
UNSOLVED
HelpAssistant and memory full?
Hello,
My Dell Latitude 610 has taken a beating. I think it is the HelpAssistant virus - something is eating up memory as well and I have been getting the blue screen of death. My computer also goes into hibernation often and I can't wake it up. I have ran every virus scan I know of.... My log file is below. Any help is GREATLY APPRECIATED!
ComboFix 10-03-29.02 - owner 03/29/2010 23:07:58.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1015.551 [GMT -4:00]
Running from: c:\documents and settings\owner\My Documents\Downloads\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Internet Explorer\SET5E.tmp
c:\program files\Internet Explorer\SET5F.tmp
c:\windows\system32\Drivers\ctwcrifl.sys
.
((((((((((((((((((((((((( Files Created from 2010-02-28 to 2010-03-30 )))))))))))))))))))))))))))))))
.
2010-03-30 01:53 . 2010-03-30 01:53 -------- d-----w- c:\program files\ESET
2010-03-30 01:30 . 2010-03-30 01:30 -------- d-----w- c:\program files\NOS
2010-03-30 01:29 . 2010-03-22 19:53 32576 ----a-w- c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\43yyfhah.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
2010-03-30 01:29 . 2010-03-22 19:53 29984 ----a-w- c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\43yyfhah.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\chrome\content\getPlusPlus_Adobe_reg.exe
2010-03-30 00:52 . 2010-03-30 00:52 152576 ----a-w- c:\documents and settings\owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll
2010-03-30 00:51 . 2010-03-30 00:51 79488 ----a-w- c:\documents and settings\owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll
2010-03-30 00:09 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2010-03-30 00:02 . 2010-03-30 00:02 -------- d-----w- c:\windows\system32\wbem\Repository
2010-03-29 23:57 . 2010-03-29 23:58 -------- d-----w- c:\program files\QuickTime
2010-03-29 23:56 . 2010-03-29 23:57 -------- d-----w- c:\program files\iTunes
2010-03-29 23:56 . 2010-03-29 23:56 -------- d-----w- c:\program files\iPod
2010-03-29 23:45 . 2010-03-29 23:45 -------- d-----w- c:\program files\Bonjour
2010-03-29 23:45 . 2010-03-29 23:45 -------- d-----w- c:\program files\Digital Line Detect
2010-03-29 23:45 . 2010-03-29 23:45 -------- d-----w- c:\program files\Modem Helper
2010-03-29 23:45 . 2010-03-29 23:45 -------- d-----w- c:\program files\ATI Technologies
2010-03-29 23:43 . 2010-03-29 23:43 -------- d-----w- c:\program files\Lavasoft
2010-03-29 23:43 . 2010-03-29 23:43 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{BC9FCCF7-E686-494B-8C9B-55C9A39A7CA9}
2010-03-29 23:42 . 2010-03-29 23:42 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-03-29 23:41 . 2010-03-29 23:41 -------- d-----w- c:\windows\tiinst
2010-03-29 23:41 . 2010-03-29 23:41 -------- d-----w- c:\program files\Common Files\supportsoft
2010-03-29 23:30 . 2010-03-29 23:30 -------- d-----w- c:\windows\SHELLNEW
2010-03-29 23:30 . 2010-03-29 23:30 -------- d-----w- c:\program files\Microsoft ActiveSync
2010-03-29 23:30 . 2010-03-29 23:30 -------- d-----w- c:\program files\Common Files\L&H
2010-03-29 23:30 . 2010-03-29 23:30 -------- d-----w- c:\program files\Microsoft Works
2010-03-29 23:29 . 2010-03-29 23:29 -------- dc----r- C:\MSOCache
2010-03-26 21:52 . 2010-03-29 23:13 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\AskToolbar
2010-03-26 21:46 . 2010-03-29 23:29 -------- d-----w- c:\program files\Foxit Software
2010-03-25 21:28 . 2010-03-25 21:28 -------- d-----w- c:\documents and settings\owner\Application Data\Malwarebytes
2010-03-25 21:28 . 2010-03-25 21:28 -------- dc----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-25 21:28 . 2010-03-29 23:32 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-21 15:12 . 2010-03-21 15:12 -------- dc----w- c:\documents and settings\Default User\Local Settings\Application Data\Adobe
2010-03-21 15:10 . 2010-03-29 23:37 -------- d-----w- c:\program files\Common Files\Adobe AIR(2)
2010-03-11 04:18 . 2010-03-29 23:42 -------- d-----w- c:\program files\Safari
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-30 01:34 . 2009-09-18 18:16 -------- dc----w- c:\documents and settings\All Users\Application Data\NOS
2010-03-30 00:08 . 2010-03-30 00:08 3218 ----a-w- c:\windows\system32\PerfStringBackup.TMP
2010-03-30 00:06 . 2007-07-25 17:59 72520 ----a-w- c:\documents and settings\owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-03-29 23:57 . 2010-02-12 01:31 -------- d-----w- c:\program files\QuickTime(2)
2010-03-29 23:56 . 2010-02-12 01:36 -------- d-----w- c:\program files\iTunes(2)
2010-03-29 23:56 . 2010-02-12 01:37 -------- d-----w- c:\program files\iPod(2)
2010-03-29 23:56 . 2009-09-26 22:27 -------- d-----w- c:\program files\Common Files\Apple
2010-03-29 23:51 . 2007-07-24 21:54 -------- d-----w- c:\documents and settings\owner\Application Data\U3
2010-03-29 23:41 . 2009-09-18 18:26 -------- d-----w- c:\program files\Yahoo SiteBuilder
2010-03-25 23:55 . 2009-09-26 23:12 56556 ---ha-w- c:\windows\system32\mlfcache.dat
2010-03-11 04:27 . 2009-09-16 19:51 -------- d-----w- c:\program files\Google
2010-03-10 04:42 . 2010-01-23 02:19 -------- dc----w- c:\documents and settings\All Users\Application Data\Lavasoft
2010-01-23 23:04 . 2010-01-23 23:03 1706 -c--a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\qbbackup.sys
2010-01-23 03:25 . 2010-01-23 03:24 862040 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\threatwork.exe
2010-01-23 03:24 . 2010-01-23 03:24 206944 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavamessage.dll
2010-01-23 03:24 . 2010-01-23 03:24 390288 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\lavalicense.dll
2010-01-23 03:24 . 2010-01-23 03:24 537576 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\aawapi.dll
2010-01-23 03:24 . 2010-01-23 03:24 372280 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\UpdateManager.dll
2010-01-23 03:24 . 2010-01-23 03:24 194104 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Savapibridge.dll
2010-01-23 03:21 . 2010-01-23 03:20 6296864 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Resources.dll
2010-01-23 03:20 . 2010-01-23 03:20 933120 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\CEAPI.dll
2010-01-23 03:20 . 2010-01-23 03:19 3803208 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AutoLaunch.exe
2010-01-23 03:19 . 2010-01-23 03:19 816272 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareCommand.exe
2010-01-23 03:19 . 2010-01-23 03:19 823928 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-AwareAdmin.exe
2010-01-23 03:19 . 2010-01-23 03:19 1643272 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Ad-Aware.exe
2010-01-23 03:19 . 2010-01-23 03:19 788880 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWTray.exe
2010-01-23 03:19 . 2010-01-23 03:18 1181328 -c--a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\AAWService.exe
2010-01-22 21:53 . 2010-01-22 21:53 0 -c--a-w- c:\windows\nsreg.dat
2010-01-22 21:43 . 2010-01-22 21:43 869664 -c--a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\qbpatch.exe
2010-01-22 21:43 . 2010-01-22 21:43 499712 -c--a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\msvcp71.dll
2010-01-22 21:43 . 2010-01-22 21:43 348160 -c--a-w- c:\documents and settings\All Users\Application Data\Intuit\QuickBooks 2009\Components\DownloadQB19\Patch\msvcr71.dll
2010-01-14 16:12 . 2010-01-23 14:27 181120 ------w- c:\windows\system32\MpSigStub.exe
2009-12-31 16:50 . 2004-08-04 12:00 353792 ----a-w- c:\windows\system32\drivers\srv.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-09-16 39408]
"wben"="c:\program files\Starfield\Desktop Notifier\wben.exe" [2009-06-25 338456]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-07-07 344064]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2007-03-16 1392640]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-09-15 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-09-15 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-09-15 118784]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2007-02-21 819200]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2007-02-21 970752]
"BluetoothAuthenticationAgent"="bthprops.cpl" [2008-04-14 110592]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-09-19 149280]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\UdaterUI.exe" [2006-11-17 136768]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-10-29 141600]
"Intuit SyncManager"="c:\program files\Common Files\Intuit\Sync\IntuitSyncManager.exe" [2009-10-28 1085704]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-7-24 24576]
QuickBooks Update Agent.lnk - c:\program files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-12-11 984352]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Intuit\\QuickBooks 2009\\QBDBMgrN.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/22/2010 10:40 PM 64288]
R3 GTIPCI21;GTIPCI21;c:\windows\system32\drivers\gtipci21.sys [7/25/2007 2:27 PM 87936]
S2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [12/2/2009 9:19 AM 1181328]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
getPlusHelper REG_MULTI_SZ getPlusHelper
.
Contents of the 'Scheduled Tasks' folder
2010-03-30 c:\windows\Tasks\Ad-Aware Update (Daily 1).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 03:19]
2010-03-29 c:\windows\Tasks\Ad-Aware Update (Daily 2).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 03:19]
2010-03-28 c:\windows\Tasks\Ad-Aware Update (Daily 3).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 03:19]
2010-03-27 c:\windows\Tasks\Ad-Aware Update (Daily 4).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 03:19]
2010-03-30 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-12-02 03:19]
2010-03-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]
2010-03-30 c:\windows\Tasks\User_Feed_Synchronization-{E6E15640-2B44-453C-BF38-C02EE205FB7B}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
Handler: intu-help-qb2 - {84D77A00-41B5-4b8b-8ADF-86486D72E749} - c:\program files\Intuit\QuickBooks 2009\HelpAsyncPluggableProtocol.dll
FF - ProfilePath - c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\43yyfhah.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - plugin: c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\43yyfhah.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Adobe Reader Speed Launcher - c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-03-29 23:11
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
.
Completion time: 2010-03-29 23:12:58
ComboFix-quarantined-files.txt 2010-03-30 03:12
Pre-Run: 7,653,580,800 bytes free
Post-Run: 8,097,681,408 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
- - End Of File - - B9D56E0571528E127E7781B0EDEB16E2
Responses (5)
Solutions (0)
I read on another forum to run it and have the scan ready when you ask for help then I couldn't loggin on that forum.
I ran ESET, malewarebytes, windows defender and right now I am rerunning Spybot (I'm on another PC). I think I have stopped the helpassistant folders from duplicating but most of my hardrive still appears to be full?
Reply
Considering those per-posting instructions, I'd say that would not be a good place to take advice from anyway.I read on another forum to run it and have the scan ready when you ask for help then I couldn't loggin on that forum. As you run ComboFix the Disclaimer is displayed:
It states that Combofix should not be run in an unsupervised environment. That means that someone trained in its use needs to be working with you. Otherwise, you should not have run the tool to begin with.
Please follow these instructions so we can take a look and see if you really do have that infection. This won't fix it, but it will give us more information.
Download and run HAMeb_check.exe
Post the contents of the resulting log on our Malware Removal Forum (with a link to this discussion).Note: if you do in fact have the Help Assistant mbr rootkit infection, fixing the mbr may prevent access the the Dell Restore Utility which allows you to press a key on startup and revert your computer to a factory delivered state. There are a couple of known fixes for said condition, though the methods are somewhat advanced.
I may not be available to help, but perhaps one of the other trained analysts will respond. If you do not get a reply within 4 days, try posting at Geeks To Go, 24/7 Fixes, Bleeping Computer, or SpywareHammer. Each of those forums requires different tools to be run prior to posting, so be sure to read the instructions.
Reply

Bugbatter
4 Apprentice
•
20487 Posts
690
0
Posted March 30th, 2010 06:00
Have your helper who advised you to run ComboFix review the log and work with you to run the additional procedures.