I have been cleaning up an infection on a machine. I did not see the original screen of the infection so I don't know what variant it was. I only got to see the symptoms and they were mostly halting local files to be run properly and running lots of weird EXE files from the Application Data folder. The machine started acting better when running ComboFix. If ComboFix is run, the machine will settle down. It does not find anything but it will start working properly.
There are two services for sure that are showing up as unable to be run that are causing problems - Cryptographic Services and DHCP Client. These services will run properly while ComboFix is installed on the machine. If I uninstall ComboFix and reboot, these services will not run or work properly again. These services will not run properly. I forgot to document the error they ran but it has to do with dependencies. There are also some weird Services that start with "%systemroot% at the top of the list. They are not running but I don't know where they are from and if they were a part of ComboFix or the infection. There was a B-Service that showed up that was referencing the the Temporary Internet Files Content.IE5 folder so I now that one is junk and has been disabled as such.
I have gone through and put a trial of AVG Internet Security 2012 on the machine, I have run a System File Checker (sfc /scannow) on the machine, I have used TDSS Killer on the machine, I have run Malwarebytes Anti-Malware on the machine, and I have gone through some other variations of possibilities.
I am trying to think of what my next step should be. I have attached the ComboFix log from the last time where it settles the services down to where they will run properly. I have also attached the latest version of the TDSS Killer log as well. Let me know where you think I can go.
I have been a longtime supporter of what you have for information on this site and I have used your advice quite a few times. I have finally become a member because I have run into a problem now that I have not seen the light on and need some insight as to where to go.