Attached Files
Edited by greyknight17, 19 May 2008 - 08:09 PM.
Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!
Edited by greyknight17, 19 May 2008 - 08:09 PM.
Edited by kevin777, 19 May 2008 - 10:38 PM.
Save this as CFScript.txt in the same location as the ComboFix.exe tool.DirLook::
C:\Documents and Settings\Kevin Mayer\Application Data\cgtzjets
Driver::
cgldeduc
File::
C:\WINDOWS\system32\avwavp.dll
C:\WINDOWS\system32\drivers\qkotrtbz.dat
C:\WINDOWS\system32\DX8VBe.dll
NetSvc::
rbfbchld
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{256A9C1F-F38D-4E22-BA27-D943236786EC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96147EDE-CE4F-4172-A719-80F811DF98CB}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"24dbio6z05lb"=-
"MSI Configuration"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"24dbio6z05lb"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lznytwib]
Edited by kevin777, 21 May 2008 - 10:06 PM.
Save this as CFScript.txt in the same location as the ComboFix.exe tool.KILLALL::
Driver::
cgldeduc
File::
C:\WINDOWS\system32\avwavp.dll
C:\WINDOWS\system32\DX8VBe.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{256A9C1F-F38D-4E22-BA27-D943236786EC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{96147EDE-CE4F-4172-A719-80F811DF98CB}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\lznytwib]
Rootkit::
cgldeduc
Edited by kevin777, 26 May 2008 - 09:36 AM.
C:\WINDOWS\system32\avwavp.dll C:\WINDOWS\system32\DX8VBe.dll C:\WINDOWS\system32\drivers\cgldeduc.dat HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{256A9C1F-F38D-4E22-BA27-D943236786EC} HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\Explorer\Browser Helper Objects\{256A9C1F-F38D-4E22-BA27-D943236786EC} HKEY_CLASSES_ROOT\CLSID\{256A9C1F-F38D-4E22-BA27-D943236786EC} HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{96147EDE-CE4F-4172-A719-80F811DF98CB} HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Currentversion\Explorer\Browser Helper Objects\{96147EDE-CE4F-4172-A719-80F811DF98CB} HKEY_CLASSES_ROOT\CLSID\{96147EDE-CE4F-4172-A719-80F811DF98CB} HKEY_LOCAL_MACHINE\System\ControlSet001\Services\cgldeduc
Edited by greyknight17, 26 May 2008 - 06:41 PM.
0 members, 0 guests, 0 anonymous users
Community Forum Software by IP.Board
Licensed to: Geeks to Go, Inc.