Please redownload Combofix and start it again. It seems that it has some trouble finishing the scan. Maybe due to Malware.
If it still hangs on a "Stage", please start the Taskmanager and kill any of these Tasks: Findstr.exe/sed.exe/swreg.exe
after that Combofix may continue scanning.
Excellent - you were spot on with this - when I killed Findstr.exe after it seemed to have hung, Combifix then carried on to the end.
Also please start catchme.exe in you Windowsfolder. Press scan and let it do its work. After finish the scan you will find a file called catchme.log on your desktop, please post the content of that file.
Right, here are the two logfiles, combofix and catchme:
http://www.digitalhome.plus.com/ComboFix.txthttp://www.digitalhome.plus.com/catchme.logThere is also a file alongside the ComboFix one called ComboFix-quarantined-files.txt. That says the following:
[ code ]
2005-11-02 09:31 45056 --a------ C:\Qoobox\Quarantine\C\WINDOWS\system32\Service.exe.vir
Folder PATH listing for volume Windows XP
Volume serial number is 00090188 C0F8:FD76
C:\QOOBOX
\---Quarantine
+---C
| \---WINDOWS
| \---system32
| Service.exe.vir
|
\---Registry_backups
[/ code ]
[/tt]
ComboFix.txt mentions C:\WINDOWS\system32\service.exe, and this quarantined files log shows it being got rid of, but I'm pretty sure it's just part of my Dell 3007WFP monitor software - Process Explorer shows it with LCDOSD.exe hanging off it, and now it's been killed I don't get an LCD on-screen display when I change the monitor's brightness. I uploaded service.exe to those online multi-engine virus-checkers earlier and none of them found anything wrong with it.
I notice it also mentions this:
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rasrad32]
rasrad32.dll 2004-11-23 02:44 8192 C:\WINDOWS\system32\rasrad32.dll
If this *was* at fault, what could I do to disable it to test if the problem then goes away?
This line looks the most suspicious in the file but I don't really understand what this part of the file is listing so it might be nothing:
*Newly Created Service* - UVKMWMXMIIQI
Surely no legitimate service would have such a ridiculous name, would it? What can I do about that? Can I remove it?
So, over to you geniuses to tell me what to do now! Thanks again!