I received the upload, thanks. It did contain an mdll.dl file you mentioned earlier. Only contained what is likely encrypted code, so surely suspect, but no info we can use here. The Reglooks log shows a few items we need to address, which may aid the ComboFix run issue. And some AVG remnants, which also can be a factor. But we still need to get a decent swap-out of the files you got replacements for.
Click here and download sUBs' SvcQuery.exe to your desktop, then click that file to open that tool. A window will open. When prompted to provide a service name, type in the following, then press Enter:
lvdgwgcb
Repeat that, using the following:
xpkihsl
Then follow the prompt to exit. The tool will create a log - post that back here please.
--------------------
Open Notepad (Start - Run, type Notepad then press OK), and copy the text inside the box above and paste it into the open Notepad textbox.Code:REGEDIT4 [HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AMService"=- [HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AMService"=-
Save this to your desktop as "fixer.reg"
Be sure to include the "" quotes in the name.
Then right click fixer.reg, select Merge, and allow it to merge the new information with the Registry.
------------------
Go here and download and run the AVG uninstaller.
-------------------
Open Notepad (Start - Run, type notepad and press Enter).Code:@ECHO OFF cd c:\windows ren lastgood lastgood-old >nul 2>&1 ren lastgood.temp lastgood-old2 >nul 2>&1 md C:\windows\lastgood\system32\drivers copy C:\Documents and Settings\Administrator\Desktop\LostWinFiles\sfcfiles.dll C:\windows\lastgood\system32\drivers\sfcfiles.dll copy C:\Documents and Settings\Administrator\Desktop\LostWinFiles\wscntfy.exe C:\windows\lastgood\system32\drivers\wscntfy.exe copy C:\Documents and Settings\Administrator\Desktop\LostWinFiles\msgsvc.dll C:\windows\lastgood\system32\drivers\msgsvc.dll
Copy/paste the above text (inside the Code box) into the open text box, then save this to your desktop as "changer.bat"
Be sure to include the "" quotes in the name. Then click on changer.bat. A window should open briefly but nothing more.
-------------------
Then restart the computer, and as it boots up tap the F8 key about once per half-second, to access the startup menu (where you can make Safe Mode selections). From that menu select the following:
Last Known Good Configuration
That should load a saved copy of the Registry, but also do the file swap we need.
------------------
Go to Start - Run, copy paste the following, then click the OK button:
"%userprofile%\desktop\combofix.exe" /killall
Then follow the previous steps and allow ComboFix to complete it's processes. Post the C:\ComboFix.txt log here please.


Zitieren