Click start/run and type services.msc into the run box and press the enter key.
When the window appears, maximise it. Double click on the following services(
if there) and select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.
[]<Look for a service that has no name.
Close the services window.
Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..
Pay particular attention to this :-
Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:
File::
C:\WINDOWS\system32\winsock32.exe
C:\WINDOWS\mrofinu173.exe
C:\WINDOWS\system32\lpertg.exe
C:\WINDOWS\system32\2C23BBC401.sys
Folder::
Registry::
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"@"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"<NO NAME>"=-
Save this as
CFScript.txt
Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.
This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with a fresh HJT log.
Regards Howard :wave: :wave:
This thread is for the use of camo12g only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.