Hello
Please remember : "All applications I ask to be used will require to be run in Administrator mode. IE: Right click on and select Run as Administrator."
Step 1I've noticed that Win32kdiag is not on your desktop, please delete it and download it again to
your desktop.
Step 2We'll try running win32kdiag from command line
Click on Start->Run, and copy/paste the contents of the code below into the "Open" box
"%userprofile%\desktop\win32kdiag.exe" -f -r
Click OK.
When it's finished, there will be a log called Win32kDiag.txt on your desktop. Please open it with notepad and post the contents here.
Step 31. Please
download The Avenger by Swandog46 to your
Desktop.
- Right click on the Avenger.zip folder and select "Extract All..."
- Follow the prompts and extract the avenger folder to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (
Ctrl+C):
Begin copying here:
Files to move:
C:\WINDOWS\system32\logevent.dll | C:\WINDOWS\system32\eventlog.dll
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.3. Now, open the avenger folder and
start The Avenger program by clicking on its icon.
- Right click on the window under Input script here:, and select Paste.
- You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
- Click on Execute
- Answer "Yes" twice when prompted.
4.
The Avenger will automatically do the following:
- It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
- On reboot, it will briefly open a black command window on your desktop, this is normal.
- After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
- The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please
copy/paste the content of
c:\avenger.txt into your reply.
Step 4Please download ComboFix from
Here or
Here to your Desktop.
**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**Step 5Please post the following logs in your next reply :
- the win32kdiag from the second step
- the avenger log from the third step
- the combofix log from the fourth step