A client mistakenly downloaded MapGalaxy instead of using Mapquest which caused all kinds of issues. She has had other PUPs on her computer in the past.
Since she had just downloaded MapGalaxy I tried to run a System Restore with not much luck. I was unable to set a SR from April...tried to run both in normal and safe mode. Said it restored to 5/15, which was 2 days before the PUPs were added, but when I got into SR is shows it was restored to 5/17??
When I tried to go into msconfig, to change to clean boot state, the cursor would simply travel, there and other places, without touching the mouse. Her homepage in IE or Chrome would not load...could not access the internet, although I am connecting remotely to her, to access any webpage. I transfer tools from my computer to hers since I could not download anything.
Norton was completely disabled. MBAM was reset to zero updates but the server could update the program, no issues found.
Major error message when attempting to download and install Google Chrome, even though I uninstalled first.
I put her computer in a clean boot state and one by one, running scans, I have been able to get her computer working again.
Autoruns has 1 scheduled task in Red - Microsoft\Windows\NetTrace
\GatherNet
workInfo, seems legit...why would it be in red?
If I understand a little about how ComboFix works I am hoping to have some assistance using it, incase we have left over beasts!
Any other suggestions?
Thanks,
Mags
Rkill--1.txt
AdwCleaner-S1-.txt
HitmanPro-20130518-1137.log
a2scan-130518-120508.txt
RKreport-1--S-05182013-02d1318.txt
RKreport-2--PR-05182013-02d1318.txt
Google-Chrome-error-message.txt
AutoRuns--2.arn
JRT.txt
Rkill--6.txt