1.

Solve : Can't open SuperAntiSpyware Installer/access user normally (Unsolved)?

Answer»

It's the most recent version, and when I try to open it (I'm installing it in Safe Mode because I can't access it in Normal Mode) and it says that the system administrator has set policies to prevent this installation. What?

I was trying to get ready to post a topic for help on a worm I found called Win32.Zafi.B and this is stopping me

All I could get was HJT and MALWARE log in the second postI think the SuperAntiSpyware Installer communicates with the home server during install so that might be what's wrong.

Try installing and running MalwareBytes from here: http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.htmlPrograms in Add/Remove that seem suspicious to me:
Bonjour
Desktop Dialer
GemMaster Mystic

And I can't get into my own user. I'll click on it, and then it'll just sit there loading. Like it's frozen

I managed to get some scans into safe mode. Here are the Malwarebytes and HJT logs

[attachment deleted by admin]Quote

Programs in Add/Remove that seem suspicious to me:
Bonjour
Desktop Dialer
GemMaster Mystic

You can uninstall all of those.

Open HijackThis and select Do a system scan only.

Place a check mark next to the following entries: (if there)

- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http:
- R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl/*http:
- O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
- O4 - HKUS\S-1-5-19\..\Run: [liyimajibu] Rundll32.exe \"C:\WINDOWS\system32\demayoha.dll\",s (User \'LOCAL SERVICE\')
- O4 - HKUS\S-1-5-20\..\Run: [liyimajibu] Rundll32.exe \"C:\WINDOWS\system32\demayoha.dll\",s (User \'NETWORK SERVICE\')
- O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\yowokifo.dll rezymv.dll kgtqqr.dll zskewr.dll wubzoe.dll C:\WINDOWS\system32\pawovuda.dll npehkd.dll uzbwnd.dll llstat.dll c:\windows\,C:\WINDOWS\system32\lepopoka.dll


Important: Close all windows except for HijackThis and then click Fix checked.

Exit HijackThis.

----------

Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

Link #1
Link #2

**Note: It is important that it is saved directly to your Desktop

Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click combofix.exe & follow the prompts.
When finished ComboFix will produce a log for you.
Post the ComboFix log in your next reply.

Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

If you have problems with ComboFix usage, see How to use ComboFixComboFix Log

For the record, I had no choice but to run this in Safe Mode with Networking

[attachment deleted by admin]Delete these files/folders, as follows:

1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
It must be Notepad, not Wordpad.
2. Copy the text in the below code BOX by highlighting all the text and pressing Ctrl+C

Code: [Select]KillAll::

File::
c:\windows\system32\jezewisa.dll
c:\windows\system32\ziwinuro.dll
c:\windows\system32\sebajuyo.dll
c:\windows\system32\rosozevi.dll
c:\windows\system32\mumonuwi.dll
3. Go to the Notepad window and click Edit > Paste
4. Then click File > Save
5. Name the file CFScript.txt - Save the file to your Desktop
6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeAlso can you get into Normal Mode now?I couldn't EXACTLY copy it, but I typed it in exactly as I saw

And I can get into Normal Mode now, but slowly

[attachment deleted by admin]Download DrWeb CureIt & save it to your desktop.

Scan with DrWeb-CureIt as follows:
  • Double-click on drweb-cureit.exe and then click Start.
  • An Express Scan of your PC notice will appear.
  • Under Start the Express Scan Now Click OK to start.
    • This is a SHORT scan that will scan the files currently running in memory.
    • If or when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the Scan tab and UNcheck Heuristic analysis and click OK
  • Back at the main window, select the Complete scan button.
  • Then click the Green Arrow Start Scanning button on the right and the scan will start.
    • Click Yes to all if it asks if you want to cure/move any file(s).
  • When the scan is done.
  • In the Dr.Web CureIt menu on top left, click File and choose Save report list.
  • Save the DrWeb.csv report to your Desktop.
  • Exit Dr.Web Cureit.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
[/COLOR]
  • After reboot, Right-click the Dr.Web log on the desktop and choose Open With > Notepad
  • Copy and paste that log in the next reply
Alright. The format of the program has changed a bit according to your instructions but it's done.

Code: [Select]ComboFix.exe/data002\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Administrator\Desktop\ComboFix.exe/data002;Program.PsExec.171;;
data002;C:\Documents and Settings\Administrator\Desktop;Archive contains infected objects;;
ComboFix.exe;C:\Documents and Settings\Administrator\Desktop;Container contains infected objects;Moved.;
GTDownAO_106.ocx;C:\Program Files\Common Files\AolCoach\en_en;Adware.Gdown;;
fagunake.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS;Trojan.Virtumod.1615;Deleted.;
arfehs.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
bamezafu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
bdexxv.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
begehr.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
bovenage.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
cpiltp.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
dmtlci.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
fabireze.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
fapilizu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
fihatoye.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
fufoyevo.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
gghxwt.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
gidobedi.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
goradoja.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
hbsvzf.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
hezubuti.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Siggen.2006;Deleted.;
hikagazu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
hqcrbp.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
johabuji.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
kafimehe.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
kejefuru.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
kgtqqr.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Packed.375;Deleted.;
kvtvub.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
lipulone.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
llstat.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
madudori.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
mazileve.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
meyobuha.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
mohafilu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
moharira.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
nakonaze.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
npehkd.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
nsgyok.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
parahuri.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
puzominu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
qmmpam.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
refemope.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1622;Deleted.;
sedebodu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
semajosu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
tuvibibu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
uglgve.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
ursnfk.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
uzbwnd.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
vfpfhgyo.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Packed.375;Deleted.;
vgvczg.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
vofehafi.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
wdpvgf.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
wewidilu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
wifufulu.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
wizuyebi.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
wubzoe.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.80;Deleted.;
yamapaso.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
yorerufo.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
yoyijite.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
zepepewa.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Virtumod.1615;Deleted.;
ziluyuda.dll.vir;C:\Qoobox\Quarantine\C\WINDOWS\system32;Trojan.Juan.77;Deleted.;
A0156750.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP342;Trojan.Siggen.568;Deleted.;
A0159786.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP342;Trojan.Virtumod.1622;Deleted.;
A0163903.exe;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP347;Modification of Win32.Bumblebee.3649;Moved.;
A0166951.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP347;Trojan.Siggen.568;Deleted.;
A0170045.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP350;Trojan.Virtumod.1628;Deleted.;
A0175115.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP350;Trojan.Virtumod.1628;Deleted.;
A0180138.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP351;Trojan.Virtumod.1628;Deleted.;
A0186150.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP352;Trojan.Virtumod.1628;Deleted.;
A0197232.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1628;Deleted.;
A0200324.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1622;Deleted.;
A0200326.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1622;Deleted.;
A0203349.exe;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.DownLoader.59802;Deleted.;
A0203350.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0203351.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Siggen.568;Deleted.;
A0203352.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0203353.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1596;Deleted.;
A0203354.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1596;Deleted.;
A0203355.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0203356.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0203357.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Packed.375;Deleted.;
A0203360.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Packed.375;Deleted.;
A0203362.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0203363.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0203366.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0203367.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0203368.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0203369.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1628;Deleted.;
A0207397.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207399.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207400.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207402.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207403.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207405.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207407.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207408.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207412.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207413.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207414.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207416.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207417.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207418.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207419.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207420.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207421.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Siggen.2006;Deleted.;
A0207422.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207423.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207427.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207429.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207430.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207431.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Packed.375;Deleted.;
A0207432.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207433.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207434.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207435.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207436.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207437.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207438.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207439.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207440.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207442.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207443.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207446.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207448.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207449.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207450.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1622;Deleted.;
A0207452.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207453.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207456.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207458.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207460.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207462.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207463.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Packed.375;Deleted.;
A0207464.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207465.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207466.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207468.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207469.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207470.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207471.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.80;Deleted.;
A0207474.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207477.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207478.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207480.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Virtumod.1615;Deleted.;
A0207481.dll;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Trojan.Juan.77;Deleted.;
A0207520.EXE;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP354;Program.PsExec.170;;
A0207617.EXE;C:\System Volume Information\_restore{CD0BACDB-7BB8-4982-9127-7CA9CF228C78}\RP356;Program.PsExec.170;;
[attachment deleted by admin]That didn't find anything new.

Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.

  • Open the folder and run Dial-a-fix.exe
  • 2 windows will open. Close the one in the background labeled Restrictive Policies
  • Check the box in section 1, Empty temp folders.
  • Check the box in section 2, Fix Windows Installer.
  • Check the box in section 3, Fix Windows Update.
  • Check the box in section 4, labeled SSL/HTTPS/Cryptography. The 4 boxes under it should be pre-checked
  • Check all boxes in section 5, labeled Registration Center.
  • Click Go
  • OK any error messages if received, but write them down and post them here.
  • Restart the computer when done.
.
How is it running now?No error messages

Seems to be running fine...for a laptop. Anything else?Let's clear out the programs we've been using to clean up your computer, they are not suitable for general malware removal and could cause DAMAGE if launched accidentally. These steps will also help secure the work you have done.
.
  • Click START then RUN
  • Now type Combofix /u in the runbox
  • Make sure there's a space between Combofix and /u
  • Then hit Enter.
.
.
The above procedure will:
  • Delete:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
    • Reset the clock settings.
    • Hide file extensions, if required.
    • Hide System/Hidden files, if required.
    • Set a new, clean Restore Point.
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Go to Microsoft Windows Update and get all critical updates.

    ----------

    Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

    Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before.

    For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable.

    To prevent unknown applications from being installed on your computer install WinPatrol 2008
    * Using Winpatrol to protect your computer from malicious software

    I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

    SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
    * Using SpywareBlaster to protect your computer from Spyware and Malware
    * If you don't know what ActiveX controls are, see here

    Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

    Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.


    Discussion

    No Comment Found