I understand that you're busy. Please understand that I also have a life. You are leaving log here, one after the other and multiple of the same logs: You have used multiple cleaning programs with no supervision.
=====================
First Mbam after you reran and removed:
5/22/2010 5:21:24 PM
mbam-log-2010-05-22 (17-21-24).txt
Files Infected:
C:\Windows\System32\drivers\yaljeou.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
The following same log was left 3 different times:
5/23/2010 1:22:23 PM
mbam-log-2010-05-23 (13-22-23).txt
C:\Windows\System32\drivers\yaljeou.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
5/23/2010 1:22:23 PM
mbam-log-2010-05-23 (13-22-23).txt
Files Infected:
C:\Windows\System32\drivers\yaljeou.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
5/23/2010 1:22:23 PM
mbam-log-2010-05-23 (13-22-23).txt
Files Infected:
C:\Windows\System32\drivers\yaljeou.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
There are multiple Combofi logs> only 2 were run with the script:
Combofix:
ComboFix 10-05-22.01 - Lyndz 05/22/2010 17:27:11.4.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3070.2445 [GMT -7:00]
Running from: c:\users\Lyndz\Desktop\ComboFix.exe
--- Other Services/Drivers In Memory ---*Deregistered* - yaljeou
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\yaljeou]
ComboFix 10-05-22.01 - Lyndz 05/22/2010 18:04:25.5.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3070.2306 [GMT -7:00]
Running from: c:\users\Lyndz\Desktop\ComboFix.exe
--- Other Services/Drivers In Memory ---*Deregistered* - yaljeou
ComboFix 10-05-22.03 - Lyndz 05/23/2010 11:26:22.6.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3070.2367 [GMT -7:00]
Running from: c:\users\Lyndz\Desktop\ComboFix.exe
Command switches used :: c:\users\Lyndz\Desktop\CFScript.txt
--- Other Services/Drivers In Memory ---*Deregistered* - yaljeou
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\yaljeou]
ComboFix 10-05-24.07 - Lyndz 05/25/2010 13:47:00.7.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1252.1.1033.18.3070.2420 [GMT -7:00]
Running from: c:\users\Lyndz\Desktop\ComboFix.exe
Command switches used :: c:\users\Lyndz\Desktop\CFScript.txt
--- Other Services/Drivers In Memory ---*Deregistered* - yaljeou
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\yaljeou]
You were instructed
not to check for removal in the Eset scan then you cheked for removal in each.
I don't think you have Rootkit.
Please
Removing all of the tools we used and the files and folders they created
- Uninstall ComboFix and all Backups of the files it deleted
- Click START> then RUN
- Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
- Download OTCleanIt by OldTimer and save it to your Desktop.
- Double click OTCleanIt.exe.
- Click the CleanUp! button.
- If you are prompted to Reboot during the cleanup, select Yes.
- The tool will delete itself once it finishes.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.
- You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
- Go to Start > All Programs > Accessories > System Tools
- Click "System Restore".
- Choose "Create a Restore Point" on the first screen then click "Next".
- Give the Restore Point a name> click "Create".
- Go back and follow the path to > System Tools.
[*]Choose Disc Cleanup
[*]Click "OK" to select the partition or drive you want.
[*]Click the "More Options" Tab.
[*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.
Empty the Recycle Bin
Then run TFC (Temp File Cleaner)
Download TFC to your desktop
- Open the file and close any other windows.
- It will close all programs itself when run, make sure to let it run uninterrupted.
- Click the Start button to begin the process. The program should not take long to finish its job
- Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean
TFC only cleans temp folders. TFC will not clean URL history, prefetch, or cookies. TFC requires a reboot immediately after running. Be sure to save any unsaved work before running TFC.
TFC (Temp File Cleaner) will clear out all temp folders for all user accounts (temp, IE temp, java, FF, Opera, Chrome, Safari), including Administrator, All Users, LocalService, NetworkService, and any other accounts in the user folder.
Empty the Recycle Bin
This will end my support. This thread is closed.