Here is the Combo Fix log: ComboFix 13-04-24.03 - Laura 24/04/2013 21:56:02.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3959.2021 [GMT 1:00] Running from: c:\users\Laura\Desktop\ComboFix.exe AV: Sophos Anti-Virus *Disabled/Updated* {65FBD860-96D8-75EF-C7ED-7BE27E6C498A} Security CheckResults of screen317's Security Check version 0.99.62 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 8 Out of date!``````````````Antivirus/Firewall Check:``````````````Windows Firewall Enabled! It may allow cyber criminals to track your computer and steal your personal information.

Mozilla Firefox (20.0.1)````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Sophos Sophos Anti-Virus SavService.exe Sophos Sophos Anti-Virus SAVAdminService.exe Sophos Sophos Anti-Virus Web Control swc_service.exeSophos Sophos Anti-Virus Web Intelligence Just like most of the Trojans, Win32/small.CA virus also can let your computer be controlled by remote hacker, and the hacker can reach anything that he wants to in your computer I also have another method to get back to the AVG 7.5 and uninstall etc ... To fix these types of problems, download the util mentioned below.

You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.NOTE: It is good practice to copy and paste the instructions into notepad and read more. Otherwise, the Win32/Small.CA virus similar as other Trojan virus such as Trojan.BitcoinMiner, may exploit found system vulnerabilities to lead to further infection of additional threats.

Sophos Anti-Virus WMI entry may not exist for antivirus; attempting automatic update.`````````Anti-malware/Other Utilities Check:`````````MVPS Hosts File Spybot - Search & DestroyMalwarebytes Anti-Malware version Java 7 Update 17 Adobe Flash Player It is common that the virus has the ability to drop and install additional threats such as worms, keyloggers or malware in order to corrupt the security of Windows badly. Remove All.donkeycom.eu popup On Android Phone, Easy Guide How to Remove Android.Fakemrat on Android Phone, Easy Tips How to Remove Ad-type.google.com On Android Phone http://www.apey.ch Moncler Jacken Schweiz Nike Air Max When your computer is infected, you will keep getting an alert from the windows flag at the bottom right corner asking you to remove Win32.Small.CA.

IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 8.0.7601.17514 BrowserJavaVersion: 10.17.2 Run by Laura at 19:40:57 on 2013-04-18 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3959.2311 [GMT 1:00] . That may cause it to stallNote 2: If you receive an error "Illegal operation attempted on a registry key that has been marked for deletion." Please restart the computer"information and logs"In http://blog.vilmatech.com/remove-win32small-ca-virus-manual-removal-help/ Read more on SpyHunter.

Close any open browsers or any other programs that are open.2. c.    Click on Restart option. When an infected document is opened within one of these programs, the program itself will be infected. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - LocalService FontCache . ------- Supplementary Scan ------- .

Any problems during the removal, you may start a live chat with VilmaTech 24/7 online tech agents here for tech support. over here I came across one problem however... Small Cat If you are unsure whether the application can be authorized, please send a sample to Sophos. 20130424 205419 Suspicious behavior detection encountered an error while checking behavior of process 'C:\ComboFix\swreg.3XE'. 20130424 Small Cap INFO: HKCU has more than 50 listed domains.

I obviously don't mind running them again without the anti-virus if you want me to.Note that Sophos came up with the following message when I ran Security Check and it quarantined No action taken. Does your computer always give you an Action Center alert that claims your computer is infected with Win32/Small.CA? navigate here No action taken.

First seen in Sophos Anti-Virus for Windows 2000+ Cause Believed to be a false-positive in Microsoft's Windows Defender triggered by a crash of services.exe. Also verify your firewall permissions as stated in this http://free.avg.com/ww.faq.num-1334. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. I realise I might have had to turn them off before scanning but I couldn't see anything in your instructions that said to switch them off so I didn't (I am Name (required) Email (will not be published) (required) Reply to "" comment: Cancel IMPORTANT! And nowadays, many computers have been suffered from this malicious Trojan all around the world.

If you still can't install SpyHunter? Hence, once you get the alert of Win32/Small.CA, you should have a full scan to check if there have other threats or not. If you wish to scan all of them, select the 'Force scan all domains' option. . his comment is here Read http://forums.avg.com/ww.avg-free-forum?sec=thread&act=show&id=371, provide all of the information mentioned in that post so that we may help you properly.

Cargando... If you are unsure whether the application can be authorized, please send a sample to Sophos. 20130424 205412 Process "C:\ComboFix\pev.3XE" exhibiting suspicious behavior pattern 'HIPS/RegMod-021'. If you are unsure whether the application can be authorized, please send a sample to Sophos. 20130424 205346 Process "C:\32788r22fwjfw\pev.3XE" exhibiting suspicious behavior pattern 'HIPS/RegMod-021'. If you wish to scan all of them, select the 'Force scan all domains' option. .

In addition, the Win32/Small.CA virus is frequently packaged with pirated or illegally acquired software programs, which contain the activation of the virus. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.Please read every post completely before doing anything.Pay special attention The firewall warns me that I'm then not protected until I restart. Infected with Win32/Small.CA?

