07-17-2012 03:32 PM
sorry...was too excited about the fix!
Here is it again!
07-17-2012 06:11 PM
Step 3.
Please read carefully Read all of this message first
Download Combofix http://www.bleepingcomputer.com/download/anti-viru
Right click the combofix.exe on the desktop and select from the menu "Run as Administrator"
****Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze ****
Note: ComboFix may reset a number of Internet Explorer's settings, including making it the default browser.
Note: Combofix prevents autorun of ALL CDs, floppies and USB devices to assist with malware removal & increase security.
*EXTRA NOTES*
Quads
07-17-2012 08:13 PM
Hi Quads,
Please see attached.
ps i don't know why it's in chinese
07-18-2012 01:00 AM
Could be that the internal system language is set to so Asian langauge
I can see that services.exe is fixed
step 4. (a)
Please read carefully and Slowly
Please scan with ESET next
I'd like us to scan your machine with ESET OnlineScan
button.
to download the ESET Smart Installer. Save it to your desktop.
button.
and DON'T (NO) check Remove found threats (reason for this is we don't want something deleted and then Windows won't load).
If you think a log should have been generated then go to C:\Program Files\ESET\ESET Online Scanner\log.txt to find it.
Quads
07-18-2012 09:40 PM
Hi Quads,
Here's the scan result.
Thanks
07-18-2012 11:19 PM
Part 4. (b)
Download OTL http://www.bleepingcomputer.com/download/otl/
Disable Norton for say 30 minutes
Start OTL,
Click the Scan All Users checkbox.
Change file age to 60 days
Press the 
An OTL.txt and extras.txt will be created.
Quads
07-19-2012 07:23 PM
Quads, please see attached.
thx.
07-20-2012 12:50 AM
Uninstall
ESET Online Scanner
I have to script for the rest
Quads
07-20-2012 03:44 PM
hi Quads, done~
thx
07-20-2012 09:15 PM
Disable Norton for say 30 minutes
Start OTL, under
Copy and paste the custom script attached which you open in for instance Notepad,(include the : at the start of :OTL and all the way to the end / bottom) and run the script. (Red Run Fix Button)
The output log, should be placed in the C:\ _OTL folder after.
Quads
