Spyware/virus problems, logs attached

Status
Not open for further replies.
Hey,

I have been recently having a few problems with my PC. I have installed Windows XP and CA Internet Security Suite 2007. Below is a list of problems I’ve been having:
1) Cannot run taskmanager/regedit/gpedit e.t.c.
2) Cannot view/make changes to folder options under my documents
3) Cannot run selected programs such as Spyware Doctor and CCleaner

Attached are logs of various scans from Malwarebytes’, Super Anti-spyware and HJT as per suggested in spyware removal threads. Please help! Thanks in advance.

Kind regards
 
Removal Instructions

Run HJT again and remove the following

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O4 - HKLM\..\Run: [MSszvc] C:\WINDOWS\system32\tmp.exe

Update adobe acrobat reader.

Check in with you later.
 
Hey,

I ran another HJT scan, I selected those and ‘fixed checked’. I ran another scan just to make sure, and O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 showed up again. I tried to run another scan and ‘fix checked’ a few more times, but it still appeared when I scanned. I tried running taskmanager e.t.c. and tried viewing folder options under my documents but without success. I updated Acrobat Reader as per requested.
 
Run HJT again and delete the following

C:\WINDOWS\system32\tmp.exe
O4 - HKLM\..\Run: [MSszvc] C:\WINDOWS\system32\tmp.exe
Restart system

There seem to be a program that keeps undoing changes that you've made. Maybe it is the above.

After you have restarted the system Run HJT again and remove the following.
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Restart the system. Run HJT again, and post new log.

Let me know if the other problems persists.
 
The system is not clean yet.

These HJT entries remain unaddressed:
O4 - HKLM\..\Run: [Print Process Spooler] spoolsi.exe
O22 - SharedTaskScheduler: lksdfj98w3rmsekfnaui3rgfdgf - {C5BF49A2-94F3-42BD-F434-3604812C897D} - (no file)
 
Status
Not open for further replies.
Back