In Addition,
You can run combofix CFScript function to delete the bad files and reg entries showing in the Combofix log.
You need to turn off your monitoring programs antivirus/antispyware shield etc when running combofix so they won't interfer with combofix.
Open notepad and copy/paste the text inside the lines below into it.
--------------------------
File::
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\system32\s7467\
C:\WINDOWS\system32\c_3754
C:\WINDOWS\_default37542.p
C:\WINDOWS\4m18138\qm8583.
C:\WINDOWS\o4375427.exe
C:\WINDOWS\j6375422.exe
C:\WINDOWS\hVCPlus.exe
C:\WINDOWS\ms.config`.exe
C:\WINDOWS\ld.exe
C:\WINDOWS\ldup.exe
C:\WINDOWS\infrom.dat
C:\Documents and Settings\4mychildren\Local
C:\Documents and Settings\4mychildren\Local
Folder::
C:\WINDOWS\system32\s7467
C:\WINDOWS\4m18138
DirLook::
C:\Documents and Settings\4mychildren\Local
Registry::
[HKEY_CURRENT_USER\SOFTWAR
"f27844my"=-
[HKEY_LOCAL_MACHINE\SOFTWA
"A6018r"=-
[HKEY_LOCAL_MACHINE\softwa
"A6018r"=-
[HKEY_CURRENT_USER\softwar
"f27844my"=-
[-HKEY_CURRENT_USER\softwa
--------------------------
Save this as CFScript in the same location as ComboFix.exe
then drag CFScript.txt into ComboFix.exe
This will start ComboFix again. Follow the prompts. After reboot, (in case it asks to reboot), attach the contents of Combofix.txt in your next reply together.
Also run this tool please;
Download and run this tool and follow the prompts:
http://www.techsupportforu
Main Topics
Browse All Topics





by: PeteLongPosted on 2008-04-28 at 04:54:24ID: 21453078
Hello tqtclipper,
shell\open \command
ace-percen t-asterisk .)
/fileassoc /xp_exe_fi x.zip
~rmbox/Ret iculated/4 IE_Only/-- ReadMe.txt
l?sa=U&sta rt=1&q=htt p:// home.e arthlink.n et/~rmbox/ Reticulate d/4IE_Only /FIX-exec. inf& e=9797
om/?kbid=8 37334 [New]
om/default .aspx?kbid =310585
om/default .aspx?kbid =311446 exefile.ht m
Click Start, Run and type Command
Type the following and then press Enter after typing each one:
cd\windows
copy regedit.exe regedit.com
start regedit.com [or regedit.com]
Navigate to and select the following key:
HKEY_CLASSES_ROOT\exefile\
Double-click the (Default) value in the right pane.
Delete the current value data, and then type: "%1" %* [with quotes]
(ie., quote-percent-one-quote-sp
Exit the Registry Editor and restart Windows.
Solution 2:
Download .exe File association fix from here:
http://www.dougknox.com/xp
[To run the .reg files, again you will need to rename regedit.exe to regedit.com and run the REG file using "regedit.com filename.reg" parameter]
NOTE: Once set, update the definition files for your anti-virus software and scan the system for viruses.
Solution 3
From http://home.earthlink.net/
Download and right click the following file > Then select Install
http://www.google.co.uk/ur
Related Microsoft Knowledgebase articles:
You receive an error message when you try to start a program that has an .exe file name extension:
http://support.microsoft.c
You Are Unable to Start a Program with an .exe File Extension:
http://support.microsoft.c
You Cannot Start Programs (.exe Files) When Your Computer Is Infected with the SirCam Virus:
http://support.microsoft.c
http://windowsxp.mvps.org/
Regards,
PeteLong