THE RECOMMENDED "CF" POST (please give attribution to rpggamergirl when using) Please download ComboFix by sUBs:(and attach the resulting log) http://download.bleepingcomputer.com/sUBs/ComboFix.exe (If it doesn't run, re-download and rename before saving to your desktop - use the "Save As" function) Now STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) as they could easily interfere with ComboFix. Double click combofix.exe & follow the prompts. When finished, it will produce a log. Please save that log and attach it in your next reply by pasting it in the "Code Snippet" or "Attach File" window. Re-enable all the programs that were disabled during the running of ComboFix. Note: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. If needed, here's the ComboFix tutorial which includes the installation of the Recovery Console: http://www.bleepingcomputer.com/combofix/how-to-use-combofix When finished with the question, don't forget this: To uninstall Combofix: Go to Start > Run and 'copy and paste' next command in the field: ComboFix /Uninstall
Recent comment from rpggamergirl "Here's my .02 with regards CF and MBAM. Many people believe that running CF or MBAM from Safe Mode is better, but that's not true because CF and MBAM are optimized to run from Normal mode, that's where they work best. Running in Safe Mode is only necessary if users have trouble loading Windows in normal mode, or in special cases where CF or MBAM just won't run successfully in normal mode. Yes, ComboFix doesn't like it when AVG or CA Internet Security Suite is installed in the system so the user must uninstall this first before running CF. Sometimes even when AVG is already uninstalled but its folder is still present CF may still complain so the AVG folder needs to be deleted. ComboFix also pops up alert if an AVG entry in the WMI is present (you can remove its entry following the steps in one of my articles) or you can just ignore it and ComboFix will still run. ComboFix in Windows 2003 Server: We should not be recommending CF to be run in systems other than those CF is designed for. CF will run in 2003 Standard Server but doing that is a big risk to take... Things have gone wrong when CF is run in the systems it is designed for, so how much likely things could go wrong if we disregard the author's instructions? sUBs doesn't even want users using ComboFix without a Helper who is trained to use the tool."
From novice to tech pro — start learning today.