the virus most definitely is not gone
What's happening?
Please check you setting for the following:
IFEO: Image File Execution Options (IFEO) with managed debugging. IFEO works great for native + interop-debugging; this is just an issue for managed-only debugging.
IFEO: regedit.exe - 0
IFEO: taskmgr.exe - 0
There was a restore point set for this> what is it?
RP628: 12/4/10 6:30:51 PM - ??????? Dreamfall - Áåñêîíå÷íîå ïóòåøåñòâèå
Installed Neverwinter Nights same date.
Explain please> is this a pirated program?
Another World 1.1b
Another World 15th Anniversary *VERSION CDRIP*
=======================================
Custom CFScript
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad and copy/paste the text in the code below into it:
Code:
File::
c:\docume~1\barton~1.ste\locals~1\temp\oUltraf.sys
DDS:
uRunOnce: [Shockwave Updater] c:\windows\system32\adobe\shockw~1\SWHELP~2.EXE -Update -1103470 -"Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.89 Safari/532.5" -"http://web.archive.org/web/20050520235310/www.lego.com/eng/spybotics/game.asp"
Folder::
Registry::
Driver::
oUltraf
LMIRfsClientNP
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please attach to your next reply.
====================
Uninstall this Java(TM) 6 Update 2 .
There is a driver/Service running for program
Sandra Lite or SandraAgentSrv. It is a (the System ANalyser, Diagnostic and Reporting Assistant) I didn't see it in your logs. Are you currently running this program? It is from Sisoftware
=================================
Shockwave Flashplayer:
Flash player is known for leaving behind old insecure files. It is better to clean out the entire entry, uninstall, then reinstall:
- Download the Flash Player Uninstaller and save it to your desktop.
Choose the Flash Player Uninstaller for you browser: http://www.adobe.com/shockwave/download/alternates/ Don't run yet.
- Boot into Safe Mode
[o] Restart your computer and start pressing the F8 key on your keyboard.
[o] Select the Safe Mode option when the Windows Advanced Options menu appears, and then press ENTER.
- Double-click the Flash Player Uninstaller setup on the desktop and run the uninstaller program.
- Reboot your computer to complete the uninstall.
- Download latest version of Flash Player HERE and save to the desktop.
- . Double click the setup and run to install. Reboot when through.
- Once the new version is installed, follow the directions to disable the auto-updater.
[1] Navigate to the Shockwave Welcome page:http://www.adobe.com/shockwave/welcome/
Note: The context menu can be accessed from any Shockwave movie if the context menu has been enabled by the author, but this URL was provided to simplify the process.
[2] Windows: Right click the Shockwave movie.
[3] From the drop down menu choose "Properties".
[4] Uncheck the box next to "Automatic Update Service" to disable the auto update feature.
Let me know what malware symptoms you still have.