Okay, hopefully we're in. Did you do the Regedit first?
Please run this Custom CFScript:
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad and copy/paste the text in the code below into it:
Code:
File::
c:\windows\system32\drivers\lvuvc.hs
c:\windows\system32\drivers\logiflt.iad
c:\windows\system32\?å
c:\windows\system32\WININET.dll
Folder::
C:\32788R22FWJFW.4.tmp
C:\32788R22FWJFW.3.tmp
C:\32788R22FWJFW.2.tmp
C:\32788R22FWJFW.1.tmp
DDS::
TB: {C4069E3A-68F1-403E-B40E-20066696354B} - No File
TCP: NameServer = 93.188.162.74,93.188.161.7
TCP: {5A3A49FE-DBD7-4740-A224-FE86CC9B687E} = 93.188.162.74,93.188.161.7
TCP: {F64DFC4F-12A2-4986-A7FE-1F63AB3935D6} = 93.188.162.74,93.188.161.7
Registry::
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
[HKEY_CLASSES_ROOT\clsid\{ccc7a320-b3ca-4199-b1a6-9f516dd69829}]
RegLock::
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
Driver::
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste into your next reply.
=================================
Now see if you can run F-SdBot
Download F-SdBot and save to your desktop.
- Unpack the F-SdBot utility from the provided ZIP archive
- Run the unpacked F-SdBot.exe either of the following ways:
[o] Doubleclick on F-SdBot from Windows explorer.
[o] Or you can start it from a command prompt: Click on Start> Run> type in F-SdBot> Enter.
Action:
- First the F-SdBot utility will kill SdBot backdoor's processes in memory.
- Then the utility will remove Registry entries created by the backdoor.
- Finally the utility will scan all hard drives for infected files and delete them.
- Reboot the computer.
==============================
Now see if Combofix will run in Normal Mode.If it will, I'll check for remaining entries and move them.
Note: You should also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).[/b]
C:\WINDOWS\Temp
C:\Documents and Settings\Ella\Local Settings\Temp[/b]
The avz log mentions that the Telnet Service is allowed to run. It is potentially dangerous and I recommend that you disable it: TlntSvr (Telnet)