1. Please open Notepad- Click Start , then Run
- Type notepad .exe in the Run Box.
2. Now copy/paste the entire content of the codebox below into the Notepad window:
Code:
File::
C:\FOUND.000
C:\FOUND.051
C:\FOUND.050
C:\FOUND.049
c:\windows\system32\drivers\lhllpn.sys
Folder::
Driver::
abp470n5
AdobeHidServ
ALGlanmanserverWmi
AudioSrvRemoteAccess
AudioSrvScheduleThemesose
AudioSrvUPSWZCSVC
avast!lanmanserverWmiNetDDE
dmadminSCardSvr
dmserverBITS
ERSvcNtLmSsp
ERSvcRemoteRegistryAdobeHidServ
EventlogDhcp
EventSystemWZCSVC
lanmanserverWmi
lanmanserverWmiNetDDE
LmHostsAudioSrvRemoteAccess
LmHostsMSIServerRemoteRegistry
MSIServerRemoteRegistry
MSIServerRemoteRegistryRemoteAccess
NetDDEAppMgmt
NetDDEdsdmFastUserSwitchingCompatibility
NetlogonNetDDEdsdm
NetlogonW32Time
PlugPlayThemes
RemoteRegistryAdobeHidServ
RemoteRegistryMSIServer
RpcSsxmlprov
RSVPTermService
RSVPUPSWZCSVC
ScheduleThemes
ScheduleThemesose
SpoolerNetlogonNetDDEdsdm
TapiSrvLmHosts
TermServiceUMWdf
Registry::
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"DisableTaskMgr"=-
"DisableRegistryTools"=-
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AdobeHidServ]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ALGlanmanserverWmi]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AudioSrvRemoteAccess]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AudioSrvScheduleThemesose]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\AudioSrvUPSWZCSVC]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\avast!lanmanserverWmiNetDDE]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmadminSCardSvr]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\dmserverBITS]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ERSvcNtLmSsp]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ERSvcRemoteRegistryAdobeHidServ]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\EventlogDhcp]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\E ventSystemWZCSVC]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\lanmanserverWmi]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\lanmanserverWmiNetDDE]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\LmHostsAudioSrvRemoteAccess]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\LmHostsMSIServerRemoteRegistry]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSIServerRemoteRegistry]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\MSIServerRemoteRegistryRemoteAccess]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetDDEAppMgmt]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetDDEdsdmFastUserSwitchingCompatibility]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetlogonNetDDEdsdm]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NetlogonW32Time]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\PlugPlayThemes]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RemoteRegistryAdobeHidServ]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RemoteRegistryMSIServer]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RpcSsxmlprov]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RSVPTermService]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\RSVPUPSWZCSVC]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ScheduleThemes]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\ScheduleThemesose]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SpoolerNetlogonNetDDEdsdm]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\TapiSrvLmHosts]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\TermServiceUMWdf]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\UPSThemes]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\UPSWZCSVC]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\UPSWZCSVCWmiApSrvEventlogDhcp]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\W32TimeHTTPFilter]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WmiApSrvEventlogDhcp]
[-HKEY_LOCAL_MACHINE\System\ControlSet002\Services\WZCSVCMSIServer]
RegLockDel::
3. Save the above as CFScript.txt
4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:- Combofix.txt
- A new HijackThis log.