Hi all,
My last combo fix log needing double checking on what I'm thinking of removing.
If you can it would be appreciated.
Now this guy is computer illiterate. (totally and utterly)
I taught him how to copy and paste tonight. (He's around 48)
The computer will be in the hands of a more computer literate person tomorrow night my time.
Combofix log attached. My thoughts below. (Forgive my ignorance if the unknowns are normal for Vista. I don't use it)
Thanks in advance,
Terry
The bad
[HKEY_CURRENT_USER\softwar
e\microsof
t\windows\
currentver
sion\explo
rer\mountp
oints2\{fb
0ba2a8-3f1
1-11dd-b41
d-001c26dd
e710}]
\shell\AutoRun\command - F:\password_viewer.exe %1
\shell\Explore\command - F:\password_viewer.exe %1
\shell\Open\command - F:\password_viewer.exe %1
The unknown
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
FirewallRu
les]
"{757A5F9D-9E31-4DE2-885D-
D600349B53
91}"= TCP:10421:SingleClick Discovery Protocol
"{33E6750B-CD3E-495F-95F9-
ECEF436F1D
7D}"= TCP:10426:SingleClick ICC
2008-04-29 03:50 181,760 ----a-w C:\Windows\System32\fsquir
t.exe
[HKLM\~\services\sharedacc
ess\parame
ters\firew
allpolicy\
Restricted
Services\S
tatic\Syst
em]
"DFSR-1"= RPort=5722|UDP:%SystemRoot
%\system32
\svchost.e
xe|Svc=DFS
R:Allow inbound TCP traffic|
Start Free Trial