InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 951. |
Solve : Good site blocked by McAfe Antivirus. True?? |
|
Answer» I got a call from a relative to tell me that MalwareBytes.org, a good site. was blocked by McAfe Anti VIRUS. That just can not ber true, -Right? Ask yourself this: why don't Mac users run anti-virus software? Why don't UNIX users run anti-virus software? Because they don't need to. It's because malware writers haven't put any effort into attacking a Mac. Too much work with no reward. But Mac viruses are rising, slowly but there new ones being released. Quote At its heart, anti-virus software is little more than a glorified blacklist. It maintains an internal list of evil applications and their unique byte signatures, and if it sees one on your system, kills it for you. Sure, anti-virus VENDORS will dazzle you with their ad copy, their heuristic this and statistical that; they'll tell you (with a straight face, even) that their software is far more than a simple blacklist. It's a blacklist with lipstick. It's the prettiest, shiniest, most kissable blacklist you've ever seen! Not true. Behavior/heuristic detection is a very good resource. That's why users have to turn off their AV before using some of the specialized tools in malware REMOVAL. They behave just like some malware and will be terminated. But hey, who am I to try and tell a PROGRAMMER that software is better than something that can be done with DOS or manually. So you are 100% sure that McAfee is blocking access to the MalwareBytes Web site?yeah I pretty much disagreed with the same two points- but as far as Admin/limited this was made pre-vista and I think that MS addressed that issue at least partly with UAC and related security features. As far as hueristics I think they work fairly well, especially in that they will find new "strains" of previously profiled viruses- and even can be set so that they detect any virus using a module or loader distributed between malware authors; Additionally I find it interesting how he says blacklists don't work and yet offers no reasonable ALTERNATIVE other then that now essentially made the default- run as a limited user. I think Vista and now Windows 7 have addressed the whole "running as admin" issue fairly well. |
|
| 952. |
Solve : Virus preventing access to antivirus sites and programs.? |
|
Answer» I am running WINDOWS XP sp3. I have a virus that is preventing firefox and IE from accessing online virus scan site, such as trans micro and kaspesky. I found another thread describing similar problems and I followed the steps recommended in it as far as I could. When the virus first hit my computer, McAfee did recognize the threat and tried to delete it, but for some reason it wasn't able to, it told me to manually remove it from Add/Remove Programs, I tried but I couldn't get to the program, I kept being redirected to a google shearch for Win32.DNSChanger. After running virus scans with McAfee and AVG, I removed a handful of trojans and spyware, the most significant one being a Win32.DNSChanger. This made it so that I was able to at least access files on my computer again.
2) I didn't find any of the .sys 3) done 4) I was able to get MBAM to run by renaming it and changing its extension to .bat (a recommendation I found on another forum). I will copy and paste the log of that run. After I restarted I was able to open MBAM with its original name, I rescanned and it detected nothing. MBAM log: Malwarebytes' Anti-Malware 1.34 Database version: 1764 Windows 5.1.2600 Service Pack 3 2/15/2009 7:09:23 PM mbam-log-2009-02-15 (19-09-23).txt Scan type: Quick Scan Objects scanned: 82318 Time elapsed: 11 minute(s), 11 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 16 Registry Values Infected: 2 Registry Data ITEMS Infected: 0 Folders Infected: 0 Files Infected: 27 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e3ce575e-c27d-4aa1-b3d8-e510f9124980} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{e3ce575e-c27d-4aa1-b3d8-e510f9124980} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\lmaspois (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\lmaspois.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7a85cdf5-284b-4496-a9a7-dd82fee9dcec} (Rogue.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{fcd4b2f5-8793-4e1f-8774-6e520cf6cd79} (Rogue.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{930e7881-d9f3-4293-a24b-23a80c013378} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{a8954909-1f0f-41a5-a7fa-3b376d69e226} (Rogue.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{930e7881-d9f3-4293-a24b-23a80c013378} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{930e7881-d9f3-4293-a24b-23a80c013378} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\crypt (Trojan.Downloader) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jgubofa (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ssemonusohoma (Trojan.Agent) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\system32\ibpwie.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\UACmxejuctn.dll (Rootkit.TDSS) -> Delete on reboot. C:\WINDOWS\system32\UACtvvmlrqj.dll (Trojan.TDSS) -> Delete on reboot. C:\WINDOWS\system32\UACubopxlvk.dll (Rootkit.TDSS) -> Delete on reboot. C:\WINDOWS\system32\UACylrdciqr.dll (Rootkit.TDSS) -> Delete on reboot. C:\WINDOWS\system32\drivers\UACrpbprdnt.sys (Rootkit.TDSS) -> Delete on reboot. C:\Documents and Settings\James Stokes\Local Settings\Temp\UACb7e4.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Local Settings\Temp\E6C3.tmp (Trojan.Backdoor) -> Quarantined and deleted successfully. C:\WINDOWS\Temp\UACc9d3.tmp (Rootkit.TDSS) -> Delete on reboot. C:\Documents and Settings\James Stokes\Local Settings\Temporary Internet Files\Content.IE5\2R0VBIDQ\pifccddur[1].txt (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Local Settings\Temporary Internet Files\Content.IE5\CX7S0RXV\upd105320[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Favorites\Cheap Software.url (Rogue.Link) -> Quarantined and deleted successfully. C:\WINDOWS\system32\sf.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Favorites\MP3 Download.url (Rogue.Link) -> Quarantined and deleted successfully. C:\WINDOWS\system32\m3.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Favorites\Search Online.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Favorites\VIP Casino.url (Rogue.Link) -> Quarantined and deleted successfully. C:\Documents and Settings\James Stokes\Favorites\Cheap Pharmacy Online.url (Rogue.Link) -> Quarantined and deleted successfully. C:\WINDOWS\system32\c.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\m.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\p.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\s.ico (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\uacinit.dll (Trojan.Agent) -> Delete on reboot. C:\Documents and Settings\James Stokes\Favorites\SMS TRAP.url (Rogue.Link) -> Quarantined and deleted successfully. C:\WINDOWS\ios.dat (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\UACdbqltltx.dat (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\UACmevxfqhr.log (Trojan.Agent) -> Delete on reboot. Download ComboFix© by sUBs from one of the below links. Be sure top SAVE it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixComboFix Log: ComboFix 09-02-15.01 - James Stokes 2009-02-15 20:42:29.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2046.1297 [GMT -5:00] Running from: c:\documents and settings\James Stokes\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\James Stokes\Desktop\ComboFix.exe AV: McAfee VirusScan *On-access scanning disabled* (Updated) FW: McAfee Personal Firewall *enabled* * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\IE4 Error Log.txt c:\windows\system32\DKmnpXyb.ini c:\windows\system32\DKmnpXyb.ini2 c:\windows\system32\WGiSvyay.ini c:\windows\system32\WGiSvyay.ini2 c:\windows\Tasks\nbzpxgnw.job . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_UACd.sys ((((((((((((((((((((((((( Files Created from 2009-01-16 to 2009-02-16 ))))))))))))))))))))))))))))))) . 2009-02-15 19:00 . 2009-02-15 19:00 d-------- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2009-02-15 18:55 . 2009-02-15 18:55 d-------- c:\documents and settings\James Stokes\Application Data\Malwarebytes 2009-02-15 18:53 . 2009-02-15 19:11 d-------- c:\program files\Malwarebytes' Anti-Malware 2009-02-15 18:53 . 2009-02-15 18:53 d-------- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-15 18:53 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-15 18:53 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys 2009-02-15 13:45 . 2009-02-15 17:07 d-------- C:\rsit 2009-02-15 13:18 . 2009-02-15 19:40 d-------- c:\program files\SUPERAntiSpyware 2009-02-15 13:18 . 2009-02-15 13:18 d-------- c:\documents and settings\James Stokes\Application Data\SUPERAntiSpyware.com 2009-02-15 11:55 . 2009-02-15 11:55 d-------- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files 2009-02-15 04:24 . 2009-02-15 15:55 d--h----- C:\$AVG8.VAULT$ 2009-02-15 04:20 . 2009-02-15 19:29 d-------- c:\documents and settings\All Users\Application Data\avg8 2009-02-14 17:11 . 2009-02-14 17:11 302,592 --a------ c:\windows\system32\byXpnmKD.dll.vir 2009-02-14 15:18 . 2009-02-14 15:18 302,592 --a------ c:\windows\system32\yayvSiGW.dll.vir 2009-02-12 03:02 . 2009-02-12 03:02 d-------- c:\windows\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$ 2009-02-06 14:18 . 2009-02-06 14:38 d-------- c:\program files\PowerStrip 2009-02-06 13:54 . 2009-02-06 13:54 d-------- c:\program files\MonInfo 2009-02-06 13:00 . 2009-02-06 13:00 d-------- c:\program files\TightVNC 2009-02-06 12:30 . 2009-02-06 12:30 d-------- c:\documents and settings\jhs\Application Data\Logitech 2009-02-06 12:30 . 2009-02-06 12:30 d-------- c:\documents and settings\jhs\Application Data\GTek 2009-02-06 12:29 . 2009-02-15 04:20 d-------- c:\documents and settings\jhs 2009-02-06 11:11 . 2009-02-06 11:16 d-------- c:\program files\AirPort . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-16 01:47 --------- d-----w c:\documents and settings\James Stokes\Application Data\nView_Wallpaper 2009-02-15 19:45 --------- d-----w c:\documents and settings\All Users\Application Data\Google Updater 2009-02-15 18:18 --------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-02-15 00:31 --------- d-----w c:\documents and settings\James Stokes\Application Data\EndNote 2009-02-14 21:09 --------- d--h--w c:\documents and settings\James Stokes\Application Data\Move Networks 2009-02-14 20:25 --------- d-----w c:\program files\McAfee 2009-02-12 08:44 --------- d-----w c:\program files\DivX 2009-02-12 08:14 --------- d-----w c:\documents and settings\James Stokes\Application Data\Azureus 2009-01-06 08:15 --------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles 2009-01-06 03:14 --------- d-----w c:\program files\Common Files\AOL 2009-01-06 03:14 --------- d-----w c:\program files\AIM 2009-01-06 03:14 --------- d-----w c:\documents and settings\James Stokes\Application Data\Aim 2009-01-06 03:13 --------- d-----w c:\documents and settings\All Users\Application Data\AOL 2008-12-29 08:14 --------- d-----w c:\program files\Java 2008-12-29 08:10 --------- d-----w c:\program files\Google 2008-12-25 18:09 --------- d-----w c:\program files\SystemRequirementsLab 2008-12-18 23:50 --------- d-----w c:\program files\Intelligen 2008-02-28 02:35 44,360 ----a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll 2008-02-28 02:35 107,928 ----a-w c:\program files\mozilla firefox\plugins\atgpcext.dll 2008-04-24 14:58 122,880 ----a-w c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll 2008-11-12 03:07 88 --sha-r c:\windows\system32\BA8C5A2E66.sys 2008-11-12 03:07 3,350 --sha-w c:\windows\system32\KGyGaAvL.sys 2008-07-01 22:06 32,768 --sha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008070120080702\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232] "Steam"="c:\program files\valve\steam\steam.exe" [2008-10-08 1410296] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-19 68856] "DellSupport"="c:\program files\DellSupport\DSAgnt.exe" [2007-03-15 460784] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "Google Update"="c:\documents and settings\James Stokes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-09-02 133104] "AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-11-12 2356088] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264] "DMXLauncher"="c:\program files\Dell\Media Experience\DMXLauncher.exe" [2005-11-01 94208] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920] "DLA"="c:\windows\System32\DLA\DLACTRLW.EXE" [2005-09-08 122940] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-24 29744] "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2003-10-23 233472] "HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd.exe" [2003-06-25 49152] "HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2005-07-22 176128] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-10-07 13574144] "VolPanel"="c:\program files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" [2006-07-13 122880] "AudioDrvEmulator"="c:\program files\Creative\Shared Files\Module Loader\DLLML.exe" [2005-11-04 49152] "UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 16384] "mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-11-04 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-10-07 86016] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-11-10 136600] "AirPort Base Station Agent"="c:\program files\AirPort\APAgent.exe" [2008-05-20 737280] "SigmatelSysTrayApp"="stsystra.exe" [2005-03-22 c:\windows\stsystra.exe] "Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2005-07-22 c:\windows\KHALMNPR.Exe] "CTHelper"="CTHELPER.EXE" [2006-08-17 c:\windows\CTHELPER.EXE] "CTxfiHlp"="CTXFIHLP.EXE" [2006-08-17 c:\windows\system32\CTXFIHLP.EXE] "nwiz"="nwiz.exe" [2008-10-07 c:\windows\system32\nwiz.exe] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RealUpgradeHelper"="c:\program files\Common Files\Real\Update_OB\upgrdhlp.exe" [2008-10-12 136768] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2006-06-05 24576] Logitech SetPoint.lnk - c:\program files\Logitech\SetPoint\SetPoint.exe [2006-06-07 528384] Run Google Web Accelerator.lnk - c:\program files\Google\Web Accelerator\GoogleWebAccWarden.exe [2007-07-09 1134592] Service Manager.lnk - c:\program files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.wmv3"= c:\progra~1\COMBIN~1\Filters\wmv9vcm.dll "msacm.avis"= ff_acm.acm HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\AirPort\\APAgent.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "5353:UDP"= 5353:UDP:Bonjour "3389:TCP"= 3389:TCP:xpsp2res.dll,-22009 R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-01-15 8944] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-01-15 55024] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-25 206096] R2 PStrip;PSTRIP;c:\windows\system32\drivers\pstrip.sys [2007-07-14 27992] S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2006-06-05 29744] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-01-15 7408] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [2008-04-29 356920] S3 se32;EnTech softEngine;c:\windows\system32\drivers\se32.sys [2007-05-03 12112] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{33220075-2790-11dc-b8cb-00038a000015}] \Shell\AutoRun\command - F:\LaunchU3.exe -a . Contents of the 'Scheduled Tasks' folder 2009-02-14 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] 2009-02-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-914741439-1241626394-3683679332-1006.job - c:\documents and settings\James Stokes\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-09-02 14:54] 2009-01-15 c:\windows\Tasks\McDefragTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32] 2009-02-01 c:\windows\Tasks\McQcTask.job - c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 12:32] . - - - - ORPHANS REMOVED - - - - HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.bat.exe HKCU-Run-BeFree4iPhone - c:\program files\E.W.E.-Software\Befree4iPhone\befree4iphone.exe . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-inc&channel=us uSearchMigratedDefaultURL = hxxp://www.google.com/search?Q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 Trusted Zone: internet Trusted Zone: mcafee.com DPF: Microsoft XML Parser for Java FF - ProfilePath - c:\documents and settings\James Stokes\Application Data\Mozilla\Firefox\Profiles\r1yv8447.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?hl=en FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll FF - plugin: c:\documents and settings\James Stokes\Application Data\Mozilla\Firefox\Profiles\r1yv8447.default\extensions\[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\documents and settings\James Stokes\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npatgpc.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npGoogleGadgetPluginFirefoxWin.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-15 20:49:18 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(700) c:\program files\SUPERAntiSpyware\SASWINLO.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\windows\system32\CTSVCCDA.EXE c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\program files\Java\jre6\bin\jqs.exe c:\progra~1\McAfee\MSC\mcmscsvc.exe c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\CTXFISPI.EXE c:\program files\McAfee\MPF\MpfSrv.exe c:\program files\McAfee\MSK\msksrver.exe c:\program files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe c:\windows\system32\rundll32.exe c:\windows\system32\rundll32.exe c:\windows\system32\nvsvc32.exe c:\windows\system32\HPZipm12.exe c:\program files\Dell Support Center\bin\sprtsvc.exe c:\program files\Common Files\Logitech\KHAL\KHALMNPR.EXE c:\program files\iPod\bin\iPodService.exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon.exe c:\program files\Google\Web Accelerator\GoogleWebAccClient.exe c:\progra~1\McAfee\MSC\mcuimgr.exe . ************************************************************************** . Completion time: 2009-02-15 20:59:25 - machine was rebooted ComboFix-quarantined-files.txt 2009-02-16 01:59:21 Pre-Run: 146,709,557,248 bytes free Post-Run: 146,866,094,080 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 258 --- E O F --- 2009-02-12 08:06:36 Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: c:\windows\system32\byXpnmKD.dll.vir c:\windows\system32\yayvSiGW.dll.vir DirLook:: c:\documents and settings\jhs 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeAttached is the Combofix log. I want to go ahead and thank you for all your help, evilfantasy. [attachment deleted by admin]That looks OK. how is the computer running now?Its running great. Its probably running better than it did before the virus infected it. Thanks again. Sounds good. Cleanup steps.
. The above procedure will:
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before. For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running SMOOTH. |
|
| 953. |
Solve : spyware or malware help?? |
|
Answer» O22 - SharedTaskScheduler: causes - {0fe36c74-667b-454b-828e-75e4e72cbef8} - (no file) thats from hijack this log.
Extra Note: If MBAM encounters a file that is difficult to remove, you will be PRESENTED with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. Scan done and the report. Malwarebytes' Anti-Malware 1.34 Database version: 1812 Windows 5.1.2600 Service Pack 3, v.5657 2/27/2009 10:01:21 PM mbam-log-2009-02-27 (22-01-21).txt Scan type: Quick Scan Objects scanned: 75461 Time elapsed: 5 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\ASpyC (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\spywarning.warningbho (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\spywarning.warningbho.1 (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Program Files\ASpyC (Rogue.AntiSpyCheck) -> Quarantined and deleted successfully. Files Infected: (No malicious items detected) Thank You evilfantasy for all your help. Thank you so much. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixthe link you gave me to disable my anit-virus s not workin i have bitdefender total security 2009. the steps they gave to temporarily disable them is not workin. i dont see virus shield on my program. help Try running ComboFix anyway. Just allow it to run if BitDefender tries to stop it.is this a anti-virus program Bitdefender Total Security 2009 there you go. ComboFix 09-02-27.02 - Administrator 2009-02-27 22:42:30.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.636 [GMT -5:00] Running from: c:\documents and settings\Administrator\Desktop\ComboFix.exe AV: BitDefender Antivirus *On-access scanning disabled* (Updated) FW: BitDefender Firewall *disabled* * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\vlc-0.9.4-win32.exe c:\documents and settings\All Users\Application Data\vlc-0.9.6-win32.exe c:\windows\system32\winio.dll . ((((((((((((((((((((((((( Files Created from 2009-01-28 to 2009-02-28 ))))))))))))))))))))))))))))))) . 2009-02-27 22:41 . 2009-02-27 22:41 731 --a--c--- c:\windows\system32\BDUpdateV1.xml 2009-02-27 21:54 . 2009-02-27 21:54 d----c--- c:\program files\Malwarebytes' Anti-Malware 2009-02-27 21:54 . 2009-02-27 21:54 d----c--- c:\documents and settings\All Users\Application Data\Malwarebytes 2009-02-27 21:54 . 2009-02-27 21:54 d----c--- c:\documents and settings\Administrator\Application Data\Malwarebytes 2009-02-27 21:54 . 2009-02-11 10:19 38,496 --a--c--- c:\windows\system32\drivers\mbamswissarmy.sys 2009-02-27 21:54 . 2009-02-11 10:19 15,504 --a--c--- c:\windows\system32\drivers\mbam.sys 2009-02-25 09:53 . 2009-02-25 09:53 d----c--- c:\program files\Trend Micro 2009-02-24 23:57 . 2009-02-24 23:57 d----c--- c:\documents and settings\All Users\Application Data\Kaspersky Lab Setup Files 2009-02-19 09:58 . 2009-02-19 10:01 d----c--- c:\program files\RegCure 2009-02-19 09:39 . 2009-02-22 19:02 d----c--- c:\program files\Security Task Manager 2009-02-19 09:39 . 2009-02-19 09:49 d----c--- c:\documents and settings\All Users\Application Data\SecTaskMan 2009-02-16 00:14 . 2009-02-16 00:17 d----c--- c:\documents and settings\Administrator\Application Data\ErrorFix 2009-02-16 00:06 . 2009-02-16 00:06 23,392 --a--c--- c:\windows\system32\nscompat.tlb 2009-02-16 00:06 . 2009-02-16 00:06 16,832 --a--c--- c:\windows\system32\amcompat.tlb 2009-02-14 19:16 . 2009-02-14 19:16 d----c--- c:\documents and settings\Administrator\Application Data\Xilisoft Corporation 2009-02-14 19:15 . 2009-02-14 19:15 d----c--- c:\program files\Xilisoft 2009-02-14 17:52 . 2009-02-14 17:52 d----c--- c:\documents and settings\Guest\Application Data\Windows Desktop Search 2009-02-14 17:52 . 2009-02-14 17:52 d----c--- c:\documents and settings\Guest\Application Data\BitDefender 2009-02-12 13:50 . 2006-10-26 19:56 32,592 --a--c--- c:\windows\system32\msonpmon.dll 2009-02-12 13:47 . 2009-02-12 13:47 d----c--- c:\program files\Microsoft Works 2009-02-12 13:46 . 2009-02-12 13:46 d----c--- c:\program files\MSBuild 2009-02-12 13:43 . 2009-02-12 13:43 d----c--- c:\program files\Microsoft.NET 2009-02-12 13:40 . 2009-02-12 13:40 d----c--- c:\program files\Microsoft Visual Studio 8 2009-02-12 13:39 . 2009-02-12 13:45 d----c--- c:\windows\SHELLNEW 2009-02-12 13:38 . 2009-02-12 13:51 d----c--- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-02-12 13:37 . 2009-02-12 13:37 dr-h-c--- C:\MSOCache 2009-02-12 13:25 . 2009-02-12 13:25 d----c--- C:\ConverterOutput 2009-02-12 13:24 . 2009-02-12 13:24 d----c--- c:\program files\Cucusoft 2009-02-12 13:24 . 2007-03-25 00:51 3,049,984 --a--c--- c:\windows\system32\libavcodec.dll 2009-02-12 13:24 . 2007-03-25 21:40 2,174,976 --a--c--- c:\windows\system32\ffdshow.ax 2009-02-12 13:24 . 2007-03-25 00:51 404,480 --a--c--- c:\windows\system32\libmplayer.dll 2009-02-12 13:24 . 2007-01-01 05:30 200,704 --a--c--- c:\windows\system32\TomsMoComp_ff.dll 2009-02-12 13:24 . 2006-07-08 04:07 114,688 --a--c--- c:\windows\system32\PropListCtrl.ocx 2009-02-12 13:24 . 2007-03-25 00:51 114,688 --a--c--- c:\windows\system32\libmpeg2_ff.dll 2009-02-12 13:24 . 2004-09-10 13:50 34,820 --a--c--- c:\windows\system32\ffdshow.reg 2009-02-12 09:43 . 2009-02-24 15:19 d----c--- c:\program files\PeerGuardian2 2009-02-11 16:38 . 2009-02-27 22:42 121 --a--c--- c:\windows\bdagent.INI 2009-02-11 16:37 . 2009-02-11 16:37 d----c--- c:\documents and settings\Administrator\Application Data\Windows Search 2009-02-11 16:34 . 2009-02-11 16:34 d----c--- c:\windows\system32\GroupPolicy 2009-02-11 16:34 . 2009-02-11 16:34 d----c--- c:\program files\Windows Desktop Search 2009-02-11 16:34 . 2009-02-11 16:34 d----c--- c:\documents and settings\Administrator\Application Data\Windows Desktop Search 2009-02-11 16:32 . 2009-02-16 00:04 d----c--- c:\program files\Windows Media Connect 2 2009-02-11 16:30 . 2009-02-11 16:31 d----c--- c:\windows\system32\drivers\UMDF 2009-02-11 16:15 . 2009-02-11 16:15 850 --a--c--- c:\windows\system32\ProductTweaks.xml 2009-02-11 16:15 . 2009-02-11 16:15 385 --a--c--- c:\windows\system32\user_gensett.xml 2009-02-11 16:04 . 2009-02-27 22:41 81,984 --a--c--- c:\windows\system32\bdod.bin 2009-02-11 15:59 . 2009-02-11 15:59 d----c--- c:\windows\system32\logs 2009-02-11 15:59 . 2009-02-11 15:59 d----c--- c:\program files\BitDefender 2009-02-11 15:59 . 2009-02-11 16:02 d----c--- c:\documents and settings\All Users\Application Data\BitDefender 2009-02-11 15:59 . 2009-02-11 15:59 d----c--- c:\documents and settings\Administrator\Application Data\BitDefender 2009-02-11 15:59 . 2009-02-11 15:59 d----c--- C:\Binaries 2009-02-11 15:57 . 2009-02-11 15:57 d----c--- c:\windows\system32\URTTemp 2009-02-11 15:50 . 2009-02-11 15:59 d----c--- c:\program files\Common Files\BitDefender . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-02-28 02:40 --------- dc----w c:\program files\lg_fwupdate 2009-02-27 19:28 --------- dc----w c:\documents and settings\Administrator\Application Data\uTorrent 2009-02-25 05:11 --------- dc----w c:\program files\LimeWire 2009-02-14 23:52 --------- dc----w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-02-13 04:10 --------- dc----w c:\program files\7-Zip 2009-02-12 14:33 --------- dc----w c:\documents and settings\All Users\Application Data\WinZip 2009-02-11 21:04 104,328 -c--a-w c:\windows\system32\drivers\bdfndisf.sys 2009-01-25 20:56 --------- dc----w c:\documents and settings\Administrator\Application Data\Apple Computer 2009-01-23 21:30 --------- dc----w c:\program files\Apple Software Update 2009-01-23 21:30 --------- dc----w c:\documents and settings\All Users\Application Data\Apple 2009-01-20 16:13 --------- dc----w c:\program files\DivX 2009-01-14 19:42 --------- dc----w c:\program files\CDisplay 2009-01-07 19:48 --------- dc----w c:\documents and settings\All Users\Application Data\ATI MMC 2009-01-07 06:44 --------- dc----w c:\documents and settings\Administrator\Application Data\vlc 2008-12-20 23:15 826,368 -c--a-w c:\windows\system32\wininet.dll 2008-12-18 16:48 410,984 -c--a-w c:\windows\system32\deploytk.dll 2008-12-11 00:33 86,016 -c--a-w c:\windows\system32\dpl100.dll 2008-12-11 00:33 200,704 -c--a-w c:\windows\system32\dtu100.dll 2008-12-09 02:28 593,920 -c--a-w c:\windows\system32\dpuGUI11.dll 2008-12-09 02:28 57,344 -c--a-w c:\windows\system32\dpv11.dll 2008-12-09 02:28 344,064 -c--a-w c:\windows\system32\dpus11.dll 2008-12-09 02:28 294,912 -c--a-w c:\windows\system32\dpu11.dll 2008-10-05 19:53 22,328 -c--a-w c:\documents and settings\Administrator\Application Data\PnkBstrK.sys 2004-10-01 19:00 40,960 -c--a-w c:\program files\Uninstall_CDS.exe 2002-05-28 12:19 61,440 -c--a-w c:\windows\inf\i386\onetUSD.dll 2002-05-20 12:22 36,864 -c--a-w c:\windows\inf\i386\Vizmicro.dll 2002-05-20 12:20 172,032 -c--a-w c:\windows\inf\i386\viceo.dll 2002-05-20 12:02 225,280 -c--a-w c:\windows\inf\i386\rtscan.dll 2001-08-03 22:29 13,824 -c--a-w c:\windows\inf\i386\Usbscan.sys 2008-12-16 22:52 61,440 -c--a-w c:\program files\mozilla firefox\components\FFComm.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ATI Launchpad"="c:\program files\ATI Multimedia\main\launchpd.exe" [2004-06-15 106571] "ATI Remote Control"="c:\program files\ATI Multimedia\RemCtrl\ATIRW.exe" [2004-04-16 196608] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2007-12-01 15360] "Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-02-04 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-01-23 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976] "ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-07-10 339968] "ATI DeviceDetect"="c:\program files\ATI Multimedia\main\ATIDtct.EXE" [2004-06-15 69705] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-18 136600] "type32"="c:\program files\Microsoft IntelliType Pro\type32.exe" [2004-06-03 172032] "RemoteControl"="c:\program files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" [2004-11-02 32768] "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-08 1397760] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2008-12-29 548864] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-07-28 185896] "OneTouch Monitor"="c:\program files\Visioneer OneTouch\OneTouchMon.exe" [2002-05-28 86016] "BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2009-01-09 741376] "BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-10-17 69632] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 31016] "SoundMan"="SOUNDMAN.EXE" [2005-04-15 c:\windows\SOUNDMAN.EXE] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Supero Doctor III Client.lnk - c:\program files\SUPERMICRO\SDIII\SuperoDoctor.exe [2008-07-23 397312] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-05-26 123904] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2008-05-26 304128] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.ffds"= c:\progra~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, credssp.dll, msnsspc.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableUnicastResponsesToMulticastBroad cast"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\WINDOWS\\system32\\PnkBstrA.exe"= "c:\\WINDOWS\\system32\\PnkBstrB.exe"= "c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"= "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"= "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"= R1 ISAIONT;ISAIONT;c:\windows\system32\drivers\IsaIoNt.sys [2008-07-23 3853] R1 MemMapNt;MemMapNt;c:\windows\system32\drivers\memmapnt.sys [2008-07-23 3908] R1 SMBus;SMBus;c:\windows\system32\drivers\smbus.sys [2008-07-23 10112] R1 superbmc;superbmc;c:\windows\system32\drivers\SUPERBMC.SYS [2008-07-23 14169] R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-10-06 82696] R2 SuperMicro Health Assistant;SuperMicro Health Assistant;c:\program files\SUPERMICRO\SDIII\NTService.exe [2008-07-23 131072] R2 Supero SD3Service Daemon;Supero SD3Service Daemon;c:\windows\system32\SD3Service.exe [2008-07-23 40960] R2 Xitami;Xitami Web Server;c:\program files\SUPERMICRO\SDIII\xitami\xiwinnt.exe [2008-07-23 552960] R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-09-18 111112] R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-10-17 104328] S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784] S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-09-18 33752] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bdx REG_MULTI_SZ scan . Contents of the 'Scheduled Tasks' folder 2009-01-23 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34] 2009-02-27 c:\windows\Tasks\ErrorFix Scan.job - c:\program files\ErrorFix\ErrorFix.exe [] 2009-02-27 c:\windows\Tasks\ErrorFix Scan.job - c:\program files\ErrorFix [] 2009-02-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-606747145-790525478-1417001333-500.job - c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-02-04 00:32] 2009-02-28 c:\windows\Tasks\RegCure Program Check.job - c:\program files\RegCure\RegCure.exe [2009-02-13 23:20] 2009-02-26 c:\windows\Tasks\RegCure.job - c:\program files\RegCure\RegCure.exe [2009-02-13 23:20] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/ uInternet Connection Wizard,ShellNext = iexplore IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\ig28otl2.default\ FF - prefs.js: browser.startup.homepage - ww.google.com FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-27 22:44:53 Windows 5.1.2600 Service Pack 3, v.5657 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_USERS\Administrator\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:8e,2e,5c,88,69,c3,a3,16,8f,2c,e2,70,9e,01,5e,ac,72,c1,33,82,c8,53,62, df,5f,bc,e7,90,01,a3,5c,79,9e,f3,19,4a,c6,b7,2e,18,4b,6d,fd,df,a4,3c,c4,2c,\ "??"=hex:0f,48,1a,76,ce,fe,3d,eb,b8,9e,e1,3e,48,7b,fe,fd . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(1008) c:\windows\system32\Ati2evxx.dll . Completion time: 2009-02-27 22:46:56 ComboFix-quarantined-files.txt 2009-02-28 03:46:42 Pre-Run: 105,960,312,832 bytes free Post-Run: 106,018,836,480 bytes free 220 --- E O F --- 2009-02-27 05:01:06
How is the computer running now? my firefox is still slow loadin up when i click on it. i dont feel anything different still the same. dont know what you mean. i do another hijack this and post the log up again. dude thanks for all your help. i will recommend you to others. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:05:47 PM, on 2/27/2009 Platform: Windows XP SP3, v.5657 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16791) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Ahead\InCD\InCDsrv.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\ATI Multimedia\main\ATIDtct.EXE C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Microsoft IntelliType Pro\type32.exe C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe C:\Program Files\Ahead\InCD\InCD.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe C:\WINDOWS\system32\ctfmon.exe C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\SUPERMICRO\SDIII\NTService.exe C:\WINDOWS\system32\SD3Service.exe C:\WINDOWS\system32\WinVNC.exe C:\WINDOWS\system32\SearchIndexer.exe C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file) O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [LGODDFU] "C:\Program Files\lg_fwupdate\fwupdate.exe" blrun O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [OneTouch Monitor] C:\Program Files\Visioneer OneTouch\OneTouchMon.exe O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe" O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe" O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" O4 - HKCU\..\Run: [ATI Launchpad] "C:\Program Files\ATI Multimedia\main\launchpd.exe" O4 - HKCU\..\Run: [ATI Remote Control] C:\Program Files\ATI Multimedia\RemCtrl\ATIRW.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c O4 - Global Startup: Supero Doctor III Client.lnk = C:\Program Files\SUPERMICRO\SDIII\SuperoDoctor.exe O4 - Global Startup: Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab O16 - DPF: {9BDF4724-10AA-43D5-BD15-AEA0D2287303} (MSN Games – Texas Holdem Poker) - http://zone.msn.com/bingame/zpagames/zpa_txhe.cab79352.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe O23 - Service: SuperMicro Health Assistant - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\NTService.exe O23 - Service: Supero SD3Service Daemon - Unknown owner - C:\WINDOWS\system32\SD3Service.exe O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe O23 - Service: TridiaVNC Server (winvnc) - Tridia Corporation - C:\WINDOWS\system32\WinVNC.exe O23 - Service: Xitami Web Server (Xitami) - Unknown owner - C:\Program Files\SUPERMICRO\SDIII\Xitami\xiwinnt.exe -- End of file - 9216 bytes i found a way to disable the anitvirus and firewall. once you the icon on right top corner it will say switch to advanced view. another window pop up and left side of screen you will see a list and anti-virus and firewall is on the list. once you click on them you will see disable and your done. you can reword and put in link you gave for people who has latest bitdefender. Have HijackThis fix this entry: O2 - BHO: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - (no file) Close all browsers before clicking Fix checked. -- Do you mean when you first start Firefox? If so then that's how it is. Mine takes a while to open when it first starts also. |
|
| 954. |
Solve : okay, so I've used the combofix...? |
|
Answer» So I USED the combfix to get rid of the crap that got on my computer. |
|
| 955. |
Solve : Can't uninstall all of program? |
|
Answer» I tried updating my antivirus program and wasn't able to CONNECT to the internet. After several attempts to find the cause, I decided to UNINSTALL and reinstall the program. After re-installing The same thing happened. I uninstalled again, but could not uninstall the firewall portion of the program. The anti virus program is CA Internet Security Suite 2007, which is provided by the cable company I have as a server. When trying to uninstall, I get an error message (Error E9011), with a message stating: You do not have sufficient privileges to install or uninstall CA Personal Fiewall. Unable to update registry key: HKEY_LOCAL_MACHINE\SOFTWARE\classes\.efw. |
|
| 956. |
Solve : Vista Firewall? |
|
Answer» Does anyone have any experience with this firewall for Vista?I don't have any experience with it but it gets GOOD reviews. http://www.mywot.com/en/scorecard/sphinx-soft.comTHANKS, Evil. I installed it on laptop and also on my daughter's laptop and appears to work well. I had ZoneAlarm but apparently, it doesn't get along well with Vista. |
|
| 957. |
Solve : further help following your mwsoemon instructions? |
|
Answer» That looks a lot better! |
|
| 958. |
Solve : newbie can't restore OS because of virus(es)? |
|
Answer» Hey all!< |
|
| 959. |
Solve : IE Script Error - opens as a pop-up for many programs? |
|
Answer» Thank GOODNESS!! I was starting to get SORT of stumped. |
|
| 960. |
Solve : Avira Anti-Virus? |
|
Answer» Hello all, |
|
| 961. |
Solve : After deleting virus still get error message.? |
|
Answer» This all HAPPENED when I download VISTA Transformation Pack 9 which was rumored to have Trojans. |
|
| 962. |
Solve : So many problems I'm having, and don't know and having problems understanding? |
|
Answer» I'll try and explain things as best as I can. |
|
| 963. |
Solve : Can a camera memory card catch a viruse?? |
|
Answer» My girl friend took the memory card out of her camera, PUT it in a card reader, and uploaded pictures to a computer. Come to find out the computer had a viruse, can her memory card catch that viruse by just uploading the pictures. Yes. Memory cards are like flash drives and can become infected. Below is a tool to cleanup flash drives, memory cards, cell phones etc.
|
|
| 964. |
Solve : Re: removing a virus? |
|
Answer» HI, You can use SYMANTEC ANTIVIRUS it automatically remove virus. Tech Tiger1Come again?Sorry, I split this from ANOTHER POST and forgot to lock it. |
|
| 965. |
Solve : Desktop Icons Flashing On and Off as well as Taskbar? |
|
Answer» My desktop icons are flashing on and off as well as my taskbar. After reading some of the topics already I have already ran the hijackthis and the results are to follow. Any help is grately appreciated.
---------- Download Malwarebytes' Anti-Malware (MBAM)
|
|
| 966. |
Solve : Trojan, no idea what kind, please help, have scan logs? |
|
Answer» i have an hp computer with windows xp and i was told by norton that it has detected a Trojan last night. my computer shut down unexpectedly a couple of times this morning but now it seems to be staying on, the only other symptoms i have so far is every time i right click on any file or try to drag it SOMEWHERE Data Execution Prevention program shows up and shuts windows explorer down. i can still open the programs its just i can't move them or delete them. i've been running scans with Norton but it doesn't detect anything anymore. i know it can't get rid of it so i was hoping someone might know what i should do. please help. |
|
| 967. |
Solve : viruses in yahoo messenger? |
|
Answer» hi GUYS am DYING please i went online to chat with friends but discovered that ma pc is just sending stupid messages to my friends in a certain language can that be viruses or spyware help please this is the message "open dis natatawata"Download random's system INFORMATION tool (RSIT) by random/random from and save it to your Desktop. |
|
| 968. |
Solve : hijack this file DELETING AUTORUN.ini? |
|
Answer» i have a virus in my USB that my antivi CNT find
---------- Now POST a new HijackThis log please. |
|
| 969. |
Solve : Windows cannot find F:\Windows\eksplorasi.pif? |
|
Answer» Hello
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder...it will help protect your drives from future infection. ---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixHello evilfantasy Many thanks for all your work. I'll try it and post back. I couldn't download the Flash disinfector from your post, but I've downloaded it from elsewhere. Cheers again. SteveHello evilfantasy The .pif error message has now gone and I have run the Flash Disinfector. Many thanks for your advice. I also downloaded ComboFix, saving it to my desktop and disabling my AVG plus other antivirus software, but I get a permission error (Windows cannot find the path). I am not able, therefore, to post the ComboFix log. Many thanks, anyway, for removing the .pif error I was getting! SteveBefore you begin the SDFix instructions you should copy these instructions in a Notepad file and save them to your desktop or print them for easy reference. Much of SDFix will be done in Safe mode and you will be unable to access this web page after booting into Safe mode. Download SDFix by AndyManchesta and save it to your desktop. When using this tool, you must use the Administrator's account or an account with Administrative rights * Now, double-click on the SDFix icon that should now be residing on your desktop. If a Open File - Security Warning box opens, click on the Run button. * A window will now open showing SDFix being extracted into the C:\SDFix folder. * Once the installation program has finished extracting SDFix, it will open a Notepad with further instructions. * DO NOT use it just yet. Reboot your computer in Safe Mode using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode". When your computer has started in safe mode, and you see the desktop, close all open Windows. * Click on the Start button, click on the Run menu option, and type the following text from the Code Box into the Open: field then click the OK button. Code: [Select]C:\SDFix\RunThis.bat * SDFix window will open containing some brief info and a disclaimer on the use of the tool. * Type Y on your keyboard and then press Enter to begin the cleanup process. * It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot. * Press any Key and it will restart the PC. * When the PC restarts, the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons. * Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt. * Copy and paste the contents of the results file Report.txt. Hello evil fantasy Thanks again for your help. This is the log: SDFix: Version 1.240 Run by Steve Higham on 11/02/2009 at 18:42 Microsoft Windows XP [Version 5.1.2600] Running From: F:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : No Trojan Files Found Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-11 18:46:02 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="avgrsstx.dll" "DeviceNotSelectedTimeout"="15" "GDIProcessHandleQuota"=dword:00002710 "Spooler"="yes" "swapdisk"="" "TransmissionRetryTimeout"="90" "USERProcessHandleQuota"=dword:00002710 "LoadAppInit_DLLs"=dword:00000001 scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:xpsp2res.dll,-22019" "F:\\Program Files\\Java\\jdk1.6.0_11\\jre\\bin\\java.exe"="F:\\Program Files\\Java\\jdk1.6.0_11\\jre\\bin\\java.exe:*:Enabled:Java(TM) Platform SE binary" "F:\\Program Files\\AVG\\AVG8\\avgupd.exe"="F:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:xpsp2res.dll,-22019" Remaining Files : Files with Hidden Attributes : Tue 30 Oct 2007 607,744 A..H. --- "F:\Documents and Settings\Steve Higham\Desktop\Windows\~WRL0037.tmp" Sun 20 Apr 2008 20,992 A..H. --- "F:\Documents and Settings\Steve Higham\Desktop\Windows\Systems Administrator\~WRL2174.tmp" Finished! I'm not getting the Window cannot find the 'pif' file any longer and that 'sluggish' feel you get from a computer when it is contaimnated has gone. It looks as if it's all clean now, doesn't it? Cheers SteveYes looks good now. Download OTCleanIt.exe and save it to your Desktop.
---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox. With more than 15,000 improvements, Firefox 3 is faster, safer and smarter than ever before. For Internet Explorer 7 users there is IE7Pro. IE7Pro is a must have add-on for Internet Explorer, which includes a lot of features and tweaks to make your IE friendlier, more useful, more secure and customizable. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 970. |
Solve : Computer problem help plz? |
|
Answer» Hello there,
. The above procedure will:
---------- Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Hello, I had run it 6 times as previously my computer was constantly crashing. Just this week, my computer is now acting worse and it does not allow my Mcafee to run. Does not allow my Firefox to run and I have no internet connection. After I do these instructions What do I do? Use the ESET Online Antivirus Scanner This scanner requires Internet Explorer 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.my computer seems to be restarting itself before it gets a chance to finish the scan. What to do? Also, I think the virus is messing with my programs so that I cannot open them. I had to reinstall internet explorer so that I could use it again. I Think the same thing would go for firefox.Note: This tool will self uninstall when you close it so please save the log before closing it. Download the latest version of the Kaspersky AVP Tool to your desktop. * Reboot your computer into Safe Mode You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter * Double click the setup file to run it. * Click Next to continue. * It will by default install it to your desktop folder.Click Next. * Click OK at the prompt for scanning in Safe Mode. * It will then open a box There will be a tab that says Automatic scan. * Under Automatic scan make sure these are checked. # System Memory # Startup OBJECTS # Disk Boot Sectors. # My Computer. # Also any other drives (Removable that you may have) * Then click on Scan at the to right hand Corner. * It will automatically Neutralize any objects found. * If some objects are left unneutralized then click the button that says Neutralize all * If it says it cannot be Neutralized then choose The delete option when prompted. * After that is done click on the reports button at the bottom and save it to file name it Kas. * Save it somewhere convenient like your desktop and just post only the DETECTED Virus\malware in the report it will be at the very top under Detected post those results in your next reply. Note: This tool will self uninstall when you close it so please save the log before closing it. |
|
| 971. |
Solve : what is tr/crypt.xpack.gen? |
|
Answer» Is it dangerous? Avira found it and (apparently) removed it. The Avira website tells me it is a low THREAT virus capable of minimum damage while this website <Link Removed> tells me it is an extremely dangerous virus.That's a rouge web SITE so I removed the link. See here http://www.mywot.com/en/scorecard/scanforfree.com |
|
| 972. |
Solve : Cannot open programmes from Desktop Icons? |
|
Answer» If I have posted in the wrong location, I apologise. |
|
| 973. |
Solve : Help! (beginner here and unexperieced): redirect virus? |
|
Answer» here is the maximized log: Save space and scrolling, please, make it an attachment... Only attach if specifically requested please Quote from: evilfantasy on January 13, 2009, 03:04:26 PM Quote from: BatchRocks on January 13, 2009, 03:01:50 PMSave space and scrolling, please, make it an attachment... Requested? I thought they always were. Sorry!They were at one time. Now I prefer them inline. Makes Googling EASIER... Download ViewpointKiller.zip
---------- Download the OTMoveIt3 by OldTimer Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator. * Save it to your Desktop. * Double-click OTMoveIt3.exe to run it. * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy) Code: [Select]:Processes explorer.exe :services :reg :files C:\WINDOWS\SET2A.tmp C:\WINDOWS\SET29.tmp C:\WINDOWS\SET8.tmp C:\WINDOWS\SET4.tmp C:\WINDOWS\SET3.tmp :Commands [purity] [emptytemp] [start explorer] [Reboot] * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste. * Click the red Moveit! button. * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply. Close OTMoveIt3 Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway. ---------- How is the computer running now?not any better. i went to yahoo and it still does the redirect thing... here is the moveit log from the last reboot: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== C:\WINDOWS\SET2A.tmp moved successfully. C:\WINDOWS\SET29.tmp moved successfully. C:\WINDOWS\SET8.tmp moved successfully. C:\WINDOWS\SET4.tmp moved successfully. C:\WINDOWS\SET3.tmp moved successfully. ========== COMMANDS ========== File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_UqdM3Z2tpw55gZy5h1xE scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_6d8.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01132009_180725 Files moved on Reboot... File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_UqdM3Z2tpw55gZy5h1xE not found! File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be moved on reboot. File C:\WINDOWS\temp\Perflib_Perfdata_5f8.dat not found! C:\WINDOWS\temp\Perflib_Perfdata_6d8.dat moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_001_ moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_002_ moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_003_ moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\Cache\_CACHE_MAP_ moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\urlclassifier3.sqlite moved successfully. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\rdfw7xfg.default\XUL.mfl moved successfully. This scanner requires Internet Explorer Scan with the BitDefender Online Scanner Click I Agree to the license and then install the ActiveX control. Please DO NOT change the Scanning Options. That will make your logs huge and we don't need to see clean files. Select Start Scan to begin. This scan can take a while so please be patient and let it complete. Once Bitdefender completes the scan: Click-on the Detected Problems tab. Then select Click here to export the scan report This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later) You will have to upload the file online. The forums will not accept HTML. Upload the file to Savefile.com There is no need to Register Select Browse and locate the file. Fill in the Title, Description and security code then click Upload Copy the link next to Your link to the file: and post the link back here.Just a question that I think might actually be important. What site did yahoo redirect to. Please give a complete url(not just the domain name).when i go to bitdefender, it fails when i click on start scan. i was using IE when doing this.Try another scanner please. Run this online scan. This scanner requires Internet Explorer Use the ESET Nod32 Online Scanner 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply. |
|
| 974. |
Solve : advanced systemcare ( advice please )? |
|
Answer» i have had this for a good while and find the UPDATE very good and easy to use |
|
| 975. |
Solve : Help, desktop died...? |
|
Answer» Here's what happened. We use Avaist. The other day, a window came up and said that Avaist was expired and we needed to ENTER a new REGISTRATION code, but Avaist was last installed in Nov., and should have expired yet. Well, sometime between it expired and we reinstalled it, something must have gotten in, because when we rebooted, the boot scan came up and just about every file that it scanned was put in the chest and then it said the chest was full, so we ESCAPED out and rebooted. Now it loads up to the user name/password LOGIN box, you hit ok, and it says loading personal settings, and then immediately LOGS back off to the login box. Does the same thing when trying to load in safe mode and from last good known configuration. |
|
| 976. |
Solve : antivirus 360? |
|
Answer» Help..... Was interupted in the middle of something, and downloaded this 'thing' in error. Now I cnt get rid of it. it WONT let me do anything... and keeps TELLING me i got VIRUS's and things. |
|
| 977. |
Solve : help everytime i open .bat files my pc shut downs!!? |
|
Answer» help everytime i open .BAT FILES my pc shut downs!!do you think its a virus and if i scan it ..it will REMOVE RIGHT? |
|
| 978. |
Solve : NORTON . allow inbound and outbound connections to? |
|
Answer» hello there ALLOW inbound and outbound connections to: |
|
| 979. |
Solve : Norton 2009 unblock virus?? |
|
Answer» I GOT a problem whit norton 2009, im TRYING to get a file but norton class it as a virus, well it is a virus but a virus i need to do a thing. |
|
| 980. |
Solve : Continue to have problems? |
|
Answer» I was here a few weeks ago, and got assistance with my computer and what I believe was spyware and such. However, now just a few weeks later, it is all starting over again. My computer, while on internet, is extremely slow, I have a DSL connection. And it's starting again where I click on certain buttons and it does nothing, just sits there. I've run the SuperAntiSpyware program, and removed the files it said, etc...but it's still so slow. Can someone tell me if I'm going to have to go through this continually now, or what the problem might be? Thanks!Hard to say. Have a friend come to you house with his laptop and see if it is the DSL connection. I've had my isp check that, it's not the connection. It's doing almost exactly what it was before, which is running extremely slow, not navigating to pages when I click on things, even the spyware, malware and virus programs I got here are all messed up, they don't run the scans the same way. One of the things that I thought was really WEIRD is when I am typing, about every 15 characters or so, it'll "miss" the stroke, I GUESS is the only way to put it. I'll be typing and one letter or character will not come through. I don't know how to explain that PART, it's just another one of the weird things happening. Anyone have any ideas here? This is causing major frustration, as I work on my computer from home, and it really slows things down for me. could you run through the malware guides and post the logs; our experts can then look over the logs for you |
|
| 981. |
Solve : Online XP Scanner: DANGER! Virus upgraded and back on the prowl!? |
|
Answer» This is a message to everyone, to watch out for page redirects on google...I was searching for some info on a local air cadet squadron, I clicked a link hoping it had valuable information (hxxp://chavrie.com/include/page.php?p=1126980&f=56 WARNING: EXTREMELY DANGEROUS SITE! GO AT OWN RISK!) and it brought me to, yet another Online XP scanner website... I went there and nothing happened.Currently no. After I heard that there is a major security FLAW, I went to FireFox. I did when I got the virus, although I'm not sure about SpywareAxe, I got Trojan.Vundoo or something like that...IMO the "major security flaw" is that MS didn't surround the execution of ActiveX controls in tight security measures and some form of sandboxing. ActiveX is great for applications, but for web programs/browsers it's a completely stupid application of the technology.For some reason not all hijacked sites "attack" every visitor. We were investigating one and it only launched (antivirus 2009) on 2 of us. Me being one, but I was smart ENOUGH to open the link while Sandboxed. |
|
| 982. |
Solve : I Have Virus(es) on my computer, please assist!? |
|
Answer» Okay, then try this: right-click on the FILE and go to Send To > COMPRESSED (zipped) Folder. That should create a .zip file. You can then attach it to your next post or try uploading it to SaveFile.http://www.savefile.com/files/1961368 |
|
| 983. |
Solve : trojan and new problem that wont come off ); im gonna cry? |
|
Answer» hi i kno that im new here but dont even kno if this is right section for me but am REQUIRING some help on y my computer is acting funny obvoiusly from a virus or trojan but ive delt with this same trogan a aday ago and seems as if it is back i have using many things trying to remove it COMBOFIX avg spybot search destroy and spybot had found it but couldnt remove it becuase it was runing in memory or something but i need help now becuase now i cant deal with this on my own im not sure if the 2 are related thow here is the website it was trying to acess |
|
| 984. |
Solve : Computer...****** completely? |
|
Answer» To be honest, I'm not really seeing much. I only noticed one file that looked suspicious, but I don't even know if it's still on your computer. For the heck of it, CREATE a new CFScript using the text below: |
|
| 985. |
Solve : csrssc.exe virus and random black windows popping up with errors? |
|
Answer» Hi, |
|
| 986. |
Solve : I Got What I Believe is a Trojan and I Need HELP Removing It? |
|
Answer» Below is the SUPERAntiSpyware Scan Log. Also Note, at the end of the scan after I pressed next to continue to allow the program to try and fix or quarantine the selected ITEMS, and immediatly my computer went into a blue screen and displyed the following: TOP: C000021 a {Fatal System Error}Quote SUPERAntiSpyware Scan LogBelow is the Malwarebytes' Anti-Malware log. Afterthis scan and the removal/quarantine of infected items I was told I need to restart my computer. I restarted my computer and as it began to turn off I once again went into a blue screen that displayed the following message again. Quote TOP: C000021 a {Fatal System Error}Quote Malwarebytes' Anti-Malware 1.28What about the other log from HJT?Here is the log from HijackThis Quote Logfile of Trend Micro HijackThis v2.0.2Looks fine but we should do an online scan just to be SURE. That was a large amount of malware and some could still be hiding. Run this online scan. Requires Internet Explorer Use the ESET Nod32 Online Scanner 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Here is the log of the Scan Quote # version=4Next: Set a New Restore Point to prevent possible reinfection from an old one. Please go to: Start -> All Programs -> Accessories -> System Tools -> System Restore -> System Restore Settings Click to add a check mark beside Turn off System Restore and click Apply When you are warned that all existing Restore Points will be deleted, click Yes to continue and wait a few moments to let System Restore clear. Uncheck "Turn off System Restore" Click "Apply," and then click "OK". ---------- Use the Secunia Software Inspector to check for out of date software. Click Start Now Check the box next to Enable thorough system inspection. Click Start Allow the scan to finish and scroll down to see if any updates are needed. Update anything listed. ---------- SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running MOZILLA based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and Spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. Learn more about how to protect yourself while on the Internet from the following link. So how did I get infected in the first place? by Tony Klien. When i start my computer it acts like its going to load and then this fatel systen error comes up that says!!!! STOP: c000021a The session manager Initialization system process Terminated unexpectedly with a status of 0xooooo3a...{0xoooooooo-0xoooooooo}. THE SYSTEM HAS BEEN SHUT DOWN. but also right before that message pops up a screen apears that says {auto check program not found. Skip auto check. then it goes to the fatel system error. If you could help me in any way it would be greatly appriciated. thank you so much laura Laura, you might want to start you own postLesson learn, its better to equipped myself with good anti virus for better protection against malicious program. Any recommendations? I'm using Kasperzky right now Quote from: irvine25 on February 05, 2009, 04:51:00 AM Lesson learn, its better to equipped myself with good anti virus for better protection against malicious program. Any recommendations? I'm using Kasperzky right now This user has Nortan. - Free antivirus software. Remember to install only ONE!
|
|
| 987. |
Solve : I keep getting sysxd.exe error? |
|
Answer» So this only pops up periodically and I have been waiting for like half an hour but it won't COME back up so I can reproduce it but I have seen others on the forum with it. |
|
| 988. |
Solve : Malware infected. Need help? |
|
Answer» Hi experts, |
|
| 989. |
Solve : Panda Active Scan Reads Adware, Hacktools and Trojan? |
|
Answer» Have you tried uninstalling HomeKey? If so, what happened? If you have trouble, you can take a look at this page: |
|
| 990. |
Solve : My computer turns completely off if idle for maybe 20 minutes? |
|
Answer» This never happened before. What would cause this to happen?Make? Model? OS? Hi Eg0Death, |
|
| 991. |
Solve : is ther any thing wrong with my system?? |
|
Answer» hi, good day... |
|
| 992. |
Solve : avast!? |
|
Answer» Hey, everyone I have a question. I'm running Windows XP, and I have use avast! 4.7 for my antivirus software. I haven't had any problems with VIRUSES since I switched from MCAFEE. I was just wondering, how GOOD is avast! at keeping viruses out and detecting them in scans? And how is the spyware protection, if there is any at all?Avast! is very reliable for protection. |
|
| 993. |
Solve : Spyware & Viruses, Trying to clean out, Can you help please. :-)? |
|
Answer» My apology for not providing all of the scan results that I should have included with my first post as requested by your forum. This is what has been going on with this computer.... |
|
| 994. |
Solve : Help with system32 in a way? |
|
Answer» Hello. Me and my friend are tying to see which one of us can get each OTHERS pw's first lol ik it is probably a stupid and childish thing to do but here is how it goes. We each get an hour a day on each others strictly limited guest ACCOUNT we are not allowed to USE the admin account on the comp. the point is to get the pw not mess with each others files. |
|
| 995. |
Solve : My HJT file as requested by evil fantasy? |
|
Answer» Here it is. Thanks |
|
| 996. |
Solve : pls check my laptop? |
|
Answer» here are the 3 logs, |
|
| 997. |
Solve : Please help!Computer won't start in normal mode after Trojan's cleaned in Safe? |
|
Answer» Hi All, |
|
| 998. |
Solve : heres my HJT log as requested broni? |
|
Answer» Logfile of Trend MICRO HijackThis v2.0.2 |
|
| 999. |
Solve : What are spr.exe files? Is that a virus or worm?? |
|
Answer» I have found several spr.exe FILES in my local settings, temp folder. My computer performance is slower than it used to be, and I found these files in an ATTEMPT to clean up the C drive. |
|
| 1000. |
Solve : firewall help!!!!? |
|
Answer» comodo is using a whole core! what should i do?? am i being hacked???it appears to be normal now must be the program i was installingUmm....What? never mind dont worry about itHeh, ok. Quote it appears to be normal now must be the program i was installing Why would you think you're being hacked? CAUSE it was using all of one coreSo? Why ELSE is the processor there?i dont no The two cores are there to relieve stress. One core can focus on installing the program and the other core will manage everything else (background processes and PROGRAMS)Nicely stated, Carbon! This is what I was trying to GET you to realize, cr ya but it was using the WHOLE core and inever saw it doing that before so i was just woried that mabye it needed more cpu to keep out a hacker or soemthing LIKE that or maybe your just paranoid?most likley |
|