InterviewSolution
| 1. |
Solve : Why me? please help!!? |
|
Answer» This is actually very puzzling. You have an odd case of malware and I'm having a TOUGH time pinpointing it. A good challenge.... Do you think Llimewire would have anything to do with any of this? The last log said it was either infected or warez. Either way it's best to get rid of it until we figure out what's going on. You never can be sure what your downloading on Limewire... Are the pop-ups still coming? Install a new copy of ComboFix and post the log please. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HIJACKTHIS log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Done. Yes there are still popups, the one in particular. Regestry defender. Also my yahoo search engine is still on the fritz. I can type something to look for and it gives me ten different sites that don't have a thing to do with what I'm looking for?.. Also when I click to open this forum, it gives me the windows cannot display this webpage... again. So I have to click refresh. [Saving space - attachment deleted by admin]This is definitely a challenge, and that file came back. Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Folder:: C:\Lop SD File:: c:\windows\system32\dispex32.dll Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\34b80127509] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeThis seems to work pretty good. It does say file deleted on the log so fingers crossed! Question, when I restart my computer after it says Vaio and plays a little tune, it goes to a black screen for a split second and prompts me to start with windows xp, or something else, do you think this will stop? [Saving space - attachment deleted by admin]One option is Win XP and the other is the Recovery Console right? The Recovery Console was installed by ComboFix. You now can recover your PC if something goes wrong. This next scan will take a while, usually well more than an hour so if you want to wait until tomorrow then that's fine. I'll be around. Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
ComboFix.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Carl Dant\Desktop\ComboFix.exe;Program.PsExec.171;; ComboFix.exe;C:\Documents and Settings\Carl Dant\Desktop;Archive contains infected objects;Moved.; SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Carl Dant\Desktop\SDFix.exe;Tool.Prockill;; SDFix.exe;C:\Documents and Settings\Carl Dant\Desktop;Archive contains infected objects;Moved.; pifCrawl.exe;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08};Trojan.Swizzor.based;Deleted.; aolcinst.exe\core.cab\GTDOWNAO_106.ocx;C:\Program Files\Online Services\AOL Setup\comps\coach\aolcinst.exe;Adware.Gdown;; aolcinst.exe;C:\Program Files\Online Services\AOL Setup\comps\coach;Archive contains infected objects;Moved.; A0001873.EXE;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Program.PsExec.170;; A0001922.exe\32788R22FWJFW\psexec.cfexe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13\A0001922.exe;Program.PsExec.171;; A0001922.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Archive contains infected objects;Moved.; A0001923.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13\A0001923.exe;Tool.Prockill;; A0001923.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Archive contains infected objects;Moved.; A0001924.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Trojan.Swizzor.based;Deleted.; A0001925.exe\core.cab\GTDOWNAO_106.ocx;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13\A0001925.exe;Adware.Gdown;; A0001925.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Archive contains infected objects;Moved.; Actually all of that was either already in a quarantined folder or very low level adware, plus corrupted System Restore Points. Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
---------- How is the computer running now?Wow, looks like alot of people have problems. You guys are great! Well everything looks fine so far. Startup is a little slow, but it does say that it will be slow for a reboot or two, so we'll see. What do you know about DVD fab decrypter? Have you heard of it causing any trouble?I wouldn't trust it. See HERE ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|