Hello.
Don't try deleting "Recycler", that is the legit folder, the malware is called "resycled", there is an s instead of the c, don't mistake them otherwise it could cause problems.
We just need to repair some things.
Now open a new notepad file.
Input this into the notepad file:
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:
This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.
............................................................................................
Site Admin / Security Administrator
Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Don't try deleting "Recycler", that is the legit folder, the malware is called "resycled", there is an s instead of the c, don't mistake them otherwise it could cause problems.
We just need to repair some things.
Now open a new notepad file.
Input this into the notepad file:
KILLALL::
AWF::
c:\program files\Common Files\Symantec Shared\bak\ccApp.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\MouseWare\system\bak\EM_EXEC.EXE
c:\program files\CA\eTrust PestPatrol\bak\PPActiveDetection.exe
c:\program files\QUICKENW\bak\QAGENT.EXE
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Keymaestro\Multimedia Keyboard\bak\MMKeybd.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\D-Tools\bak\daemon.exe
Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\V]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{38a4d306-b2d6-11dc-ab4e-00e0988595d9}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5395a160-2a47-11d9-a4a7-806d6172696f}]
Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:
This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.
Site Admin / Security Administrator
Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.