I should have mentioned that in the original post, I always rename ComboFix before running it because I've had problems with viruses recognizing the name before.
Main Topics
Browse All TopicsI am taking a look at a friend's laptop who was complaining that one day several desktop shortcuts appeared out of nowhere and that Windows Defender and AVG popped up with alerts.
My first reaction was to run ComboFix is Safe Mode, however even though it is a fresh download, ComboFix displays a warning that the computer may be infected with a file-patching virus like "Virut". Malwarebytes found 30 items and removed them, however ComboFix still will not run.
I attempted to run Trend Micro Housecall, however the browser will not navigate to that page, it hangs up on searching for 'search.avg.com'. Usually ComboFix is my go-to, but if it won't run even in Safe Mode I'm concerned. Are there are any boot disks that have it pre-installed?
Attached is the HiJackThis log, any input on how to remove this malware would be greatly appreciated.
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Have you tried renaming Combofix before saving to your desktop?
Fix these entries in Hijackthis:
R3 - URLSearchHook: (no name) - *{4D25F926-B9FE-4682-BF72-
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-
F2 - REG:system.ini: UserInit=C:\WINDOWS\system
O1 - Hosts: 92.241.176.188 advanced-virus-remover2009
O1 - Hosts: 92.241.176.188 www.advanced-virus-remover
C:\WINDOWS\system32\sdra64
You can also try DrWebCureIt, it's a very tool for detecting and removing virut.
http://www.freedrweb
Can you acces this link below, use the Combofix instructions there and see if it runs.
http://www.experts-ex
Another approach that works sometimes, if renaming doesn't fix the problem,
Start in Safe Mode
- Click/Enter username
-- ASAP, CRTL + ALT + DEL to get the taskbar, even before the desktop loads. This is very important. Any programs that run in the applications list, kill it. If you can kill it quick enough, or even get CF turned on before the rogue program does, it will sometimes allow you to run CF.
Business Accounts
Answer for Membership
by: Admin3kPosted on 2009-07-14 at 07:16:35ID: 24849731
try renaming combofix first