I've noticed that my own Win 7 reg keys for NetBT are a little different from the XP one I gave you.Now it cannot start normallyPlease explain. C:\Users\Steve\Local Settings\iei.exe (Trojan.FakeAV) -> Quarantined and deleted successfully. Checking service configuration: The start type of Dhcp service is OK.

Download a new Malwarebytes' Anti-Malware from HereDouble Click mbam-setup.exe to

Please run Farber and ComboFix (download a new copy, it was just updated). The service key does not exist.File Check:===========C:\WINDOWS\system32\svchost.exe => MD5 is legitC:\WINDOWS\system32\rpcss.dll => MD5 is legitC:\WINDOWS\system32\services.exe => MD5 is legitC:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legitC:\WINDOWS\system32\Drivers\afd.sys => MD5 is legitAttention!

I just happened to open the Action Center and noticed the below screenshot which I thought was interesting, but probably not anything new. C:\Users\Steve\AppData\Local\Temp\wera0.37253882863410515.exe (Trojan.FakeAV) -> Quarantined and deleted successfully. I did remove it and ran malware this morning and detected no threats.

AVG Free 9.0 ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java 6 Update 17 Java SE Runtime Environment 6 Java SE Runtime Environment 6 Update 1 Java 6 Update 2 Java After downloading the tool, disconnect from the internet and disable all antivirus protection. Memory Processes Infected: c:UsersPaulAppDataLocalojx.exe (Trojan.ExeShell.Gen) -> 3508 -> No action taken. http://www.spywareinfoforum.com/topic/133029-trojanexeshellgen/ Register now!

You'll be asked to confirm, click Yes. If ComboFix caused any error message, reboot again should fix it.

C:\Users\Steve\Local Settings\hsx.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. http://wpquickadminthemes.com/general/trojan-win-bho-cmd.html Several functions may not work. Thank you. Log-Analyse und Auswertung Archiv Search Engine Optimization by vBSEO ©2011, Crawlability, Inc. 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19

trojan.exeshell.gen Letzter Beitrag Antworten Hits Forum Antivir findet EXP/CVE-2010-4452.CE Trojan.exeshell.gen

Checking service configuration:Checking Start type: Attention! LAN connected. Computing.Net and Purch hereby disclaim all responsibility and liability for the content of Computing.Net and its accuracy.

The value does not exist.

The computer still can't find the server. Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. type notepad and press enter.

Now it cannot start normally. Attached are the two text files that were created after running dds.ser. Unable to open NetBt registry key.

Found this thread and ran rogue killer and .exe helperhttp://www.computing.net/answers/se...exeHelper by RaktorBuild 20100414Run at 01:46:19 Registry Values Detected: 1 HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings|ProxyServer (PUM.Bad.Proxy) -> Data: http= -> Quarantined and deleted successfully. C:\Users\Steve\Local Settings\Application Data\rrp.exe (Trojan.ExeShell.Gen) -> Quarantined and deleted successfully. Attached Files OTL.Txt 78.59KB 114 downloads

Do not start a new topic. Logs can take some time to research, so please be patient with me. Possibly it is only browsing that you cannot do.You still have AVG installed. If not please perform the following steps below so we can have a look at the current condition of your machine.

Please try the request again. ERROR The requested URL could not be retrieved The following error was encountered while trying to retrieve the URL: Connection to failed. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command\\""|""%1" %*" /E : value set successfully! ========== FILES ========== File C:\WINDOWS\system32\Drivers\netbt.sys successfully replaced with C:\WINDOWS\system32\dllcache\netbt.sys ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp That said, here are the OTL results: All processes killed ========== OTL ========== Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully.