Well . . .crap! I have attached a tiny batch file to have a look at the registry policy.
-- Please download the attached Looky.bat and DoubleClick it to run it.
A log will pop up in Notepad - please post the contents for me.
wowfax.dll is legit. Often malware will have similarly named .exes.
I think most of the actual malware files have been cleaned along the way and we are just dealing with remnants. But, just to be certain, I have attached a fresh CFScript.txt.
-- Please DL the latest version of ComboFix.exe and delete any older versions and then drag and drop this new CFScript over ComboFix.exe to run it.
--Also, since you have StartupCPL onboard, I am going to remove most of those MSConfig keys.
Please post the new Combofix log along with the log from my batch file.
As I mentioned, we are probably dealing with remnants and they ought not to cause any problems. But, I'd like to try to be as thorough as possible.
PP





Reply With Quote