Hi
ComboFix is deleting the malware on your machine, it does reset items back to their default settings as a precaution in case malware has changed the defaults, same with those proxy settings, set back to default, you can just easily set Firefox as your default browser if that's what you choose etc. custom settings are generally easy to set. (let me know if you have any difficulty with any of your custom preferences)
Yes keygens are generally evil, they enable you to steal software, so of course they are going to be exploited by malware writers to spread their wares, they are inevitably infected and can wreak havoc on a system, it really isn't worth it:
I would avoid torrents and P2P in the future, most of the infections we see are because users download pirated programs, cracks and keygens.
Try REVO for uninstalling Alcohol:
Download and install the
Revo Uninstaller- Double click the new Revo Uninstaller icon on your desktop to start the program
- Scroll through the listed programs and Right Click on the program you wish to uninstall
- From the pop out menu choose Uninstall
- Click Yes to the confirmation dialogue
- In the next window select the Advanced mode
- Click Next to start uninstalling the program
- Answer Yes to confirm the uninstall
- When the program has completed the four steps, click Next to allow the program to search for leftovers
- Once complete, click Next, then Finish
- Repeat the above steps for any other programs you wish to remove.
please run Farbar Service Scanner, see if we can figure out why system restore isn't working:
Please download
Farbar Service Scanner and run it on the computer with the issue.
- Make sure the following options are checked:
- Internet Services
- Windows Firewall
- System Restore
- Security Center
- Windows Update
- Windows Defender
- Press "Scan".
- It will create a log (FSS.txt) in the same directory the tool is run.
- Please copy and paste the log to your reply.
NEXT- Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below.
- They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Copy/paste the text inside the Codebox below into notepad:Here's how to do that:
Click
Start > Run type
Notepad click
OK.This will open an empty notepad file:
Copy all the text
inside of the code box -
Press Ctrl+C (or right click on the highlighted section and choose 'copy')
NetSvc::
SetupNT
PAC7302
cwafrmiregistry
ntsecure
vcommmgr
omniinet
bhmonitorservice
3compxe
AFGMp50
dlcf_device
oracleorahomeagent
ASNDIS5
NetTcpActivator
liveupdate
File::
C:\Program Files\Alcohol Soft\Alcohol 120\Alcohol.exe
C:\WINDOWS\FixCamera.exe
E:\6 Installers\42 Fájlszerkeszt?k\Unlocker\Unlocker1.9.1.exe
E:\6 Installers\54 Toolok\Alcohol120%\Alcohol 120 v.1.9.6 full version+serial\Alcohol 120 v.1.9.6 full version+serial.rar
E:\6 Installers\81 Tervez?programok\ProE_WF4\ProE.WF4.M130x32.Eng.part01.rar
E:\6 Installers\81 Tervez?programok\ProE_WF4\ProE_WF4_M130x32_eng\ProE_WF4_M130x32_eng.iso
E:\6 Installers\_atnezni\NERO\nero7\Keygen_premium_approve_zsi.exe
E:\6 Installers\_atnezni\NERO\nero7\Ahead.Nero.v7.0.1.4.Premium.not approvd\Keygen.exe
E:\6 Installers\_atnezni\NERO\nero7\nero7xxxkeygen_not approved\nero7keygen.exe
ClearJavaCache::
Now
paste the copied text into the open notepad - press
CTRL+V (or right click and choose 'paste')
Save this file to your desktop, Save this as "CFScript"Here's how to do that:
1.Click
File;
2.Click
Save As... Change the directory to your
desktop;
3.Change the
Save as type to
"All Files";4.Type in the file name:
CFScript5.Click
Save ...
- Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
- ComboFix may request an update; please allow it.
- ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
- When finished, it shall produce a log for you.
- Copy and paste the contents of the log in your next reply.
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.