This is a great tool; just cleaned a PC with it :)
Main Topics
Browse All TopicsI have user who's computer been getting two errors in their system log in sequence, it recently was affected by the antivirus xp 2008 virus, I was able to get rid of it by running malwarebyte's anti-malware utility, but I'm suspecting that this computer is still infected. Any Ideas?
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7028
Date: 8/28/2008
Time: 12:20:38 PM
User: N/A
Computer: 7ND5441
Description:
The Abiosdsk Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7028
Date: 8/28/2008
Time: 12:20:38 PM
User: N/A
Computer: 7ND5441
Description:
The rzjrtxht Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Can we look at the MalwareBytes log?
You could also try SDFix or Combofix. Also show us the logfiles.
How to use SDFix.
http://www.bleepingcompute
OR, Combofix
download ComboFix by sUBs:
http://download.bleepingco
You must download it to and run it from your Desktop
Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix.
Double click combofix.exe & follow the prompts.
When finished, it will produce a log. Please save that log and attach it in your next reply.
Re-enable all the programs that were disabled during the running of ComboFix..
Note:
Do not mouse-click combofix's window while it is running. That may cause it to stall.
CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Here's Malware's Log
Malwarebytes' Anti-Malware 1.24
Database version: 1052
Windows 5.1.2600 Service Pack 2
10:32:20 AM 8/14/2008
mbam-log-8-14-2008 (10-32-20).txt
Scan type: Quick Scan
Objects scanned: 46095
Time elapsed: 6 minute(s), 52 second(s)
Memory Processes Infected: 3
Memory Modules Infected: 9
Registry Keys Infected: 146
Registry Values Infected: 14
Registry Data Items Infected: 2
Folders Infected: 37
Files Infected: 120
Memory Processes Infected:
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\rhcr8lj0er69\rhcr8lj
C:\WINDOWS\system32\pphcv8
Memory Modules Infected:
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\rhcr8lj0er69\MFC71.d
C:\Program Files\rhcr8lj0er69\MFC71EN
C:\Program Files\rhcr8lj0er69\msvcp71
C:\Program Files\rhcr8lj0er69\msvcr71
C:\WINDOWS\system32\blphcv
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Typelib\
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{0
HKEY_CLASSES_ROOT\CLSID\{0
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{0
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{0
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{0
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{5
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{0
HKEY_CLASSES_ROOT\CLSID\{b
HKEY_CLASSES_ROOT\CLSID\{c
HKEY_CLASSES_ROOT\CLSID\{c
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\CLSID\{1
HKEY_CLASSES_ROOT\CLSID\{1
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{2
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{3
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{9
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{3
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{6
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{8
HKEY_CLASSES_ROOT\CLSID\{a
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\CLSID\{7
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{7
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\CLSID\{7
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\CLSID\{8
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\CLSID\{9
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{9
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\CLSID\{9
HKEY_CLASSES_ROOT\screensa
HKEY_CLASSES_ROOT\screensa
HKEY_CLASSES_ROOT\CLSID\{a
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\CLSID\{a
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\funwebpr
HKEY_CLASSES_ROOT\CLSID\{d
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\TypeLib\
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\CLSID\{e
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CLASSES_ROOT\mywebsea
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Interfac
HKEY_CLASSES_ROOT\Typelib\
HKEY_CURRENT_USER\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SYSTEM\
HKEY_LOCAL_MACHINE\SYSTEM\
HKEY_LOCAL_MACHINE\SYSTEM\
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CURRENT_USER\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CURRENT_USER\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CURRENT_USER\SOFTWARE
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CURRENT_USER\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CURRENT_USER\SOFTWARE
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_LOCAL_MACHINE\SOFTWAR
HKEY_CURRENT_USER\Control Panel\Desktop\originalwall
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwal
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE
HKEY_CURRENT_USER\SOFTWARE
Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Delete on reboot.
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\Avat
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Game
C:\Program Files\MyWebSearch\bar\Hist
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\Mess
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\SrchAstt
C:\Program Files\MyWebSearch\SrchAstt
C:\Program Files\MyWebSearch\SrchAstt
C:\Program Files\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Scree
C:\Program Files\FunWebProducts\Scree
C:\Program Files\FunWebProducts\Share
C:\Program Files\FunWebProducts\Share
C:\Program Files\rhcr8lj0er69 (Rogue.Multiple) -> Quarantined and deleted successfully.
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\hthompson\Applica
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008 (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
Files Infected:
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\SrchAstt
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\WINDOWS\system32\f3PSSa
C:\Program Files\Internet Explorer\msimg32.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\1.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\2.bi
C:\Program Files\MyWebSearch\bar\Avat
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Cach
C:\Program Files\MyWebSearch\bar\Game
C:\Program Files\MyWebSearch\bar\Game
C:\Program Files\MyWebSearch\bar\Game
C:\Program Files\MyWebSearch\bar\Hist
C:\Program Files\MyWebSearch\bar\Hist
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\icon
C:\Program Files\MyWebSearch\bar\Mess
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Noti
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\bar\Sett
C:\Program Files\MyWebSearch\SrchAstt
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Insta
C:\Program Files\FunWebProducts\Scree
C:\Program Files\FunWebProducts\Share
C:\Program Files\FunWebProducts\Share
C:\Program Files\FunWebProducts\Share
C:\Program Files\FunWebProducts\Share
C:\Program Files\FunWebProducts\Share
C:\Program Files\FunWebProducts\Share
C:\Program Files\rhcr8lj0er69\databas
C:\Program Files\rhcr8lj0er69\license
C:\Program Files\rhcr8lj0er69\MFC71.d
C:\Program Files\rhcr8lj0er69\MFC71EN
C:\Program Files\rhcr8lj0er69\msvcp71
C:\Program Files\rhcr8lj0er69\msvcr71
C:\Program Files\rhcr8lj0er69\rhcr8lj
C:\Program Files\rhcr8lj0er69\rhcr8lj
C:\Program Files\rhcr8lj0er69\Uninsta
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\How to Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\License Agreement.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Register Antivirus XP 2008.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008\Uninstall.lnk (Rogue.AntivirusXP2008) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\blphcv
C:\WINDOWS\system32\lphcv8
C:\WINDOWS\system32\pphcv8
C:\Documents and Settings\All Users\Start Menu\Programs\Antivirus XP 2008.lnk (Rogue.AntivirusXP) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Desktop\Antivirus XP 2008.lnk (Rogue.Antivirus) -> Quarantined and deleted successfully.
C:\Documents and Settings\hthompson\Applica
I went ahead and ran the combofix utility, but I still seem to be getting errors, I tried running windows updates and it installed all of them exept an update for .net,
Event Type: Error
Event Source: Windows Update Agent
Event Category: Installation
Event ID: 20
Date: 9/2/2008
Time: 4:00:18 PM
User: N/A
Computer: 7ND5441
Description:
Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework, Version 1.1 Service Pack 1 (KB928366).
For more information, see Help and Support Center at http://go.microsoft.com/fw
Data:
0000: 57 69 6e 33 32 48 52 65 Win32HRe
0008: 73 75 6c 74 3d 30 78 38 sult=0x8
0010: 30 30 37 30 36 34 33 20 0070643
0018: 55 70 64 61 74 65 49 44 UpdateID
0020: 3d 7b 31 38 32 35 30 45 ={18250E
0028: 37 43 2d 42 33 36 45 2d 7C-B36E-
0030: 34 31 36 32 2d 38 33 38 4162-838
0038: 44 2d 31 43 34 42 34 30 D-1C4B40
0040: 38 44 38 42 37 33 7d 20 8D8B73}
0048: 52 65 76 69 73 69 6f 6e Revision
0050: 4e 75 6d 62 65 72 3d 31 Number=1
0058: 30 32 20 00 02 .
followed by that same registry denied error I was getting previously
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7028
Date: 9/2/2008
Time: 4:00:34 PM
User: N/A
Computer: 7ND5441
Description:
The rzjrtxht Registry key denied access to SYSTEM account programs so the Service Control Manager took ownership of the Registry key.
For more information, see Help and Support Center at http://go.microsoft.com/fw
eegrep:
Initially I tried running your suggested spyware removal too http://www.superantispywar
Event Type: Error
Event Source: Windows Installer 3.1
Event Category: None
Event ID: 4379
Date: 9/2/2008
Time: 3:31:44 PM
User: 7ND5441\hthompson
Computer: 7ND5441
Description:
Windows Installer Hotfix KB893803v2 installation failed.
KB893803v2 installation did not complete.
For more information, see Help and Support Center at http://go.microsoft.com/fw
Run combofix again using this script.
1. Open Notepad.
2. Now copy/paste the text between the lines below into the Notepad window:
--------------------------
File::
C:\WINDOWS\system32\pwrrrs
C:\Program Files\eblnryc\ShDsc.dll
Folder::
C:\Program Files\eblnryc
C:\Documents and Settings\All Users\Application Data\nshehqvy
Rootkit::
C:\WINDOWS\system32\driver
Driver::
rzjrtxht
Registry::
[HKEY_LOCAL_MACHINE\SOFTWA
"ShDsc"=-
--------------------------
3. Save the above as CFScript.txt on your desktop.
4. Then drag the CFScript.txt into ComboFix.exe. This will start ComboFix again.
Business Accounts
Answer for Membership
by: eegrepPosted on 2008-08-30 at 05:45:50ID: 22351612
Go here and download and run this program [the free edition]: ntispyware .com/downl oad.html
e what it comes up with and what it can clean up.
oad.com/Tr end-Micro- HijackThis /3000-8022 _4- 1022735 3.html
se post the results from hijackthis here.
http://www.supera
Se
Next - download and run hijackthis
http://www.downl
Plea