-Pro.com
C:\WINDOWS\system32\snmpkbidobeh.bmp
C:\WINDOWS\system32\yv12vfw.dll
C:\WINDOWS\system32\x.264.exe
Folder::
C:\Program Files\AntiVirusPro
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{41596d7a-2d43-11db-a551-000d87356e88}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a13cc520-ac39-11dc-9015-000d87356e88}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e27abc60-337b-11db-a560-000d87356e88}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ecb80a3b-9611-11db-a6e0-000d87356e88}]
-
Then in the text file go to FILE > SAVE AS and in the dropdown box select SAVE AS TYPE to ALL FILES
-
Save the above as CFScript.txt
-
Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.
http://users.pandora.be/bluepatchy/miekiemoes/images/CFScript.gif
- After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
[*]Combofix.txt [*]A new HijackThis log.