This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Services and controller app has stopped working

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Was this the only place it was found?
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]



No..It was found in some other places as well… But the same error message "Cannot delete ldkxkff". Error while deleting the key
Try this
Click Start > Run and Copy/Paste these commands hitting enter after each one:

net stop ldkxkff Hit enter.

sc delete ldkxkff Hit enter.

Let me know what happens

Try this
Click Start > Run and Copy/Paste these commands hitting enter after each one:

net stop ldkxkff Hit enter.

sc delete ldkxkff Hit enter.

Let me know what happens


LD,

I did that…A commant prompt appears for a second and went off quickly… Also, in regedit, ldkxkff is still visible but there are no subkeys, no content….I just plugged in network card and its working perfect. What can we do now ?

–Sathia–

Run a new combofix scan



I did it and here is the scan results. After scan, I again reconnet the network card. Again the same problem pops up " Services and controller app has stopped working "

ComboFix 10-07-31.01 - sathia.gamesh 08/01/2010 4:47.4.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3573.2500 [GMT 5.5:30]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Created from 2010-06-28 to 2010-07-31 )))))))))))))))))))))))))))))))
.

2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\temp
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\Public\AppData\Local\temp
2010-07-31 23:23 . 2010-07-31 23:23 ——– d—–w- c:\users\Default\AppData\Local\temp
2010-07-31 23:16 . 2010-07-31 23:16 ——– d—–w- C:\32788R22FWJFW
2010-07-30 20:01 . 2010-07-30 20:01 0 —-a-w- c:\windows\nsreg.dat
2010-07-30 20:01 . 2010-07-30 20:01 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Mozilla
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\programdata\Malwarebytes
2010-07-30 18:14 . 2010-04-29 10:09 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
2010-07-30 15:41 . 2010-07-30 15:41 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Microsoft Help
2010-07-30 15:41 . 2010-07-30 20:40 ——– d—–w- c:\programdata\Microsoft Help
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut106_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut104_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut102_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut101_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut107_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut103_4E5D8DB3B289401D8458DF0125189210.exe
2010-07-29 18:09 . 2010-07-29 18:09 ——– d—–w- c:\program files\WebEx
2010-07-24 18:25 . 2010-07-24 18:25 ——– d—–w- c:\programdata\muvee Technologies
2010-07-24 18:25 . 2010-07-24 18:37 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\muvee Technologies
2010-07-24 17:07 . 2010-07-24 17:07 ——– d—–w- c:\programdata\Seagate
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Downloaded Installations
2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\program files\Carbonite
2010-07-24 17:06 . 2010-07-24 17:06 ——– d-sh–w- c:\windows\ftpcache
2010-07-24 17:05 . 2010-07-24 17:07 ——– d—–w- c:\program files\Seagate
2010-07-24 17:05 . 2010-07-24 17:05 ——– d—–w- c:\program files\Common Files\muvee Technologies
2010-07-24 17:02 . 2010-07-24 17:02 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Leadertech

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-31 22:16 . 2010-06-25 16:55 12 —-a-w- c:\windows\bthservsdp.dat
2010-07-31 19:49 . 2010-05-21 15:02 ——– d—–w- c:\program files\AmiBroker
2010-07-31 14:34 . 2010-03-18 13:04 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\vlc
2010-07-30 20:40 . 2010-03-18 14:57 ——– d—–w- c:\program files\Microsoft Works
2010-07-30 18:17 . 2010-03-29 12:46 ——– d—–w- c:\program files\Elecard
2010-07-30 15:56 . 2010-03-16 18:34 101216 —-a-w- c:\users\sathia.gamesh\AppData\Local\GDIPFONTCACHEV1.DAT
2010-07-24 17:08 . 2010-03-19 14:22 ——– d–h–w- c:\program files\InstallShield Installation Information
2010-06-13 14:22 . 2010-06-13 14:17 ——– d—–w- c:\programdata\Yahoo! Companion
2010-06-13 14:18 . 2010-06-13 14:17 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:17 262144 —-a-w- C:\ntuser.dat
2010-06-13 14:17 . 2010-06-13 13:54 ——– d—–w- c:\program files\Yahoo!
2010-06-13 14:17 . 2010-06-13 14:16 ——– d—–w- c:\programdata\Yahoo!
2010-06-02 17:24 . 2010-06-02 17:23 ——– d—–w- c:\program files\Real Alternative
2010-06-02 14:37 . 2010-06-02 14:37 ——– d—–w- c:\program files\K-Lite Codec Pack
2010-06-01 04:58 . 2010-06-13 14:16 607544 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe
2007-02-21 19:49 . 2007-02-21 19:49 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT
.

((((((((((((((((((((((((((((( SnapShot@2010-07-31_21.34.32 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-03-16 22:53 . 2010-07-31 22:19 42642 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2010-03-16 22:53 . 2010-07-31 21:04 42642 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2006-11-02 13:05 . 2010-07-31 21:21 59958 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2010-07-31 22:20 59958 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2010-03-16 18:35 . 2010-07-31 22:20 11354 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2165722446-2496424982-340524404-1000_UserData.bin
- 2010-03-16 18:35 . 2010-07-31 21:21 11354 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2165722446-2496424982-340524404-1000_UserData.bin
+ 2006-11-02 13:02 . 2010-07-31 22:17 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2006-11-02 13:02 . 2010-07-31 21:31 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2006-11-02 13:02 . 2010-07-31 22:17 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2010-07-31 21:31 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2006-11-02 13:02 . 2010-07-31 21:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:02 . 2010-07-31 22:17 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2010-07-31 21:30 . 2010-07-31 21:31 1666 c:\windows\SoftwareDistribution\PostRebootEventCache\{5E6C7E83-AD80-4F04-8D79-14159147E1FB}.bin
+ 2010-07-31 21:30 . 2010-07-31 23:21 1666 c:\windows\SoftwareDistribution\PostRebootEventCache\{5E6C7E83-AD80-4F04-8D79-14159147E1FB}.bin
+ 2010-07-31 22:17 . 2010-07-31 22:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2010-07-31 21:02 . 2010-07-31 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-31 22:17 . 2010-07-31 22:17 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-07-31 21:02 . 2010-07-31 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2006-11-02 10:33 . 2010-07-31 22:24 598588 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-07-31 21:26 598588 c:\windows\System32\perfh009.dat
- 2006-11-02 10:33 . 2010-07-31 21:26 102194 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:33 . 2010-07-31 22:24 102194 c:\windows\System32\perfc009.dat
+ 2006-11-02 10:22 . 2010-07-31 22:22 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2010-07-31 21:23 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2010-07-31 21:25 . 2010-07-31 21:25 6414336 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2010-07-31 21:25 . 2010-07-31 23:16 6414336 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2010-03-18 07:38 . 2010-07-31 23:07 166733750 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-01 1180976]
"SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-29 206064]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096]
"MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-12-18 197928]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240]
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"VistaSp2"=hex(B):3f,40,0d,dd,77,c6,ca,01

R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-04-27 83496]
R3 PCD5SRVC{0F020303-306A84E7-05040104};PCD5SRVC{0F020303-306A84E7-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-04-27 64304]
S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-04-27 160720]
S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728]
S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-12-18 189736]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-04-27 188136]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-04-27 141792]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-04-27 55456]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-04-27 312616]
S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-03-19 4233728]


— Other Services/Drivers In Memory —

*Deregistered* - ldkxkff
*Deregistered* - mfeavfk01

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2010-03-18 c:\windows\Tasks\Uniblue DiskRescue 2009.job
- c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://in.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-08-01 04:53
Windows 6.0.6002 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{0F020303-306A84E7-05040104}]
"ImagePath"="\??\c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]

.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'Explorer.exe'(4636)
c:\progra~1\mcafee\SITEAD~1\saHook.dll
.
Completion time: 2010-08-01 04:56:33
ComboFix-quarantined-files.txt 2010-07-31 23:26
ComboFix2.txt 2010-07-31 21:38

Pre-Run: 41,988,214,784 bytes free
Post-Run: 41,831,972,864 bytes free

Current=1 Default=1 Failed=0 LastKnownGood=1 Sets=1,2,3,4,5,6,7,8
- - End Of File - - 61583627C471DCABC1A29BD1C3986D14
Click Start > Run and Copy/Paste these commands hitting enter after each one:

net stop ldkxkff Hit enter.

sc delete ldkxkff Hit enter.

Next:
Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet\Services\ldkxkff]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ldkxkff]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\ldkxkff]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste


Also please describe how your computer behaves at the moment.
Hi LD, Extremely sorry for my late reply. Got internet connection issue with service provider. Just fixed that with them and now coming to our problem. I ran combo fix scan as per your latest advice and here is the scan results. Please let me know your view ComboFix 10-07-31.01 - sathia.gamesh 08/01/2010 10:16:34.6.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3573.2544 [GMT 5.5:30] Running from: c:\users\[removed]\Desktop\ComboFix.exe Command switches used :: c:\users\sathia.gamesh\Desktop\CFScript.txt SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((( Files Created from 2010-07-01 to 2010-08-01 ))))))))))))))))))))))))))))))) . 2010-08-01 04:53 . 2010-08-01 04:53 ——– d—–w- c:\users\RA Media Server\AppData\Local\temp 2010-08-01 04:53 . 2010-08-01 04:53 ——– d—–w- c:\users\Public\AppData\Local\temp 2010-08-01 04:53 . 2010-08-01 04:53 ——– d—–w- c:\users\Default\AppData\Local\temp 2010-07-31 23:52 . 2010-08-01 04:53 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\temp 2010-07-30 20:01 . 2010-07-30 20:01 0 —-a-w- c:\windows\nsreg.dat 2010-07-30 20:01 . 2010-07-30 20:01 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Mozilla 2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Malwarebytes 2010-07-30 18:14 . 2010-04-29 10:09 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-07-30 18:14 . 2010-07-30 18:14 ——– d—–w- c:\programdata\Malwarebytes 2010-07-30 18:14 . 2010-04-29 10:09 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-07-30 15:41 . 2010-07-30 15:41 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Microsoft Help 2010-07-30 15:41 . 2010-07-30 20:40 ——– d—–w- c:\programdata\Microsoft Help 2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut106_4E5D8DB3B289401D8458DF0125189210.exe 2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut104_4E5D8DB3B289401D8458DF0125189210.exe 2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut102_4E5D8DB3B289401D8458DF0125189210.exe 2010-07-29 18:09 . 2010-07-29 18:09 45056 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut101_4E5D8DB3B289401D8458DF0125189210.exe 2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut107_4E5D8DB3B289401D8458DF0125189210.exe 2010-07-29 18:09 . 2010-07-29 18:09 40960 —-a-r- c:\users\sathia.gamesh\AppData\Roaming\Microsoft\Installer\{7B189FD2-B936-4D8A-B329-48A5ECC89FD0}\NewShortcut103_4E5D8DB3B289401D8458DF0125189210.exe 2010-07-29 18:09 . 2010-07-29 18:09 ——– d—–w- c:\program files\WebEx 2010-07-24 18:25 . 2010-07-24 18:25 ——– d—–w- c:\programdata\muvee Technologies 2010-07-24 18:25 . 2010-07-24 18:37 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\muvee Technologies 2010-07-24 17:07 . 2010-07-24 17:07 ——– d—–w- c:\programdata\Seagate 2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\users\sathia.gamesh\AppData\Local\Downloaded Installations 2010-07-24 17:06 . 2010-07-24 17:06 ——– d—–w- c:\program files\Carbonite 2010-07-24 17:06 . 2010-07-24 17:06 ——– d-sh–w- c:\windows\ftpcache 2010-07-24 17:05 . 2010-07-24 17:07 ——– d—–w- c:\program files\Seagate 2010-07-24 17:05 . 2010-07-24 17:05 ——– d—–w- c:\program files\Common Files\muvee Technologies 2010-07-24 17:02 . 2010-07-24 17:02 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Leadertech . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-07-31 23:59 . 2010-06-25 16:55 12 —-a-w- c:\windows\bthservsdp.dat 2010-07-31 19:49 . 2010-05-21 15:02 ——– d—–w- c:\program files\AmiBroker 2010-07-31 14:34 . 2010-03-18 13:04 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\vlc 2010-07-30 20:40 . 2010-03-18 14:57 ——– d—–w- c:\program files\Microsoft Works 2010-07-30 18:17 . 2010-03-29 12:46 ——– d—–w- c:\program files\Elecard 2010-07-30 15:56 . 2010-03-16 18:34 101216 —-a-w- c:\users\sathia.gamesh\AppData\Local\GDIPFONTCACHEV1.DAT 2010-07-24 17:08 . 2010-03-19 14:22 ——– d–h–w- c:\program files\InstallShield Installation Information 2010-06-13 14:22 . 2010-06-13 14:17 ——– d—–w- c:\programdata\Yahoo! Companion 2010-06-13 14:18 . 2010-06-13 14:17 ——– d—–w- c:\users\sathia.gamesh\AppData\Roaming\Yahoo! 2010-06-13 14:17 . 2010-06-13 14:17 262144 —-a-w- C:\ntuser.dat 2010-06-13 14:17 . 2010-06-13 13:54 ——– d—–w- c:\program files\Yahoo! 2010-06-13 14:17 . 2010-06-13 14:16 ——– d—–w- c:\programdata\Yahoo! 2010-06-02 17:24 . 2010-06-02 17:23 ——– d—–w- c:\program files\Real Alternative 2010-06-02 14:37 . 2010-06-02 14:37 ——– d—–w- c:\program files\K-Lite Codec Pack 2010-06-01 04:58 . 2010-06-13 14:16 607544 —-a-w- c:\programdata\Yahoo!\YUpdater\yupdater.exe 2007-02-21 19:49 . 2007-02-21 19:49 8192 –sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( SnapShot@2010-07-31_21.34.32 ))))))))))))))))))))))))))))))))))))))))) . + 2010-03-16 20:32 . 2010-03-16 20:32 84480 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6002.18197_none_7b3d56a455f59b03\INETRES.dll + 2010-03-16 20:32 . 2010-03-16 20:32 84480 c:\windows\winsxs\x86_microsoft-windows-mail-comm-dll_31bf3856ad364e35_6.0.6001.18416_none_79ac63d2588f4d00\INETRES.dll + 2010-03-16 21:47 . 2010-03-16 21:47 19456 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6002.18248_none_170a947c06d19246\tzupd.exe + 2010-03-16 21:47 . 2010-03-16 21:47 19456 c:\windows\winsxs\x86_microsoft-windows-i..rnational-timezones_31bf3856ad364e35_6.0.6001.18464_none_150a7fae09bf1281\tzupd.exe + 2010-03-16 22:37 . 2010-03-16 22:37 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\lpk.dll + 2010-03-16 22:37 . 2010-03-16 22:37 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\fontsub.dll + 2010-03-16 22:37 . 2010-03-16 22:37 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18262_none_ab7ab4ea57db7e87\dciman32.dll + 2010-03-16 22:37 . 2010-03-16 22:37 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\lpk.dll + 2010-03-16 22:37 . 2010-03-16 22:37 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\fontsub.dll + 2010-03-16 22:37 . 2010-03-16 22:37 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18482_none_a97ea1445ac5641e\dciman32.dll + 2010-03-16 22:53 . 2010-08-01 04:41 42658 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2006-11-02 13:05 . 2010-08-01 04:41 59982 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin + 2010-03-16 18:35 . 2010-08-01 04:41 11406 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2165722446-2496424982-340524404-1000_UserData.bin + 2006-11-02 13:02 . 2010-08-01 04:39 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2006-11-02 13:02 . 2010-07-31 21:31 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2006-11-02 13:02 . 2010-08-01 04:39 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2006-11-02 13:02 . 2010-07-31 21:31 98304 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2006-11-02 13:02 . 2010-08-01 04:39 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat - 2006-11-02 13:02 . 2010-07-31 21:31 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2010-03-16 20:33 . 2010-03-16 20:33 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6002.18244_none_0de17507ef8f87d4\AcRes.dll + 2010-03-16 20:33 . 2010-03-16 20:33 2560 c:\windows\winsxs\x86_microsoft-windows-a..ence-mitigations-c1_31bf3856ad364e35_6.0.6001.18461_none_0be26083f27c2166\AcRes.dll + 2010-07-31 21:30 . 2010-08-01 04:53 1666 c:\windows\SoftwareDistribution\PostRebootEventCache\{5E6C7E83-AD80-4F04-8D79-14159147E1FB}.bin - 2010-07-31 21:30 . 2010-07-31 21:31 1666 c:\windows\SoftwareDistribution\PostRebootEventCache\{5E6C7E83-AD80-4F04-8D79-14159147E1FB}.bin + 2010-08-01 04:39 . 2010-08-01 04:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2010-07-31 21:02 . 2010-07-31 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2010-08-01 04:39 . 2010-08-01 04:39 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2010-07-31 21:02 . 2010-07-31 21:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2006-11-02 10:33 . 2010-07-31 21:26 598588 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2010-08-01 04:45 598588 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2010-07-31 21:26 102194 c:\windows\System32\perfc009.dat + 2006-11-02 10:33 . 2010-08-01 04:45 102194 c:\windows\System32\perfc009.dat + 2006-11-02 12:34 . 2006-11-02 12:34 2836992 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6002.18197_none_5a0aedc022b31946\MSOERES.dll + 2006-11-02 12:34 . 2006-11-02 12:34 2836992 c:\windows\winsxs\x86_microsoft-windows-mail-core-dll_31bf3856ad364e35_6.0.6001.18416_none_5879faee254ccb43\MSOERES.dll + 2010-03-18 13:04 . 2010-01-06 15:39 1696256 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6002.18244_none_43bf8becbe801d82\gameux.dll + 2010-03-16 20:33 . 2010-03-16 20:33 1695744 c:\windows\winsxs\x86_microsoft-windows-gameexplorer_31bf3856ad364e35_6.0.6001.18461_none_41c07768c16cb714\gameux.dll + 2006-11-02 10:22 . 2010-07-31 23:55 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT - 2006-11-02 10:22 . 2010-07-31 21:23 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT + 2010-03-18 07:38 . 2010-07-31 23:42 168456540 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-04-11 1233920] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952] "Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" [2010-06-01 5252408] "Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-18 1008184] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656] "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-05-09 36864] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-11 34672] "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2010-04-01 1180976] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-09-13 405504] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-01-29 206064] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2007-10-19 286720] "googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648] "YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856] "CarboniteSetupLite"="c:\program files\Carbonite\CarbonitePreinstaller.exe" [2009-08-04 318096] "MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2009-12-18 197928] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-2-22 1193240] WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2008-9-10 525664] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc] "VistaSp2"=hex(B):3f,40,0d,dd,77,c6,ca,01 R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-04-27 83496] R3 PCD5SRVC{0F020303-306A84E7-05040104};PCD5SRVC{0F020303-306A84E7-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms [2008-11-04 22904] S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2010-04-27 64304] S1 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2010-04-27 160720] S2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2007-09-20 73728] S2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2009-12-18 189736] S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480] S2 McMPFSvc;McAfee Personal Firewall;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480] S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe [2009-12-14 271480] S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-04-27 188136] S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-04-27 141792] S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-04-27 55456] S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-04-27 312616] S3 NETw5v32;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-03-19 4233728] — Other Services/Drivers In Memory — *Deregistered* - ldkxkff *Deregistered* - mfeavfk01 [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache bthsvcs REG_MULTI_SZ BthServ . Contents of the 'Scheduled Tasks' folder 2010-03-18 c:\windows\Tasks\Uniblue DiskRescue 2009.job - c:\program files\Uniblue\DiskRescue\UBDiskRescue.exe [2008-09-10 15:22] . . ——- Supplementary Scan ——- . uStart Page = about:blank mStart Page = hxxp://in.yahoo.com IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** scanning hidden processes … scanning hidden autostart entries … scanning hidden files … scan completed successfully hidden files: ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\PCD5SRVC{0F020303-306A84E7-05040104}] "ImagePath"="\??\c:\progra~1\Dell Support Center\HWDiag\bin\PCD5SRVC.pkms" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ldkxkff] . ——————— LOCKED REGISTRY KEYS ——————— [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . ——————— DLLs Loaded Under Running Processes ——————— - - - - - - - > 'Explorer.exe'(3432) c:\progra~1\mcafee\SITEAD~1\saHook.dll . Completion time: 2010-08-01 10:27:02 ComboFix-quarantined-files.txt 2010-08-01 04:56 ComboFix2.txt 2010-07-31 23:26 ComboFix3.txt 2010-07-31 21:38 Pre-Run: 41,849,876,480 bytes free Post-Run: 41,684,574,208 bytes free Current=1 Default=1 Failed=0 LastKnownGood=1 Sets=1,2,3,4,5,6,7,8,9,10,11 - - End Of File - - 614856692AE40433C7E16F3BF41102AD

Got internet connection issue with service provider

Is the connection issue still there?


Hi LD,

Welcome back…Good Morning :)…. Connection issue resolved yesterday. Now we need to focus on "Services and controller app has stopped working" error :)…Please help..

-Sathia–

Once connected to internet, I am immediately getting the message "Services and controller app has stopped working" ." and also second message "Windows has encountered a critical problem and will restart automatically in one minute.Please save your work now" . Today Morning, I executed an .exe file also executed a registry file that came with it. Because of this, I think some virus/trojans/malware attacked my system. I did SFC scan and also tried Malwarebytes anti Malware. But couldn't fix it. Everytime I open the internet, the same problem is coming. But the problem won't come, If I am not connected to the internet.

Is that what is still happening?

Once connected to internet, I am immediately getting the message "Services and controller app has stopped working" ." and also second message "Windows has encountered a critical problem and will restart automatically in one minute.Please save your work now" . Today Morning, I executed an .exe file also executed a registry file that came with it. Because of this, I think some virus/trojans/malware attacked my system. I did SFC scan and also tried Malwarebytes anti Malware. But couldn't fix it. Everytime I open the internet, the same problem is coming. But the problem won't come, If I am not connected to the internet.

Is that what is still happening?


Yes LD…After running Combofix, it worked fine…But lateron once i connect to network card again, the same error pops up.
Try this:

VISTA:
To repair and reset the Windows Vista

1. Click on Start button.
2. Type Cmd in the Start Search text box.
3. Press Ctrl-Shift-Enter keyboard shortcut to run Command Prompt as Administrator. Allow elevation request.
4. Type netsh winsock reset in the Command Prompt shell, and then press the Enter key.
Exit


Reset IP Stack.

1. Click on Start button.
2. Type Cmd in the Start Search text box.
3. Press Ctrl-Shift-Enter keyboard shortcut to run Command Prompt as Administrator. Allow elevation request.
4. Type netsh int ip reset in the Command Prompt shell, and then press the Enter key.
Restart the computer.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI