Please attach the other two Combofix logs: ComboFix2.txt 2009-05-07 14:15 and ComboFix3.txt 2009-05-07 08:07
Run this script, PC will reboot, instructions:
http://forum.kaspersky.com/index.php?s=&am...st&p=678368Run this script, PC will reboot:
CODE
begin
SetAVZGuardStatus(True);
SearchRootkit(true, true);
QuarantineFile('c:\windows\system32\vcmgcd32.dll','');
QuarantineFile('c:\windows\zts2.exe','');
QuarantineFile('c:\windows\rundll16.exe','');
QuarantineFile('c:\windows\logo1_.exe','');
QuarantineFile('c:\windows\system32\systems.txt','');
QuarantineFile('c:\windows\system32\iifgfgf.dll','');
QuarantineFile('C:\¡¡¡¡¡¡.exe','');
DeleteFile('C:\¡¡¡¡¡¡.exe');
DeleteFile('c:\windows\system32\iifgfgf.dll');
DeleteFile('c:\windows\system32\systems.txt');
DeleteFile('c:\windows\logo1_.exe');
DeleteFile('c:\windows\rundll16.exe');
DeleteFile('c:\windows\zts2.exe');
DeleteFile('c:\windows\system32\vcmgcd32.dll');
BC_ImportDeletedList;
ExecuteSysClean;
BC_Activate;
RebootWindows(true);
end.
Then, run this one:
CODE
begin
CreateQurantineArchive('c:\quarantine.zip');
end.
A file called quarantine.zip should be created in C:\. Then please zip up C:\qoobox\quarantine and upload both it and C:\quarantine.zip to a filehost such as
http://rapidshare.com/ Then, Private Message me the Download link to the uploaded file. Click my user name and select Send message. Lastly, uninstall Combofix by:
pause Kaspersky > Start > run > type
combofix /u > ok. Or Start > run > type
46 /u > ok. Restart Kaspersky.
Also, if you use Windows System restore, turn it off > reboot and do a full scan with Kaspersky. Then turn system restore back on, if you wish; this to remove malware
from system volume information files. How to turn it off/on:
http://support.kaspersky.com/faq/?qid=208279208Before doing the scan, Clear the Detected list: Detected > Active threats > right click > Disinfect all > right click > Clear list > then scan again > then post
screenshot of Detected > Active threats. With columns widened to show full name and object details.
Also, scan with Malwarebytes' Anti-Malware:
http://www.malwarebytes.org/mbam.php and attach its log, but Please Don't fix anything yet, until the log is reviewed.
How to take and post screenshot: PrtSc (Print screen) key (upper right part of keyboard)> open Paint (Start > All programs > Accessories) > Edit > Paste, File > Save as (jpeg or
png, Not bmp). When replying, Browse > click once to select file > Open > Upload > add reply.