Please post the "C:\ComboFix.txt" **Note 1: Do not mouseclick combofix's window while it's running. RKreport.txt could also be found on your desktop.

Wait until the Status box shows Scan Finished Click on Delete.

Go to top Share this post Link to post Share on other sites donmusicman    Member Members 251 posts March 9, 2013 OS: Windows XP Post #: 9   Posted March If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum. How is computer doing? ========================= Please download AdwCleaner by Xplode onto your desktop. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Finished : << RKreport[1]_S_12262012_02d2044.txt >> RKreport[1]_S_12262012_02d2044.txt ---------------------------------------------------------------------------------------------------------------------------------------------------------------- RogueKiller V8.4.1 [Dec 24 2012] by Tigzy mail : tigzyRKgmailcom Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/ Website : http://tigzy.geekstogo.com/roguekiller.php Blog : http://tigzyrk.blogspot.com/ Operating System : Windows 7 IF REQUESTED, ZIP IT UP & ATTACH IT . CONTRIBUTE TO OUR LEGAL DEFENSE All unused funds will be donated to the Electronic Frontier Foundation (EFF). Exploit Swf_c. Avg I'm not sure what archived files are actually.8/25/2008 8:45:11 PMVicki Hull3496Sign of "Win32:Trojan-gen {Other}" has been found in "C:\Documents and Settings\All Users\Application Data\AOL Downloads\ccu_suite\\ccu_suite_4.3.38.1\ecuinst.exe\$R1\$PLUGINSDIR\utility.dll" file. 8/25/2008 9:06:28 PMVicki Hull3496Sign of "Win32:Trojan-gen

Contents of the 'Scheduled Tasks' folder . 2015-03-04 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-19 00:44] . 2015-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-07-19 18:14] . 2015-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files NOTE: Recent updates to some versions of Windows won't allow this util to backup the registry so ignore any errors you may get and perform the registry backup manually if needed.

If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.

If yours is not listed and you don't know how to disable it, please ask.

Download into a temp folder. When finished, it will produce a report for you.

If Combofix asks you to install Recovery Console, please allow it.

IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.

c:\users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Stardock ObjectDock.lnk - c:\program files (x86)\Stardock\ObjectDockFree\ObjectDock.exe [2010-10-6 3768176] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) .

uStart Page = hxxp://google.com/ uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm Trusted Zone: aletaps.com\www TCP: DhcpNameServer = FF - ProfilePath - c:\users\robert\AppData\Roaming\Mozilla\Firefox\Profiles\uz719rj1.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ Malwarebytes Never run more than one scan at a time.

Please be patient as this can take a while to complete depending on your system's specifications. The miscreants may have installed password stealers or other Trojans to capture your keystrokes.

Attached logs won't be reviewed. Your mistakes during cleaning process may have very serious consequences, like unbootable computer. Click on Scan button. Thank you. March 31, 2009 16:46 Re: Update fails #5 Top jonath Senior Join Date: 31.3.2009 Posts: 32 Sorry for omissions - now collected here I hope.

rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/ iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/ Restart computer in safe mode Double-click on the Rkill desktop icon to run the tool.

Close any open browsers. If there is any doubt in your mind, you should contact your security vendor and ask them to confirm whether an infection really is present".

Hovering over the icon it says "Identifying" "no network access".

Very Important! Went back, a couple months ago,and it seems to be better. Help please? « Reply #21 on: August 24, 2008, 04:06:01 AM » Okay I just ran the program and followed the steps. Help please? « Reply #26 on: August 26, 2008, 06:09:56 AM » I would think that if the only entries were avast entires and there were no others then you are

You should now be able to export any file in the chest to this folder and upload it to VirusTotal without avast alerting.What is this CCU_Suite from AOHell that is causing