Please read this description:
PLEASE NOTE ComboFix is an extremely powerful tool which should only be used when instructed to do so by someone who has been properly trained. ComboFix is intended by its creator to be "used under the guidance and supervision of an expert." It is NOT for private use. Please read Combofix's Disclaimer. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again.
The Disclaimer:
Obviously there was a problem with Combofix and what is on your system- per the bug report.
To uninstall ComboFix.exe without removing any backups of files that it deleted
Right click ComboFix.exe and select delete
Please open HijackThis, and select
Do a system scan only.
Place a checkmark next to the following entries (if present):
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\wuauclt.exe (there are 2 of these processes- they are for the Windows Autoupdate)
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O23 - Service: Windows User Mode Driver Framework (UMWdf) - Unknown owner - C:\WINDOWS\system32\wdfmgr.exe (file missing)
Then, close all other open windows, leaving only HijackThis open, and select
Fix checked.
When finished:
Boot into Safe Mode
[*] Restart your computer and start pressing the F8 key on your keyboard.
[*] Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.
Start> Run> msconfig> enter> Selective Startup> Startup tab> UNCHECK the following if present:
Winamp
UMWdf
Apply> OK
Start> Run> services.msc> OK
[*] In the list of services, right-click Windows User Mode Driver Framework, and then click Properties.
[*] Click the General tab.
[*] In the Startup type box, click Disabled or Manual, and then click OK.
[*] On the File menu, click Exit.
Right click on Start> Explore> Windows> System 32>
verify location of both of the following processes this folder:
lsass.exe
smss.exe
Reboot into Normal Mode. NOTE: a nag message will display- you can ignore it and close after checking 'don't show this message again.' Stay in Selective Startup.
Please empty the Recycle Bin.
Run a full system scan wit Eset Nod32. Attach log.
Rescan with HijackThis and attach new log.
As mentioned previously, the HJ log doesn't display a 'normal system'. There is a possibility that you will have to reformat and reinstall.
Regarding UMWdf- from Microsoft:
After you install Microsoft Windows Media Player 10, a new process appears in Windows Task Manager. This process is named the Windows User Mode Driver Framework service (Wdfmgr.exe). The Startup type setting for this process is Automatic.
You will change that startup to either Disabled or Manual per the instruction above.