Open a command window. Highlight and copy the bolded text below and paste it in. regsvr32 /u /s softpub.dll regsvr32 /u /s wintrust.dll...
I would like to see what happens with the 2180 version.
Good to know. Thanks! :) extra.txt log suggests that you have 3 hard drives - 2 internal? and 1 USB, and 3 cd-rom drives. Is that correct?...
Open a command window and paste the first command below then hit enter. sc stop cryptsvc Wait 10 seconds and do the next sc query...
Open a command window and paste the following command, then hit enter. ren %systemroot%\system32\catroot2\Edb.log *.tst Check for updates...
edit - not applicable
Looks as though the infections are cleaned up. I am curios about some things though. From the extra.txt log. Event Record #/Type20319 /...
Click Review update history in the left pane on the Windows Update site and see what you get.
I knew that ...... see if it will allow you to rename it. Often times you can rename a file (a system file) that's in use and it will be replaced...
Yes ...... !Killbox should go. Empty the recycle bin too.
See if you can delete it. May need to disable UAC to do so. It doesn't appear to be hooked into anything.
Try replacing the one in the dllcache folder with the one I noted, then rename the one in system32 and reboot.
There should not be a perfs back in system32 ..... ugghhh. Please post a fresh dss log.
Replace the one in system32 with the following and reboot. Directory of C:\WINDOWS\system32\mui\040D 04/08/2004 12:56 AM 2,842,112...
Copy the following bolded command. sc stop wuauserv Click Start then Run and paste the command on the run line then hit enter. Rename the...
Logs look great! I'd say we're done ....... Geri?
I would also like to see what all copies of xpsp2res.dll you have, so please do the following as well. Highlight and copy the contents of the...
No need to apologize. I appreciate your patience and co-operation. ;) Let's clean up a bit and run a scan. Click Start>Run and type ComboFix /u...
In a subfolder of C:\Deckard you will find a log named extra.txt .... please post it's contents here as well.
Paste the following command in a command window and hit enter. sc query wscsvc It should report the service as running. Let me know.
Separate names with a comma.