If you can do anything at all, please run this:
Please run this Custom CFScript:
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad> click on Format> Uncheck 'Word Wrap'> and copy/paste the text in the code below into it:Be sure to scroll down to include ALL lines.
Code:
File::
d:\docume~1\Owner\LOCALS~1\Temp\KKSJF.exe
Folder::
DDS::
mSearch Page =
uInternet Connection Wizard,ShellNext = hxxp://bt.yahoo.com/start?.pd=l%3Danthonygodfrey11@btinternet.com%26c%3DK1gXhD2p2e7uH.80E1C6CGa x
uSearchURL,(Default) = hxxp://uk.red.clientapps.yahoo.com/customize/btyahoo/defaults/su/*http://uk.search.yahoo.com/
BHO: MediaBar: {0974ba1e-64ec-11de-b2a5-e43756d89593} - c:\progra~1\bearsh~1\mediabar\toolbar\BearshareMediabarDx.dll
mSearchAssistant = hxxp://search.babylon.com/?babsrc=SP_ss&q={searchTerms}&mntrId=24421b500000000000000016e61b4c16&tlver =1.4.19.19&affID=17160
TB: MediaBar: {0974ba1e-64ec-11de-b2a5-e43756d89593} - c:\progra~1\bearsh~1\mediabar\toolbar\BearshareMediabarDx.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
mRunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVMV0gtR0JZUzQtOU5USEQtUUE3WEQtQzJRSEgtTkZGS0o"&"inst=NzctNjg4Njg xMTE5LVZJUCsxLVNQMSsxLUZMMTArMS1YTzEwKzExLVRVRyszLUREVCsxNjE1MC1MU0QrMi1ERD EwRisxLVNUMTBGQVBQKzE"&"prod=90"&"ver=10.0.1392
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_04-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_26-windows-i586.cab
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"c:\\Program Files\\uTorrent\\uTorrent.exe"=-
Driver::
KKSJF
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste in your next reply.
====================
I suggest removing these from Scheduled TasK:
Click on Start> Run> type in cmd> enter> at the blinking C Prompt type in each of the following with 'enter after each:
Note: there is a space before each /
Code:
schtasks /end /FacebookUpdateTaskUse>>> 2 entries for this
schtasks /end /NCH Software\Doxillion\doxillion.ex
In response, SchTasks.exe stops the instance of Notepad.exe that the task started, and it displays the following success message:
SUCCESS: The Scheduled Task "xxxxxx" has been terminated successfully.
If you have a problem or want to see other options, check HERE for the specific Commands.
/schtasks.mspx?mfr=true
=================================================
red(windows?) shield with a white"x" on it and a bubble saying firewall is not on and I may be at risk.
That will be emedies.