Bobbye
Posts: 16,313 +36
Will, I'd like to check this out: this is an unsigned driver.
Please run this Custom CFScript
Save this as CFScript.txt, in the same location as ComboFix.exe
Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste into to your next reply.
====================
======================
Okay, I need you to stop downloading/installing/renaming/moving location, etc. unless I direct you to do so. You appear to be comfortable on the system- that's a good thing, but everything you do can affect what I see or what I think you should do.
Regarding the Recovery Console: I'm not sure why you decided to 'see if it worked'. This would be when you boot from the CD- correct? So you would havve had to change the BIOS to boot from the CD first instead of the hard drive? Let's get you back online, then run Combofix again and install the RC from there.
======================
Without checking into anything else, please just give me an update on what is or is not happening. I'll start you off:
1. Can't get online>>> what happens when you try? Message? What?
2. Malware>> are you experiencing problems that appear to be directly related to the malware itself>
3. To distinguish from #2:>> without trying to do any special feature or function, do you have issues that you "think" may be related to the system settings?
Please run this Custom CFScript
[1]. Close any open browsers.
[2]. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
[3]. Open notepad> click on Format> Uncheck 'Word Wrap> and copy/paste the text in the code below into it:
Code:
FileLook::
c:\windows\system32\drivers\tcpip.sys
CTHELPER.EXE

Referring to the picture above, drag CFScript into ComboFix.exe
When finished, it will produce a log for you at C:\ComboFix.txt . Please paste into to your next reply.
====================
Make sure the external drive is connected and run the disinfector again, just to be sure.Flash Disinfector did install the folder autorun on flash drive, but not the external hdd. (There is an autorun.inf file there already).
======================
Okay, I need you to stop downloading/installing/renaming/moving location, etc. unless I direct you to do so. You appear to be comfortable on the system- that's a good thing, but everything you do can affect what I see or what I think you should do.
Regarding the Recovery Console: I'm not sure why you decided to 'see if it worked'. This would be when you boot from the CD- correct? So you would havve had to change the BIOS to boot from the CD first instead of the hard drive? Let's get you back online, then run Combofix again and install the RC from there.
======================
Without checking into anything else, please just give me an update on what is or is not happening. I'll start you off:
1. Can't get online>>> what happens when you try? Message? What?
2. Malware>> are you experiencing problems that appear to be directly related to the malware itself>
3. To distinguish from #2:>> without trying to do any special feature or function, do you have issues that you "think" may be related to the system settings?