For Technical Support, double-click the e-mail address located at the bottom of each menu. C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFDE91.tmp scheduled to be deleted on reboot.File delete failed. If you have problems, let me know. 0 Discussion Starter reyjr80 7 Years Ago Sorry for the double post. Please save that log to post in your next reply along with a fresh HJT log Re-enable all the programs that were disabled during the running of ComboFix..

Click Close to exit the program. NOTE: If you would like to keep your saved passwords, please click No at the prompt. Recently when I boot up my computer I get a bunch of XXXX.exe bad image error windows. … IEXPLORE.EXE - a process that stops the games for a few seconds...

have a HJT log, and some symptoms. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Please be patient while it scans your computer. Keep this thread open, and if the problem persists I'll post new logs here, hopefully later today.

HJT Log: IEXPLORE.EXE Started by Patient , Nov 18 2008 03:05 PM HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\diagnostic manager (Trojan.Downloader) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully. I was simply reinstalling windows over the same formatted partition, thus, allowing corrupt files to carry over. Post that log and a HiJackthis log in your next reply Note: Do not mouseclick combofix's window while its running. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\mvapy574.default\XUL.mfl scheduled to be deleted on reboot.FireFox cache emptied.Temp folders emptied.

Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\services (Trojan.Agent) -> Delete on reboot. If there are several logs, click the current dated log and press View log. Here's my Malwarebytes' Antimalware log after removal: Malwarebytes' Anti-Malware 1.36 Database version: 2060 Windows 5.1.2600 Service Pack 1 5/5/2009 10:42:52 PM mbam-log-2009-05-05 (22-42-52).txt Scan type: Full Scan (C:\|) Objects scanned: 99058

Powershell keeps crashing & I have to reset IE options to allow file download after every reboot. Double-click on Killbox.exe to run it.

That may cause it to stall cybertech, May 6, 2007 #2 awake.02 Thread Starter Joined: May 6, 2007 Messages: 4 "Administrator" - 07-05-06 12:31:32 Service Pack 2 ComboFix 07-04-25.4V -

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\services\del (Malware.Trace) -> Quarantined and deleted successfully. how can I tell? 4 replies On a friend's computer, HJT scan turned up windows\system32\ctfmon.exe McAfee scan shows no viruses. A case like this could easily cost hundreds of thousands of dollars. awake.02, May 6, 2007 #1 cybertech Moderator Joined: Apr 16, 2002 Messages: 72,012 You have no anti-virus software running.

In the "Full Path of File to Delete" box, copy and paste the following: C:\WINDOWS\system32\wjwdfpel.dll Click on the button that has the red circle with the X in the middle after OTMoveIt3 by OldTimer - Version log created on 11202008_193451Files moved on Reboot...File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_MOPJ6HbIR7E4z6aZTAXW not found!File C:\DOCUME~1\Owner\LOCALS~1\Temp\Perflib_Perfdata_5b4.dat not found!File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DF2C49.tmp not found!File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFC433.tmp not found!File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFDE91.tmp not found!File C:\DOCUME~1\Owner\LOCALS~1\Temp\~DFDF08.tmp not found!File Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully. Note: It is possible that Killbox will tell you that the file does not exist.

Here is my HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 1:55:28 PM, on 5/1/2009 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot We can try to plough ahead, but it may be to no avail? == Can you please do the following. =============== Next, Open a command prompt by: 1. On the left, make sure you check C:\Fixed Drive. File "C:\Documents and Settings\Matt\reader_s.exe" deleted successfully.

Yes, my password is: Forgot your password?

C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> Quarantined and deleted successfully. The scanner will check the file with various AV companies.Copy and paste the results box into a reply to this thread.If Jotti's too busy, try here:Go here: http://www.virustotal.com/en/virustotalf.html=================Please download Malwarebytes Anti-Malware I was choosing the same partition without deleting the partition first, and then reformatting it to NTFS. Please re-enable javascript to access full functionality.