http://forum.lowyat.net/index.php?showtopi...post&p=10982416
Added on April 1, 2007, 7:14 pmAlso, please do this after you've tried the fix by Hattori:
Please download OTMoveIt by OldTimer:
- Save it to your desktop.
- Please double-click OTMoveIt.exe to run it.
- Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
C:\WINDOWS\system32\wdata32.dll
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\tlservet3.exe
C:\WINDOWS\system32\Deleteme.bat
C:\WINDOWS\IFinst27.exe
C:\WINDOWS\rundl13a.exe
C:\WINDOWS\uninstall\rundl132.exe
C:\WINDOWS\LSASS.EXE
C:\WINDOWS\system32\SVCH0ST.EXE"
C:\DOCUME~1\Tan\LOCALS~1\Temp\upxdnd.exe
C:\WINDOWS\RUNDLL32.exe
C:\WINDOWS\CSRSS.exe
C:\WINDOWS\SMSS.EXE - Return to OTMoveIt, right-click on the Paste List of Files/Folders to be Moved window and choose Paste.
- Click the red MoveIt! button.
- Copy everything in the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy), and paste it in your next reply.
- Close OTMoveIt.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. After reboot, please run OTMoveIt again, follow the directions as above, and post the Results report for me to see.
NEXT:
Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below (don't forget to copy and paste REGEDIT4 as well):
CODE
REGEDIT4
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dwevv0]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mppds]
-[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVCHOST]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upxdnd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserKill]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhereOU]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wsvbs]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dwevv0]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Load]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mppds]
-[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SVCHOST]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\upxdnd]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserKill]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WhereOU]
[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\wsvbs]
Save this as fix.reg and change the "Save as type" to "All Files" and place it on your desktop.
It should look like this:

Double-click on it and when it asks you if you want to merge the contents to the registry, click "Yes" or "OK". You should receive a message that it was successful.
In case you still are unsure on how to create a REG file, please take a look HERE with screenshots.
NEXT:
Please REBOOT your computer normally into Windows and post these logs in your next reply:
- The results report from OTMoveIt.
- A new ComboFix log.
- A new HijackThis log.
How are things running now? Please let me know of any problems that still persist.
This post has been edited by Sempurna: Apr 1 2007, 07:15 PM
Apr 1 2007, 05:42 PM
Quote
0.0257sec
0.66
7 queries
GZIP Disabled