One file removed in Mbam
Another files for same malware removed in SAS
Adware from a program called PUZEGINI
Additional processes for Adware removed in CFFix> run with security on, processes returned
Malware removed in Dr. Web and OTMoveIt
Reboot allowed access to programs: if RAM is low, rebooting frees it up, but can start the cycle again. I don't know how much RAM you have, if it's enough or if all of the chips are good.
You need to sign on using the Administrator's account to make changes in msconfig.
If you make changes using the msconfig utility, the first time you reboot afterward produces a nag message which can be ignored and closed after checking 'don't show this message again. You have to stay in Selective Startup to retain the changes.
I requested that you disable the security per the instructions in Combofix and the CFScript. You did not. As far as I know the malware has been removed.
Uninstall ComboFix and all Backups of the files it deleted
- Click START> then RUN
- Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
Remove all of the tools we used and the files and folders they created
- Download OTCleanIt by OldTimer and save it to your Desktop.
- Double click OTCleanIt.exe.
- Click the CleanUp! button.
- If you are prompted to Reboot during the cleanup, select Yes.
- The tool will delete itself once it finishes.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.
You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
- Go to Start > All Programs > Accessories > System Tools
- Click "System Restore".
- Choose "Create a Restore Point" on the first screen then click "Next".
- Give the Restore Point a name> click "Create".
- Go back and follow the path to > System Tools.
[*]Click "OK" to select the partition or drive you want.
[*]Click the "More Options" Tab.
[*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.
More details and screenshots for Disk Cleanup in Windows Vista can be found here.
If the permission problem continues, please post in the Windows OS forum.
If I can be of help in the future, let me know.