Yes, that location is fine, exactly what I was looking for.
Win32k.sys might be 0 bytes because its information is hidden. Now, we need to replace the 0byte win32k.sys (bad one) with the good one (the one with he long directory)
1. Open Command Prompt -
http://www.petri.co.il/vista_command_prompt.htm2. Copy the following line
CODE
copy C:\Windows\winsxs\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6001.18211_none_b8e9ade49a8df956\win32k.sys C:\ /y
3. In the black window which opens up, right-click in it and click Paste.
4. Click Return on your keyboard.
ONLY IF IT SAYS "1 FILE(S) COPIED", then continue reading on.
IF IT DOESN'T, don't do anything else. Just post back saying it doesn't work. Also, close the command prompt window, regardless of whether it works or not.
5. Disable your antivirus program and save and exit all non-essential programs.
6. Download
The Avenger to your desktop. Extract it.
7. Run Avenger.exe and click OK in the first prompt. Make sure "scan for rootkits" is
ticked and "automatically disable rootkits" is
unticked.
8. Copy the script bellow (all 5 lines)
CODE
Files to move:
C:\Windows\win32k.sys | C:\win32k.sys.old
C:\win32k.sys | C:\Windows\win32k.sys
9. Click Edit - Paste in The Avenger. Doublecheck both lines of the script are in the box.
10. Click "Execute" and then click all the "Yes"'s
Your PC will then restart.
Attach the log C:\avenger.txt to your next post.
Download and run Combofix again using the instructions shown
here. Remember, download combofix again, don't use the old one.
Attach the new combofix log to your next post.
Installing Kaspersky again:
Download Kaspersky but DO NOT install it yet.
Download
KAVremover10.zip. Extract it to your c:\ directory, so it is c:\kavremover10.exe
Open Command Prompt and type in:
CODE
cd c:\
kavremover10 kis2009
Enter the removal code in the KAV Remover Window and click Remove.
Restart your computer.
Uninstall AVG, SuperAntiSpyware and MBAM - (you can install SAS or MBAM again
after installing Kaspersky if you wish).
Restart your computer.
Install Kaspersky, update Kaspersky and restart the computer.
Does it work?