InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 1251. |
Solve : Wierd virus? |
|
Answer» i saved a hijack this file so im going to copy and paste that but when i boot my computer the bottom taskbar is locked in the hidden position (windows xp sp3), also the internet sends me to a belkin hotel login screen, finally besides other problems i cannot drag and drop or open malwarebytes i hav kav 2010 and it cannot find anything.
also i dont know if i had mentioned before that malwarebytes will not open here is the error "Run-time error '372': failed to load control 'vbalsGrid' form vbalgrind6.ocx. Your version of vbalsgrind6.osx may be outdated. Make sure you are using the latest version of the control that was provided with your application. " exeHelper by Raktor Build 20091220 Run at 17:32:46 on 03/23/10 Now searching... Checking for numerical processes... Checking for sysguard processes... Checking for bad processes... Checking for bad files... Checking for bad registry entries... Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values... Resetting policies... --Finished-- This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Ran as Owner on 03/23/2010 at 17:31:19. Processes terminated by Rkill or while it was running: Rkill completed on 03/23/2010 at 17:31:25. im stumped Ok. Let's try this. Please download ComboFix from BleepingComputer.com Alternate link: GeeksToGo.com Alternate link: Forospyware.com Rename ComboFix.exe to commy.exe before you save it to your Desktop Important:. Rename it before you save it to your flashdrive.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
what i found that was odd is they were not found under the combofx folder but a folder c:\qoobox (i didnot create this file) first is the last time ran : ComboFix 10-03-14.04 - Owner 03/14/2010 22:30:07.1.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.958.559 [GMT -4:00] Running from: c:\documents and settings\Owner\Desktop\Combofx.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\Owner\LOCALS~1\Temp\install_flash_player.exe c:\program files\Cheat Engine\dbk32.sys c:\recycler\S-1-5-21-2557824024-1178833378-110756417-500 . ((((((((((((((((((((((((( Files Created from 2010-02-15 to 2010-03-15 ))))))))))))))))))))))))))))))) . 2010-03-11 04:20 . 2010-03-11 04:59 -------- d-----w- c:\documents and settings\Owner\Application Data\Apple Computer 2010-03-11 04:20 . 2009-05-18 19:17 26600 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2010-03-11 04:20 . 2008-04-17 18:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2010-03-11 04:19 . 2010-03-11 04:19 -------- d-----w- c:\program files\iPod 2010-03-11 04:18 . 2010-03-11 04:20 -------- d-----w- c:\program files\iTunes 2010-03-11 04:18 . 2010-03-11 04:20 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD} 2010-03-11 04:18 . 2010-03-11 04:18 -------- d-----w- c:\program files\Bonjour 2010-03-11 04:17 . 2010-03-11 04:18 -------- d-----w- c:\program files\QuickTime 2010-03-11 04:17 . 2010-03-11 04:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer 2010-03-11 04:17 . 2010-03-11 04:17 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Apple 2010-03-11 04:17 . 2010-03-11 04:17 -------- d-----w- c:\program files\Apple Software Update 2010-03-11 04:17 . 2009-08-29 00:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys 2010-03-11 04:17 . 2009-08-29 00:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll 2010-03-11 04:16 . 2010-03-11 04:22 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple 2010-03-11 04:16 . 2010-03-11 04:19 -------- d-----w- c:\program files\Common Files\Apple 2010-03-11 04:01 . 2009-10-23 15:28 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe 2010-03-04 04:29 . 2010-03-11 05:05 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Apple Computer 2010-02-18 03:45 . 2010-02-18 03:45 -------- d-----w- c:\program files\YouTube Downloader 2010-02-18 03:43 . 2010-02-18 03:43 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\TubeTilla 2010-02-18 03:10 . 2010-02-18 03:11 -------- d-----w- c:\documents and settings\Owner\Application Data\ManyCam 2010-02-18 03:10 . 2010-02-18 03:11 -------- d-----w- c:\program files\ManyCam 2.4 2010-02-15 23:41 . 2010-02-15 23:41 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-03-15 02:33 . 2010-02-04 04:16 -------- d-----w- c:\program files\Cheat Engine 2010-03-15 02:24 . 2009-12-16 02:52 -------- d-----w- c:\documents and settings\Owner\Application Data\uTorrent 2010-03-15 01:05 . 2009-12-17 04:37 -------- d-----w- c:\program files\PeerGuardian2 2010-03-13 17:27 . 2009-12-16 02:52 -------- d-----w- c:\program files\uTorrent 2010-02-24 14:16 . 2009-10-04 03:55 181632 ------w- c:\windows\system32\MpSigStub.exe 2009-12-31 16:50 . 2006-06-17 09:23 353792 ----a-w- c:\windows\system32\drivers\srv.sys 2009-12-22 05:21 . 2006-06-17 09:23 667136 ----a-w- c:\windows\system32\wininet.dll 2009-12-22 05:20 . 2006-06-17 09:23 81920 ----a-w- c:\windows\system32\ieencode.dll 2009-12-17 04:32 . 2009-12-17 04:32 411368 ----a-w- c:\windows\system32\deploytk.dll 2009-12-17 04:31 . 2009-12-17 04:31 152576 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2009-12-17 04:31 . 2009-12-17 04:31 79488 ----a-w- c:\documents and settings\Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2009-12-16 18:43 . 2006-06-17 09:35 343040 ----a-w- c:\windows\system32\mspaint.exe 2009-12-16 13:35 . 2009-12-16 13:35 128 ----a-w- c:\documents and settings\Owner\Local Settings\Application Data\fusioncache.dat 2009-12-16 05:16 . 2009-09-19 02:14 4844296 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Power2GoExpress"="NA" [X] "Google Update"="c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-19 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray"="c:\windows\ehome\ehtray.exe" [2005-08-06 64512] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-07-21 61440] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-17 149280] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] ="Service" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search] 2009-09-01 02:57 169984 ----a-w- c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update] 2009-09-19 02:44 133104 ----atw- c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2010-02-15 23:07 141608 ----a-w- c:\program files\iTunes\iTunesHelper.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] 2009-07-26 20:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "PrismXL"=2 (0x2) "WMPNetworkSvc"=3 (0x3) "WinDefend"=2 (0x2) "ose"=3 (0x3) "JavaQuickStarterService"=2 (0x2) "iPod Service"=3 (0x3) "idsvc"=3 (0x3) "Bonjour Service"=2 (0x2) "ATI Smart"=2 (0x2) "Ati HotKey Poller"=2 (0x2) "Apple Mobile Device"=2 (0x2) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\AIM\\aim.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\WINDOWS\\system32\\sessmgr.exe"= "c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"= "c:\\WINDOWS\\system32\\dpvsetup.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= R2 SBKUPNT;SBKUPNT;c:\windows\system32\drivers\SBKUPNT.SYS [9/20/2009 11:20 PM 14976] R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [8/31/2009 10:26 PM 200576] R3 ManyCam;ManyCam Virtual Webcam, WDM Video Capture Driver;c:\windows\system32\drivers\ManyCam.sys [1/14/2008 6:06 AM 21632] R4 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] --- Other Services/Drivers In Memory --- *Deregistered* - pgfilter . Contents of the 'Scheduled Tasks' folder 2010-03-11 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34] 2010-03-14 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1861525334-4237561970-3360464881-1006Core.job - c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-19 02:44] 2010-03-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1861525334-4237561970-3360464881-1006UA.job - c:\documents and settings\Owner\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-19 02:44] 2009-09-19 c:\windows\Tasks\ISP signup reminder 3.job - c:\windows\system32\OOBE\oobebaln.exe [2006-06-17 00:12] 2010-03-14 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/keyword/%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-03-14 22:33 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(672) c:\windows\system32\Ati2evxx.dll . Completion time: 2010-03-14 22:35:18 ComboFix-quarantined-files.txt 2010-03-15 02:35 Pre-Run: 72,925,417,472 bytes free Post-Run: 73,000,374,272 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect /usepmtimer - - End Of File - - 0C6092FE8EC49C9F9B91E6ECF76B3941 next is the add/remove programs file?: µTorrent 7-Zip 4.65 [email protected] ISO Burner Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin AIM 7 Apple Application Support Apple Mobile Device Support Apple Software Update ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver ATITool Overclocking Utility Bonjour Catalyst Control Center - Branding Catalyst Control Center Core Implementation Catalyst Control Center Graphics Full Existing Catalyst Control Center Graphics Full New Catalyst Control Center Graphics Light Catalyst Control Center Graphics Previews Common Catalyst Control Center HydraVision Full Catalyst Control Center Localization All ccc-core-preinstall ccc-core-static ccc-utility CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Cheat Engine 5.5 CompuApps SwissKnife V3 Conexant AC-Link Audio DV TS DVD Solution EVEREST Home Edition v2.20 Google Chrome Google Desktop Google Toolbar for Internet Explorer HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB932716-v2) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) ImTOO MPEG Encoder Platinum iTunes Java(TM) 6 Update 17 Kaspersky Anti-Virus 2010 Malwarebytes' Anti-Malware ManyCam 2.4 (remove only) Media Player Codec Pack 3.9.1 Microsoft .NET Framework 1.0 Hotfix (KB953295) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft CHOICE Guard Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Standard Edition 2003 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries MSVCRT MSXML 6 Service Pack 2 (KB954459) PeerGuardian 2.0 Power2Go 4.0 PowerDVD QuickTime Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956744) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371-v2) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972260) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974455) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB976325) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) Segoe UI Skins Soft Data Fax Modem with SmartCP Sonic Encoders Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Windows Media Player 10 (KB910393) Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB951978) Update for Windows XP (KB953356) Update for Windows XP (KB955759) Update for Windows XP (KB961503) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) Update for Windows XP (KB976749) Update for Windows XP (KB978207) Update ROLLUP 2 for Windows XP Media Center Edition 2005 WebFldrs XP Windows 7 USB/DVD Download Tool Windows Driver Package - Advanced Micro Devices (AmdK8) Processor (05/27/2006 1.3.2.0) Windows Genuine Advantage Validation Tool (KB892130) Windows Imaging Component Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Messenger Windows Live Sign-in Assistant Windows Live Upload Tool Windows Media Format 11 runtime Windows Media Player 11 Windows XP Media Center Edition 2005 KB925766 Windows XP Media Center Edition 2005 KB973768 Windows XP Service Pack 3 WinRAR archiver YouTube Downloader 2.5.3 finally is the quarantined file 2010-03-15 02:32:54 . 2010-03-17 06:59:07 6,608 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2010-03-15 02:25:31 . 2010-03-17 06:53:58 255 ----a-w- C:\Qoobox\Quarantine\catchme.log 2010-02-04 04:33:10 . 2009-01-27 23:43:54 36,096 ----a-w- C:\Qoobox\Quarantine\C\Program Files\Cheat Engine\dbk32.sys.vir P2P - I see you have P2P software installed on your machine. (uTorrent) We are not here to pass judgment on file-SHARING as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs. ============================================= Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups. Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply. Exit out of MessengerDisable then delete the two files that were put on the desktop. ================================================ ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the Back button then click Finish. In your next reply please include the ESET Online Scan Log ===================== Please let me know how your computer is working now. im not sure if you actually read my previous responses and took them into consideration because i cannot install/remove anything i cant go online i cant do practically anything Ok. Please describe to me what happens when you boot your computer. Are you able to boot in Normal Mode? Do you get to your desktop?. Are other programs running correctly? We know that you have some kind of malware or something I'd say it is malware because of you're computers activity. What you can do is: EDITED. |
|
| 1252. |
Solve : All my folders turned into applications!? |
|
Answer» I'm kind of freaked out with what happened to my Documents folder. I plugged in a USB in my laptop which I used in another computer (which was used by A LOT of people already) earlier, then I opened a folder (in the USB) which was already turned into an application (.exe FILE). I was kinda puzzled at first but I just opened other files on the USB instead. After copying some files to my Documents folder, I noticed that all my other folders in the Documents area were turned into applications as well! I'm guessing I'm infected with some worm or virus, but for the first time I couldn't really FIND a specific solution on the net. I don't even have an idea on what this virus or worm is called. I do hope you GUYS can help me out. |
|
| 1253. |
Solve : Virus freezing computer?? |
|
Answer» I wrote in the windows xp section of the forum that a virus made to look LIKE an antivirus seemed to have DOWNLOADED itself onto my computer and that I tried to DELETE it before anything happened and run a scan, but my computer froze. I was told on the forum to follow the malware guide thing but before I can do anything, my computer freezes. I was then told to ask here. Also, sometimes before the screen to choose the user, it'll do some sort of chkdsk thing for a couple of seconds, but it doesn't seem to do anything. Not only that, but WHENEVER I try going into safe mode it freezes. |
|
| 1254. |
Solve : Got a Virus, now can't install XP from CD drive? |
|
Answer» My Dell PC has a virus. I realized a reinstallation of the OS was the fix, but didn't have the original disk. So I reqeusted one from Dell and they sent one right away, to their credit. So I backed everything up and made a list of all my apps to reinstall and set about to try to boot from the disk. |
|
| 1255. |
Solve : command view? |
|
Answer» how can juse prompt command |
|
| 1256. |
Solve : HELP!...MSLS5L.DLL virus/spyware has infected my computer !? |
|
Answer» Hi, about a week ago today i was playing some music on my computer. I left my library on shuffle and went to do something else so during that time i wasn't using the computer. Suddenly the music began skipping and and stuttering then the screen suddenly went blank the desktop screen was STILL there but no icons or startbar menu was there and teh program I was playing my music on had disappeared. On a whim and without really thinking i turned of the computer by holding the button on/off button on the CPU until the computer shut down and then proceeded to restart. On restarting I was met with an error saying "This application has failed to start because msls51.dll was not found. Reinstalling the application may fix this problem". This appeared several times and i clicked OK to get rid of it and then continued logging on. But again the error box came up for several programs and i was unable to log on. The only thing on the monitor was a blank desktop screen, no icons no menu bar. I was able to get into some programs on my desktop into the C: DRIVE and My documents via the task manager but not through the start button as i couldn't see it. I've been able to use programs like fire fox which I'm on now through task manager but i am very worried it will get worse. I really want to get rid of it I've had this computer for about 4 years now and i don't think i am financially able to get it fixed at a repair shop. Also i do not want to do a complete System re installation as i have alot of ACCUMULATED important files stored on my computer. Could SOMEONE who is able please help me. I am not really good at computers and this virus the first major one I've gotten since i had my computer and it is really scaring me. Thank you much Visio xHello, I am sorry we had to meet under these circumstances, but it is as it is. To ensure you get the best help you possibly can, go here and try to do as much as possible. Hi and me too but ye... thanks for yur referral though i looked at the post but i am unsure as to what to do and where to start from. It seems the post is more genral for any type of virus/malware/spyware etc and not specific to my PARTICULAR one so i'm not too sure if it will work. But thnanks anyways Visio xxvisio, please go back to that link and try to download SAS, MBAM and HJT. If you're successful in downloading them, try running them and send the logs they generate in your next post. Quote from: visio on March 26, 2010, 06:52:52 AM Hi and me too but ye...The scanners are important to the experts (Like SD) so they know what they're dealing with. sorri i replied so late i haven't been using my computer lately im kind of ignoring the problem and using my laptop instead right now i am not on my home computer so i can't do as you suggested bdut i will asap thanks though at least it looks like theres hope Visio xx |
|
| 1257. |
Solve : I need A decent Malware Scanner? |
|
Answer» Ok I have 7 INFECTED files which is A Malware virus, None of the scanners I use can identify them or can't clean them such as |
|
| 1258. |
Solve : Proxy resetting? |
|
Answer» HI, I have a machine that the owner got a malware infected. It was a popup that said pay us to remove it. Anyway the USER got rid of most of it but now when the machine is rebooted the proxy settings change to manual and this makes the internet go down. I tried to run malwarebytes update but it won't let me import the lastest updates. Anyone know of a registry hack or something to stop the change from AUTO configuration to manual? Windows 2000 pro I got it fixed. I set the proxy to auto and DOWNLOADED the latest antivirus update for symantec and ran it. It found a TROJAN and removed it. I then ran the updates for malwarebytes. Its all good. |
|
| 1259. |
Solve : Possible Ave.exe infection, Please HELP!? |
|
Answer» Hello, |
|
| 1260. |
Solve : Google Redirect? |
|
Answer» CLEAN. ty for UR help. My windows login STARTUP is faster You're welcome. |
|
| 1261. |
Solve : After removal of the virus "Rahul'svirusprotection.vbe" getting error message? |
|
Answer» Sir, my data-traveller was somehow affected by the virus "Rahul'svirusprotection.vbe". It was affected somehow. When I scan it with the antivirus "Avira antivirus" it was REMOVED. But a new problem arose. Each time I turn on or restart Windows_xp SHOWS the dialogue, windows script engine error "C:\windows\system32\Rahul'svirusprotection.vbe" could not be found. Now how can I get rid of this bad message ? I also repair my OS in vain. |
|
| 1262. |
Solve : atapi.sys is infected :(? |
|
Answer» okay so i have been doin reasearch and as it apears my atapi file is infected. i really need to get rid of this can ANYONE give me step by step instructions on how to get rid of this virus? i tried making a clean copy, delete the infected one and replace it but i keeps making copies of its self please help me atapi.sys is located in the folder C:\Windows\System32\drivers. file sizes on Windows XP are 95,360 bytes |
|
| 1263. |
Solve : How to Uninstall Antivirus 7?? |
| Answer» ALLAN, I POSTED my logs in the right forum but no one is responding. Am I still doing something wrong? Thanks.Thats really good, your problem have been solved now, i always avoid to download such things which i dont have the complete INFORMATION, this is the only way to KEEP yourself secure from such problem. | |
| 1264. |
Solve : A very huge problem for me? |
|
Answer» Hello Everybody,
Thanks for your suggestion. But instead of doing a long procedure i formatted my xp and reinstalled xp by norton ghost and my problem is solved now. Now no error is coming on my desktop Thanks , |
|
| 1265. |
Solve : backing up of update files? |
|
Answer» Hello |
|
| 1266. |
Solve : Computer is Playing Random Sounds and Music!! Virus?? |
|
Answer» This started about 3 days ago, I was WATCHING YouTube videos, and then suddenly something started playing in the background. I turned off firefox, and all the other things i had open and listened, and it was some random music playing all by itself! I had no program open, and I thought, "MAYBE its nothing..." |
|
| 1267. |
Solve : 15 Trojans in 3 seconds killed my computer, now OS won't load! HELP? |
|
Answer» avira suddenly reported about 10-15 trojan viruses in a few seconds, before I was able to deny them all access I got the blue SCREEN of death and my computer restarted. Now I can't load the OS at all ( yes, that means no safe MODE ... Sorry just came from yahoo answers lol).
Thanks!It lists certain files and other information, that I can analyze and provide a fix. It is worth a shot.Hello, your comment has been removed. Please do not post malware advice, or post here in the malware forum, UNLESS you need help. ~ DragonMaster JayOK so at this point I have managed to fix my computer myself but I didn't REALISE my Windows XP is OEM so now I can't activate it Do you know where I can find a product key that will work?No. Having your original product key is required. There is an option to replace the product key. Contact Microsoft. See here: http://support.microsoft.com/kb/811224 |
|
| 1268. |
Solve : Home Page is Porn Site? |
|
Answer» Whenever i start internet explorer. it pops up with the same porn site! when i go to change it back to default home page (earthlink.net) it works temporarlily but when i restart my computer or have it on for a long period of time, it changes back to the same porn site! please help me find out what the problem is!Cory , several thing COME to mind, first what operating system are you using and exactly how did you reset your home page. maybe you shouldnt look at porn And maybe you should look at the last post date?kizza1645: do not reply to old topics. mroilfield: PM a mod, instead of REPLYING, next time. =>TOPIC CLOSED! |
|
| 1269. |
Solve : HTML script virus. removed. stuck in boot loop.? |
|
Answer» I was browsing the INTERNET yesterday and avira detected TWO virus HTML.webpage script. I selected to delete both. I then did a full scan with avira, and mbam, and super antispyware. they came up clean so I rebooted. I got to the windows loading screen with the bar moving across, then my computer restarted. I booted up in safe mode, ran the scans again. ran CC cleaner. I then restarted again and it rebooted itself. I booted to safemode and did a system restore to april 1st. Restarted. tried to boot normaly and it rebooted again. I booted to safemode and it said the restore was COMPLETE, so I tried restarting and booting normaly; it didn't work. I attempted to boot to safe mode again and dialogue poped up to the effect of:'Windows can not continue because you have not activated windows; please boot in normal mode to activate windows' It was several months AGO that I activated my copy of windows. I know the restore point was after that. |
|
| 1270. |
Solve : Cant boot of the secondary hard drive? |
|
Answer» i installed windows 7 on a 2nd hard drive from the 1ST hard drive. which means me downloading a COPY of windows 7 the making it into a virtual drive and installing it from my first hard drive to the second hard drive. |
|
| 1271. |
Solve : Antispyware Vista?? |
|
Answer» I'm SURE that this is a virus and I need help getting rid of it. I keep having popups on my sidebar asking me to download this software to help my computer get rid of SUPPOSED trojans and keyloggers and a list of trojans and viruses popup in a supposed "scan result" and it tells me to get the software to save my computer. OBVIOUSLY its a trap. I have AVG scanning my whole computer at the moment but no sign of it so far. Also, I've tried downloading Malwarebytes but when I can't seem to download it. What should I do? What should you do? Hmmm... Hi slipknotthe9, go to this link Read this before requesting malware removal help and FOLLOW the steps. |
|
| 1272. |
Solve : is reinstalling recommened, on occasion ?? |
|
Answer» I was just wondering if it's a good idea to reinstall every now and then, to make sure there are no viruses in your system. I have systems that are 8 years old. I've never reinstalled an OS ever unless a system crashed and there was no backup available. I've never understood people who do this. And it depends on the av - if it's good, if you scan on a regular basis with the av and MalwareBytes you should be fine. But you shouldn't be doing things that are likely to "attract" malware in the first place. 26 years and DOZENS of systems later - I've never had any virus on any of them. Same here, PRETTY much. Except for once, the only time I've "re-installed" was actually for new builds/computers. The one exception was when I managed to get infected with a strain of Virut/Sality. OF course using an AV at the time wouldn't have helped since it wasn't detected by any of them, except the one specifically designed to remove it, which didn't work anyway. That was a toughie, but otherwise it was pretty easy to remove. reinstall C:, and then delete all the EXE,DLL, OCX, etc files from D: THX Everyone who helped out gets a Twinkie |
|
| 1273. |
Solve : Best anti virus,What are you using?? |
|
Answer» To be honest, I've worked with all sorts of AV's and heard several reports, but I find Kaspersky to be the top winner. It's just a TAD better than NOD32, which is ALREADY the top notch out there. Quote *REMOVED website of bad reputation* SORRY but If you are going to post links, make sure they are of good reputation and are RELEVANT to the information displayed in the topic. Here are some relevant SITES to research site reputation: http://www.mywot.com http://www.siteadvisor.com http://www.trustedsource.org http://linkscanner.explabs.com/linkscanner/default.aspx Quote http://www.mywot.comWell. Thanks! |
|
| 1274. |
Solve : New rogue/antivirus infection - Please help? |
|
Answer» UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT DDS (Ver_10-03-17.01) Microsoft Windows XP Home Edition Boot Device: \Device\HarddiskVolume1 Install Date: 9/4/2007 12:45:13 PM System Uptime: 4/5/2010 11:11:58 PM (0 hours ago) Motherboard: ASUSTek Computer INC. | | Kelut Processor: AMD Athlon(tm) XP 3200+ | Socket A | 2199/200mhz ==== Disk Partitions ========================= C: is FIXED (NTFS) - 149 GiB total, 64.556 GiB free. D: is CDROM () E: is CDROM () F: is Removable G: is Removable H: is Removable I: is Removable J: is Removable ==== Disabled Device Manager Items ============= ==== System Restore Points =================== RP390: 1/12/2010 2:05:37 PM - System Checkpoint RP391: 1/13/2010 1:12:03 AM - Software Distribution Service 3.0 RP392: 1/14/2010 2:43:59 AM - System Checkpoint RP393: 1/15/2010 12:29:51 PM - System Checkpoint RP394: 1/16/2010 1:17:45 PM - System Checkpoint RP395: 1/17/2010 10:34:30 PM - System Checkpoint RP396: 1/18/2010 10:56:33 PM - System Checkpoint RP397: 1/20/2010 1:43:45 AM - System Checkpoint RP398: 1/21/2010 2:29:57 AM - System Checkpoint RP399: 1/22/2010 6:11:16 PM - System Checkpoint RP400: 1/23/2010 3:00:17 AM - Software Distribution Service 3.0 RP401: 1/24/2010 3:30:48 AM - System Checkpoint RP402: 1/25/2010 4:30:47 AM - System Checkpoint RP403: 1/26/2010 4:35:25 AM - System Checkpoint RP404: 1/27/2010 4:40:23 AM - System Checkpoint RP405: 1/28/2010 1:21:08 AM - Removed Cisco Network Magic RP406: 1/28/2010 1:22:28 AM - Removed Pure Networks Platform RP407: 1/29/2010 1:41:57 AM - System Checkpoint RP408: 1/30/2010 2:31:34 AM - System Checkpoint RP409: 1/31/2010 3:22:32 AM - System Checkpoint RP410: 2/1/2010 4:22:34 AM - System Checkpoint RP411: 2/2/2010 5:22:33 AM - System Checkpoint RP412: 2/3/2010 6:22:37 AM - System Checkpoint RP413: 2/4/2010 7:08:23 AM - System Checkpoint RP414: 2/5/2010 8:08:21 AM - System Checkpoint RP415: 2/6/2010 12:18:35 PM - System Checkpoint RP416: 2/7/2010 1:05:47 PM - System Checkpoint RP417: 2/8/2010 3:23:06 PM - System Checkpoint RP418: 2/9/2010 3:43:33 PM - System Checkpoint RP419: 2/10/2010 5:59:13 PM - System Checkpoint RP420: 2/11/2010 3:00:16 AM - Software Distribution Service 3.0 RP421: 2/12/2010 3:08:45 AM - System Checkpoint RP422: 2/13/2010 7:22:07 AM - System Checkpoint RP423: 2/14/2010 8:50:44 AM - System Checkpoint RP424: 2/15/2010 12:10:02 PM - System Checkpoint RP425: 2/16/2010 1:26:37 PM - System Checkpoint RP426: 2/17/2010 3:22:31 PM - System Checkpoint RP427: 2/18/2010 3:51:56 PM - System Checkpoint RP428: 2/19/2010 8:01:16 PM - System Checkpoint RP429: 2/20/2010 8:37:52 PM - System Checkpoint RP430: 2/21/2010 4:12:13 AM - Installed Java(TM) 6 Update 17 RP431: 2/22/2010 6:31:07 AM - System Checkpoint RP432: 2/23/2010 7:16:41 AM - System Checkpoint RP433: 2/24/2010 3:00:21 AM - Software Distribution Service 3.0 RP434: 2/25/2010 3:59:25 AM - System Checkpoint RP435: 2/26/2010 5:17:04 AM - System Checkpoint RP436: 2/27/2010 5:59:24 AM - System Checkpoint RP437: 2/28/2010 6:59:25 AM - System Checkpoint RP438: 3/1/2010 7:03:39 AM - System Checkpoint RP439: 3/2/2010 7:59:05 AM - System Checkpoint RP440: 3/3/2010 8:59:06 AM - System Checkpoint RP441: 3/4/2010 10:55:13 AM - System Checkpoint RP442: 3/5/2010 10:59:05 AM - System Checkpoint RP443: 3/6/2010 11:59:07 AM - System Checkpoint RP444: 3/7/2010 5:53:19 PM - System Checkpoint RP445: 3/8/2010 3:20:19 PM - Removed Safari RP446: 3/8/2010 10:50:24 PM - Removed imeem Uploader RP447: 3/8/2010 10:51:14 PM - Software Distribution Service 3.0 RP448: 3/10/2010 4:06:14 AM - System Checkpoint RP449: 3/15/2010 1:19:43 AM - System Checkpoint RP450: 3/15/2010 3:00:34 AM - Software Distribution Service 3.0 RP451: 3/16/2010 3:09:03 AM - System Checkpoint RP452: 3/17/2010 3:10:56 AM - System Checkpoint RP453: 3/18/2010 3:15:40 AM - System Checkpoint RP454: 3/19/2010 3:51:41 AM - System Checkpoint RP455: 3/20/2010 6:02:11 PM - System Checkpoint RP456: 3/21/2010 6:32:28 PM - System Checkpoint RP457: 3/22/2010 8:53:17 PM - System Checkpoint RP458: 3/22/2010 10:42:41 PM - Installed Windows XP KB914882. RP459: 3/22/2010 10:46:02 PM - Software Distribution Service 3.0 RP460: 3/23/2010 11:40:25 AM - Software Distribution Service 3.0 RP461: 3/24/2010 3:00:42 AM - Software Distribution Service 3.0 RP462: 3/24/2010 11:59:47 AM - Software Distribution Service 3.0 RP463: 3/25/2010 3:00:45 AM - Software Distribution Service 3.0 RP464: 3/25/2010 2:19:49 PM - Software Distribution Service 3.0 RP465: 3/26/2010 2:18:58 PM - Software Distribution Service 3.0 RP466: 3/27/2010 2:19:06 PM - Software Distribution Service 3.0 RP467: 3/28/2010 2:05:09 AM - Software Distribution Service 3.0 RP468: 3/29/2010 3:19:57 AM - System Checkpoint RP469: 3/29/2010 2:19:21 PM - Software Distribution Service 3.0 RP470: 3/30/2010 2:19:48 PM - Software Distribution Service 3.0 RP471: 3/31/2010 3:00:22 AM - Software Distribution Service 3.0 RP472: 4/1/2010 3:10:51 AM - System Checkpoint RP473: 4/1/2010 12:56:43 PM - Software Distribution Service 3.0 RP474: 4/2/2010 3:35:46 AM - Software Distribution Service 3.0 RP475: 4/3/2010 3:36:38 AM - Software Distribution Service 3.0 RP476: 4/4/2010 2:04:06 AM - Software Distribution Service 3.0 RP477: 4/5/2010 5:09:14 AM - System Checkpoint RP478: 4/5/2010 2:35:09 PM - Software Distribution Service 3.0 ==== Installed Programs ====================== AAC Decoder Adobe AIR Adobe Flash Player 10 Plugin Adobe Reader 8.1.3 Adobe Shockwave Player 11.5 Agere Systems PCI Soft Modem AIMTunes Apple Application Support Apple Mobile Device Support Apple Software Update AT&T Connect Participant AutoUpdate BitTorrent Bonjour Compaq Connections DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Plus Web Player DivX Version Checker H.264 Decoder Help and Support Additions High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB970653-v3) Hotfix for Windows XP (KB976098-v2) Hotfix for Windows XP (KB979306) HpSdpAppCoreApp iTunes Java 2 Runtime Environment, SE v1.4.2_03 Java(TM) 6 Update 17 K-Lite Codec Pack 5.8.3 (Basic) KBD LiveUpdate 1.90 (SYMANTEC Corporation) Malwarebytes' Anti-Malware Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft Antimalware Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Office Standard Edition 2003 Microsoft Plus! Dancer LE Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft Security Essentials Microsoft Silverlight Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Works 7.0 MKV Splitter Morrowind Mozilla Firefox (3.6.3) Norton WMI Update Pando Media Booster PC-DOCTOR for Windows Prism Video Converter PS2 Python 2.2 combined Win32 extensions Python 2.2.1 QuickTime S3 S3Display S3 S3Gamma2 S3 S3Info2 S3 S3Overlay Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB938127-v2) Security Update for Windows Internet Explorer 7 (KB961260) Security Update for Windows Internet Explorer 7 (KB963027) Security Update for Windows Internet Explorer 7 (KB969897) Security Update for Windows Internet Explorer 7 (KB972260) Security Update for Windows Internet Explorer 7 (KB974455) Security Update for Windows Internet Explorer 7 (KB976325) Security Update for Windows Internet Explorer 7 (KB978207) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB968816) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows Media Player 9 (KB936782) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938464-v2) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB941568) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB941644) Security Update for Windows XP (KB941693) Security Update for Windows XP (KB943055) Security Update for Windows XP (KB943460) Security Update for Windows XP (KB943485) Security Update for Windows XP (KB944338) Security Update for Windows XP (KB944653) Security Update for Windows XP (KB945553) Security Update for Windows XP (KB946026) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB947864) Security Update for Windows XP (KB948590) Security Update for Windows XP (KB948881) Security Update for Windows XP (KB950749) Security Update for Windows XP (KB950759) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958470) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB958869) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB961371) Security Update for Windows XP (KB961373) Security Update for Windows XP (KB961501) Security Update for Windows XP (KB968537) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB969898) Security Update for Windows XP (KB969947) Security Update for Windows XP (KB970238) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971468) Security Update for Windows XP (KB971486) Security Update for Windows XP (KB971557) Security Update for Windows XP (KB971633) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB971961) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973346) Security Update for Windows XP (KB973354) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973525) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975561) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977165) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978037) Security Update for Windows XP (KB978251) Security Update for Windows XP (KB978262) Security Update for Windows XP (KB978706) Skype Toolbars Skype™ 4.2 Spyware Doctor 7.0 TES Construction Set Update for Windows Internet Explorer 7 (KB976749) Update for Windows Internet Explorer 7 (KB980182) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB914882) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB933360) Update for Windows XP (KB938828) Update for Windows XP (KB942763) Update for Windows XP (KB955759) Update for Windows XP (KB955839) Update for Windows XP (KB967715) Update for Windows XP (KB968389) Update for Windows XP (KB971737) Update for Windows XP (KB973687) Update for Windows XP (KB973815) VC80CRTRedist - 8.0.50727.4053 VIA Rhine-Family Fast Ethernet Adapter VIA/S3G Display Driver WavePad Sound Editor WebEx Support Manager for Internet Explorer WebFldrs XP Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 World of Warcraft ==== Event Viewer Messages From Past Week ======== 4/4/2010 12:57:33 PM, error: Microsoft Antimalware [1008] - Microsoft Antimalware has encountered an error when taking action on spyware or other potentially unwanted software. For more information please see the following: http://go.microsoft.com/fwlink/?linkid=37020&name=HackTool:Win32/CrackSearch.A&threatid=2147515165 User: BECKSCOMPUTER\Compaq_Owner Name: HackTool:Win32/CrackSearch.A ID: 2147515165 Severity: Medium Category: Tool Path: Action: Remove Error Code: 0x80508023 Error description: The program could not find the spyware and other potentially unwanted software on this computer. Status: Signature Version: AV: 1.79.1151.0, AS: 1.79.1151.0 Engine Version: 1.1.5605.0 4/4/2010 12:30:41 PM, error: Cdrom [11] - The driver detected a controller error on \Device\CdRom0. 3/30/2010 4:19:59 PM, error: Service Control Manager [7031] - The Microsoft Antimalware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 15000 milliseconds: Restart the service. 3/30/2010 4:19:58 PM, error: Service Control Manager [7034] - The Machine Debug Manager service terminated unexpectedly. It has done this 1 time(s). 3/30/2010 4:19:58 PM, error: Service Control Manager [7034] - The Java Quick Starter service terminated unexpectedly. It has done this 1 time(s). 3/30/2010 4:19:58 PM, error: Service Control Manager [7034] - The Bonjour Service service terminated unexpectedly. It has done this 1 time(s). 3/30/2010 4:19:58 PM, error: Service Control Manager [7034] - The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s). 3/30/2010 4:19:58 PM, error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 3/30/2010 4:19:57 PM, error: Service Control Manager [7034] - The Print Spooler service terminated unexpectedly. It has done this 1 time(s). 3/30/2010 4:19:57 PM, error: Service Control Manager [7034] - The iPod Service service terminated unexpectedly. It has done this 1 time(s). ==== End Of File =========================== DDS (Ver_10-03-17.01) - NTFSx86 Run by Compaq_Owner at 23:24:29.17 on Mon 04/05/2010 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_17 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.119 [GMT -4:00] AV: Microsoft Security Essentials *On-access scanning disabled* (UPDATED) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe c:\Program Files\Microsoft Security Essentials\MsMpEng.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe -k imgsvc C:\windows\system\hpsysdrv.exe C:\HP\KBD\KBD.EXE C:\WINDOWS\system32\VTTimer.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Microsoft Security Essentials\msseces.exe C:\WINDOWS\System32\svchost.exe -k HTTPFilter C:\Program Files\Compaq Connections\6750491\Program\Compaq Connections.exe C:\Program Files\Interwise\Participant\pull.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\explorer.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Compaq_Owner\My Documents\Downloads\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop uInternet Settings,ProxyOverride = BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on for Internet Explorer: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized mRun: [hpsysdrv] c:\windows\system\hpsysdrv.exe mRun: [KBD] c:\hp\kbd\KBD.EXE mRun: [Recguard] c:\windows\sminst\RECGUARD.EXE mRun: [VTTimer] VTTimer.exe mRun: [PS2] c:\windows\system32\ps2.exe mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [MSSE] "c:\program files\microsoft security essentials\msseces.exe" -hide -runkey StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\compaq~1.lnk - c:\program files\compaq connections\6750491\program\Compaq Connections.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\pushcl~1.lnk - c:\program files\interwise\participant\pull.exe IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office11\EXCEL.EXE/3000 IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office11\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\compaq~1\applic~1\mozilla\firefox\profiles\fte4u602.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\documents and settings\all users\application data\nexonus\ngm\npNxGameUS.dll FF - plugin: c:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: c:\program files\mozilla firefox\plugins\npPandoWebInst.dll FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} ---- FIREFOX POLICIES ---- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut. enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugi n", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-3-16 207280] R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 149040] =============== Created Last 30 ================ 2010-04-04 17:58:14 0 d-----w- c:\program files\NCH Software 2010-04-02 06:41:57 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2010-04-02 06:35:07 0 d-----r- c:\program files\Skype 2010-03-29 05:27:40 165376 ----a-w- c:\windows\system32\unrar.dll 2010-03-29 05:27:31 0 d-----w- c:\program files\K-Lite Codec Pack 2010-03-23 14:39:12 274288 ----a-w- c:\windows\system32\mucltui.dll 2010-03-23 14:39:12 215920 ----a-w- c:\windows\system32\muweb.dll 2010-03-23 14:39:12 16736 ----a-w- c:\windows\system32\mucltui.dll.mui 2010-03-23 02:46:15 181632 ------w- c:\windows\system32\MpSigStub.exe 2010-03-23 02:42:55 0 d-----w- c:\program files\Microsoft Security Essentials 2010-03-18 03:38:42 98816 ----a-w- c:\windows\sed.exe 2010-03-18 03:38:42 77312 ----a-w- c:\windows\MBR.exe 2010-03-18 03:38:42 261632 ----a-w- c:\windows\PEV.exe 2010-03-18 03:38:42 161792 ----a-w- c:\windows\SWREG.exe 2010-03-16 18:49:37 0 d-----w- c:\program files\Trend Micro 2010-03-16 17:03:57 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat 2010-03-16 17:03:57 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2010-03-16 17:03:52 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat 2010-03-16 17:03:52 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2010-03-16 17:03:51 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2010-03-16 17:03:51 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat 2010-03-16 17:03:35 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat 2010-03-16 17:03:35 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2010-03-16 17:03:21 0 d-----w- c:\program files\Spyware Doctor 2010-03-16 17:03:21 0 d-----w- c:\program files\common files\PC Tools 2010-03-16 17:03:21 0 d-----w- c:\docume~1\compaq~1\applic~1\PC Tools 2010-03-16 17:03:21 0 d-----w- c:\docume~1\alluse~1\applic~1\PC Tools 2010-03-16 16:34:19 0 d-----w- c:\program files\common files\Wise Installation Wizard 2010-03-16 16:26:59 0 d-----w- c:\docume~1\compaq~1\applic~1\Malwarebytes 2010-03-16 16:25:43 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-16 16:25:41 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes 2010-03-16 16:25:40 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-16 16:25:40 0 d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-16 02:31:51 552 ----a-w- c:\windows\system32\d3d8caps.dat 2010-03-16 02:31:49 1324 ----a-w- c:\windows\system32\d3d9caps.dat 2010-03-15 07:27:38 0 d--h--w- c:\windows\PIF ==================== Find3M ==================== 2010-03-11 12:38:54 832512 ------w- c:\windows\system32\wininet.dll 2010-03-11 12:38:52 78336 ----a-w- c:\windows\system32\ieencode.dll 2010-03-11 12:38:51 17408 ----a-w- c:\windows\system32\corpol.dll ============= FINISH: 23:24:52.64 =============== Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6CB8582E-0C1D-E161-9CA4-DE7CEE947816}-Craagle.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze ============================ You still have BitTorrent on your computer which is another P2P program. See previous information concerning P2P programs. ============================= Please go to Jotti's malware scan (If more than one file needs scanned they must be done separately and logs posted for each one) * Copy the file path in the below Code box: Code: [Select]c:\windows\system32\ezsidmv.dat * At the upload site, click once inside the window next to Browse. * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. * Next click Submit file * Your file will possibly be entered into a queue which normally takes less than a minute to clear. * This will perform a scan across multiple different virus scanning engines. * Important: Wait for all of the scanning engines to complete. * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply. ======================== It's been a long time since we started this process. How's your computer running? My computer's doing pretty good at the moment. It'll go smooth and fine for a few days and then the original virus's symptoms will show up again, but like with a different name. This only happens because I don't check your replies for a couple of days at a time, so I'm trying to check it at least once a day. As for the Jotti's Malware Scan, it does not let me copy&paste that into it...as soon as I click next to the "browse" button, it opens up a browser. Also, that latest script for CF is running currently. I'll post the log as soon as it reboots.ComboFix 10-04-05.01 - Compaq_Owner 04/07/2010 20:23:36.9.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.447.109 [GMT -4:00] Running from: c:\documents and settings\Compaq_Owner\My Documents\Downloads\ComboFix.exe Command switches used :: J:\CFScript.txt AV: Microsoft Security Essentials *On-access scanning disabled* (Updated) {BCF43643-A118-4432-AEDE-D861FCBCFCDF} FILE :: "c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6CB8582E-0C1D-E161-9CA4-DE7CEE947816}-Craagle.exe" . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\LocalCopy\{6CB8582E-0C1D-E161-9CA4-DE7CEE947816}-Craagle.exe . ((((((((((((((((((((((((( Files Created from 2010-03-08 to 2010-04-08 ))))))))))))))))))))))))))))))) . 2010-04-06 23:34 . 2010-04-06 23:34 -------- d-----w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\PCHealth 2010-04-06 23:34 . 2010-04-06 23:34 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\PCHealth 2010-04-06 02:44 . 2010-04-06 02:44 196096 --sha-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\1585116398.dll 2010-04-04 17:58 . 2010-04-04 17:58 -------- d-----w- c:\program files\NCH Software 2010-04-02 06:41 . 2010-04-02 06:41 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2010-04-02 06:41 . 2010-04-02 06:41 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\skypePM 2010-04-02 06:36 . 2010-04-07 00:04 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Skype 2010-04-02 06:35 . 2010-04-02 06:35 -------- d-----w- c:\program files\Common Files\Skype 2010-04-02 06:35 . 2010-04-02 06:36 -------- d-----r- c:\program files\Skype 2010-04-02 06:34 . 2010-04-02 06:35 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype 2010-03-29 05:27 . 2010-02-10 17:13 165376 ----a-w- c:\windows\system32\unrar.dll 2010-03-29 05:27 . 2010-03-29 05:28 -------- d-----w- c:\program files\K-Lite Codec Pack 2010-03-23 14:39 . 2009-08-06 23:23 274288 ----a-w- c:\windows\system32\mucltui.dll 2010-03-23 14:39 . 2009-08-06 23:23 215920 ----a-w- c:\windows\system32\muweb.dll 2010-03-23 02:46 . 2010-02-24 14:16 181632 ------w- c:\windows\system32\MpSigStub.exe 2010-03-23 02:42 . 2010-03-23 02:43 -------- d-----w- c:\program files\Microsoft Security Essentials 2010-03-21 03:06 . 2010-03-21 03:06 5115824 ----a-w- c:\documents and settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2010-03-16 18:49 . 2010-03-16 18:49 -------- d-----w- c:\program files\Trend Micro 2010-03-16 18:07 . 2010-03-16 18:07 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes 2010-03-16 18:04 . 2010-03-16 18:04 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla 2010-03-16 17:03 . 2010-02-05 13:17 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys 2010-03-16 17:03 . 2009-09-23 20:10 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys 2010-03-16 17:03 . 2009-10-06 20:31 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys 2010-03-16 17:03 . 2010-02-05 13:25 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys 2010-03-16 17:03 . 2010-03-16 18:39 -------- d-----w- c:\program files\Spyware Doctor 2010-03-16 17:03 . 2010-03-16 17:03 -------- d-----w- c:\program files\Common Files\PC Tools 2010-03-16 17:03 . 2010-03-16 17:03 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\PC Tools 2010-03-16 17:03 . 2010-03-16 17:03 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools 2010-03-16 17:03 . 2010-03-16 18:39 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2010-03-16 16:34 . 2010-03-16 16:34 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2010-03-16 16:26 . 2010-03-16 16:26 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Malwarebytes 2010-03-16 16:25 . 2010-01-07 20:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-03-16 16:25 . 2010-03-16 16:25 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes 2010-03-16 16:25 . 2010-03-21 03:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-16 16:25 . 2010-01-07 20:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2010-03-16 02:31 . 2010-03-16 02:31 552 ----a-w- c:\windows\system32\d3d8caps.dat 2010-03-16 02:31 . 2010-03-16 18:36 1324 ----a-w- c:\windows\system32\d3d9caps.dat 2010-03-16 02:30 . 2010-03-16 02:31 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe 2010-03-15 07:27 . 2010-03-15 07:27 -------- d--h--w- c:\windows\PIF . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-05 06:52 . 2009-12-15 03:55 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\BitTorrent 2010-04-04 18:00 . 2009-05-12 23:10 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\NCH Software 2010-04-04 17:58 . 2009-05-12 23:10 -------- d-----w- c:\documents and settings\All Users\Application Data\NCH Software 2010-03-29 05:14 . 2009-12-15 05:07 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\DivX 2010-03-24 18:17 . 2008-12-15 20:38 64624 ----a-w- c:\documents and settings\Compaq_Owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-03-24 18:11 . 2008-06-17 19:54 -------- d-----w- c:\program files\Microsoft Silverlight 2010-03-24 07:03 . 2004-08-09 06:47 -------- d-----w- c:\program files\Microsoft Works 2010-03-23 02:44 . 2009-01-19 17:59 -------- d-----w- c:\program files\Common Files\AOL 2010-03-23 02:36 . 2009-01-19 18:00 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint 2010-03-11 12:38 . 2004-08-09 04:28 832512 ------w- c:\windows\system32\wininet.dll 2010-03-11 12:38 . 2004-08-09 04:28 78336 ----a-w- c:\windows\system32\ieencode.dll 2010-03-11 12:38 . 2004-08-09 04:28 17408 ----a-w- c:\windows\system32\corpol.dll 2010-02-23 04:58 . 2009-06-17 00:04 -------- d-----w- c:\program files\AIMTunes 2010-02-21 09:12 . 2004-08-09 06:12 -------- d-----w- c:\program files\Java 2010-02-21 09:11 . 2010-02-21 09:11 152576 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\lzma.dll 2010-02-21 09:11 . 2009-11-25 18:17 79488 ----a-w- c:\documents and settings\Compaq_Owner\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-02-21 04:26 . 2008-09-05 01:23 -------- d-----w- c:\documents and settings\Compaq_Owner\Application Data\Apple Computer 2010-02-18 19:48 . 2010-02-18 19:47 -------- d-----w- c:\program files\iTunes 2010-02-18 19:47 . 2010-02-18 19:47 -------- d-----w- c:\program files\iPod 2010-02-18 19:47 . 2009-03-11 22:52 -------- d-----w- c:\program files\Common Files\Apple 2010-02-18 19:42 . 2010-02-18 19:42 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2010-03-09 26100520] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736] "KBD"="c:\hp\KBD\KBD.EXE" [2003-02-12 61440] "Recguard"="c:\windows\SMINST\RECGUARD.EXE" [2004-04-15 233472] "VTTimer"="VTTimer.exe" [2004-10-22 53248] "PS2"="c:\windows\system32\ps2.exe" [2003-09-13 98304] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-23 141608] "MSSE"="c:\program files\Microsoft Security Essentials\msseces.exe" [2010-02-21 1093208] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Compaq Connections.lnk - c:\program files\Compaq Connections\6750491\Program\Compaq Connections.exe [2004-8-9 16423] Push Client.LNK - c:\program files\Interwise\Participant\pull.exe [2009-9-15 886000] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc] ="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 "FirewallOverride"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) "DisableNotifications"= 1 (0x1) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Compaq Connections\\6750491\\Program\\Compaq Connections.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"= "c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"= "c:\\Program Files\\World of Warcraft\\Launcher.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.1.3.9947-to-3.2.0.10192-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.2.0.10314-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.0.10314-to-3.2.2.10482-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft\\WoW-3.2.2.10482-to-3.2.2.10505-enUS-downloader.exe"= "c:\\Program Files\\World of Warcraft Public Test\\WoW-0.3.0.10522-enUS-ptr-downloader.exe"= "c:\\Program Files\\World of Warcraft Public Test\\WoW-0.3.0.10522-to-0.3.0.10554-enUS-ptr-downloader.exe"= "c:\\Program Files\\World of Warcraft Public Test\\Launcher.exe"= "c:\\Program Files\\World of Warcraft Public Test\\WoW-0.3.0.10554-to-0.3.0.10571-enUS-ptr-downloader.exe"= "c:\\Program Files\\World of Warcraft Public Test\\WoW-0.3.0.10571-to-0.3.0.10596-enUS-ptr-downloader.exe"= "c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"= "c:\\Program Files\\BitTorrent\\bittorrent.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Skype\\Phone\\Skype.exe"= "c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "58964:TCP"= 58964:TCP:Pando Media Booster "58964:UDP"= 58964:UDP:Pando Media Booster "3724:TCP"= 3724:TCP:Blizzard Downloader: 3724 R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [3/16/2010 1:03 PM 207280] . Contents of the 'Scheduled Tasks' folder 2010-04-06 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-04-08 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Microsoft Security Essentials\MpCmdRun.exe [2009-12-09 22:02] 2007-09-04 c:\windows\Tasks\Symantec NetDetect.job - c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2004-08-10 08:38] . . ------- Supplementary Scan ------- . uStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q404&bd=presario&pf=desktop uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q404&bd=presario&pf=desktop uInternet Settings,ProxyOverride = IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 IE: {{898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll FF - ProfilePath - c:\documents and settings\Compaq_Owner\Application Data\Mozilla\Firefox\Profiles\fte4u602.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ FF - plugin: c:\documents and settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut. enabled", true); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugi n", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-04-07 20:32 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(956) c:\windows\system32\WININET.dll c:\docume~1\COMPAQ~1\LOCALS~1\Temp\IadHide5.dll c:\windows\system32\ieframe.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Microsoft Security Essentials\MsMpEng.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Bonjour\mDNSResponder.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\windows\system32\VTTimer.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2010-04-07 20:38:05 - machine was rebooted ComboFix-quarantined-files.txt 2010-04-08 00:38 ComboFix2.txt 2010-04-06 03:21 ComboFix3.txt 2010-04-04 08:17 ComboFix4.txt 2010-03-30 20:33 ComboFix5.txt 2010-04-08 00:22 Pre-Run: 69,310,857,216 bytes free Post-Run: 69,284,540,416 bytes free - - End Of File - - BCF769C084FB0DA2B40BE1C5963A1F43 Ok. We'll wait a few days to see what happens. In the meantime let's run this scan. ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * Click the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the Back button then click Finish. In your next reply please include the ESET Online Scan Log |
|
| 1275. |
Solve : Updating antivirus without internet connection? |
|
Answer» I have a new computer that I don't want to connect to the internet at home. Is there an antivirus software that will allow me to update manually like download the update from another pc and install the update to my other pc via a usb flash drive?ClamWin Portable is a portable freeware antivirus for detecting viruses and spyware on your computer. It can be place on a usb key and CD to be used on any computer.Thanks for the reply but I want to limit my search to the more established antivirus software out there like Kaspersky, NOD32, bitdefender, etc. Doesn't have to be free. I just want the option to update the antivirus definitions without internet connection. I think Bitdefender used to have that option in which you can download a weekly definition, save it on a usb flash drive and update from the saved file. Does it still do that? Are there any other antivirus that does that?i'v heard of people doing this with mcaffee.I recommend Kasparsky . Antivirus 2010. Full update downloads can be found on AVGI agree with him if you want a free program - of course there is not free -AVG is not recommended, as the software has a lot of false positives, and severely slows down systems. Quote from: DragonMaster Jay on April 06, 2010, 01:42:59 PM AVG is not recommended, as the software has a lot of false positives, and severely slows down systems. And Norton charges for that type of thing! That's a great deal! Quote AVG is not recommended, as the software has a lot of false positives, and severely slows down systemsAll or most of the antivirus programs. Sometimes GIVES error messages. Kasparsky including: Compressed files by( UPX ) in lupopensuite portable softwere Treat them as viruses and Kaspersky Says Google Spreads MALWARE http://news.softpedia.com/news/Kaspersky-Says-Google-Spreads-Malware-but-Trojan-JS-Redirector-ar-Is-a-False-Positive-133118.shtml Quote from: on April 07, 2010, 04:01:14 PM ALL Anti-virus software gives out false positives at one point in time, no one is excusing ESET or Kaspersky, but what is being said is there are a large amount of false-positives being given out by AVG.Hi, New to the forum, I thought I would mention that 'Avast' is a pretty decent solution and it is free for home use. I would have to agree regarding AVG and NORTONS, both 'imho' are resource hogs and tax the system. AVG I wouldn't recommend to anyone looking for decent Viri protection. Zaquria, |
|
| 1276. |
Solve : An undeletable folder with the name print on my thump drive? |
|
Answer» There an empty folder with NAME PRINT on my thump drive.I am not being ABLE to REMOVE it all.I cant even format the thump drive. |
|
| 1277. |
Solve : Major Infections?? |
|
Answer» My Scanner finds 4+ infections some Trojans and some adware and stuff. I've RAN multiple scanners at differant times to remove them all. |
|
| 1278. |
Solve : Spybot Search & Destroy Question? |
|
Answer» Hi there, I'm at my wits end.I have always used Spybot Search & DESTROY...but this time, it done something really crazy. I updated (as usual)...so its current.Then I ran the scan and when I tried to "Fix the Problem" it gave me 2 pop ups.One saying that "some probs couldnt be fixxed..the reason could be that the associated files are still in use(in memory)" .....THEN the other pop-up said " 0 problems fixxed.35 problems could not be fixed.You should have an administrator scan and fix again!" I am the ONLY person that uses this computer,so therefore shouldn't "I" be the administrator? It seems like the pop up is insinuating that I am a guest & NOT the administrator running the scan.Is there a way I can check 2 make SURE I am under admin.? I know that sounds dumb b/cv I have access to ALL things on my computer...BUT actually I have seen this comment before about "you cannot delete this,only the administrator can".....Its saying I have 18 Trojans 7 PUPS and 7 Pups So its not letting me delete all this stuff that Spybot found!What can I do.....any HELP would be appreciated, Thanks Spybot is now considered "OLD school". The current best of breed are MalwareBytes & SuperAntispyware. I suggest you uninstall Spybot and install one or both of the other two. Quote from: Allan on April 09, 2010, 07:33:51 AM Spybot is now considered "old school". The current best of breed are MalwareBytes & SuperAntispyware. I suggest you uninstall Spybot and install one or both of the other two.I do have Malawarebytes and run it often,but it didnt pick up all those things that Spybot Search & Destroy did...hmmmm? I agree its pretty old school,b/c I've used it since I got my 1st computer in 2000...lol. So I suppose I'll try the SuperAntispyware as well.But it still may say I'm not running this under administrator.Is there a place where I can check to make sure I am useing my computer under Admin...? I really should know this,but where I go,it SAYS I'm the Admin.....wierd,huh?Spybot is not old school. Along with Ad-Aware, they were pioneers in spyware removal. Spybot can compare to other anti-spyware software. It is not, however, an anti-malware. SuperAntiSpyware is a deceiving name for them, as they remove malware. If you want anti-malware, go with SAS or MBAM. If you need anti-spyware, Spybot will work. |
|
| 1279. |
Solve : Unable to delete a folder? |
|
Answer» Hi, |
|
| 1280. |
Solve : how can remove these virus? |
|
Answer» my system is effected by two malicious CODE. every after few minute my anti virus( FREE VERSION AVAST antivirus) is detected the virus whose the detail is: |
|
| 1281. |
Solve : Cannot open any window/application on Windows Vista? |
|
Answer» Hi, I have a serious problem with my system. Somehow some virus has infected my system. It keeps flashing me virus alert and whenever i try to run any program it says "Application cannot be executed. The file **** is infected......." (not even a command prompt, notepad, task manager etc can be opened.. but with multiple tries, sometimes i get the command prompt but it is ridiculous). Thanks SuperDave. I will create a USB right now. One clarification though "My infected system is running on vista, but the computer I am accessing the internet is a library computer running XP. By creating the USB on the library computer, will I be able to use it on vista?"Shouldn't be a problem. |
|
| 1282. |
Solve : Digital protection antivirus? |
|
Answer» My system was infected wit this digital protection antivirus. Firstly, I thought that it is SECURITY software but later on I come to know that this is not security tool, it is a deadly infection. |
|
| 1283. |
Solve : anti-virus + Anti-spyware and Anti-Malware? |
|
Answer» It is well known. It must not be RUNNING 2 anti-virus program at the same time. You can run more than one Anti-Spyware programs if you wish. I have four running on my computer with no problems.Realtime?If you are using Kasparsky Internet Security 2010 which contains Anti-spyware and Anti-Malware then there is no need of external anti spyware and anti-malware.Simply: I use Kasparsky 2010, then installed anti-spy (SuperAntiSpyware) were uncovered spy files by it. For some reason i removed Kasparsky. And left anti-spyware. And when i re-install Kasparsky. Kasparsky gave the message that i must remove the anti-spyware. Prior to the installation Kasparsky. In short: 1 - I want to use 2 programs. Because of the inability Kasparsky. To detect all the spyware files. 2 - anti-virus and anti spy after: No ERROR Messages 3 - anti-spy and then after the anti-virus: Error Message Quote from: kpac on April 11, 2010, 12:24:52 PM Realtime?Three realtime.Kasparsky only. Others. I manage. Their WORK as I want Quote from: SuperDave on April 12, 2010, 01:12:12 PM Three realtime.Oh right. I thought it was the same as AVs..... Quote Oh right. I thought it was the same as AVs....AVs.. Anti-virus. AS = Anti-spyware. CLEAR |
|
| 1284. |
Solve : rootkit.Win32.TDSS.d infection on Vista? |
|
Answer» Hi, |
|
| 1285. |
Solve : Possible virus/spyware to do with Runes of Magic?? |
|
Answer» Hello there everyone, |
|
| 1286. |
Solve : before removing antivirus in regedit? |
|
Answer» I have had problems as i uninstalled avira anti virus from my machine ,but today when trying to remove windows defender and windows firewall,which will not dissapear ,it said in the security that my firewall was avira, so i have been in regedit, system root and searched ,i have found a file called avi,as i am not a computer expert hence my name not a pc ,instead of im a pc lol!,im not sure if this is the file im searching for as i cannot FIND avira,and im thinking if i delete this i may regret it,so its best to ask some one,is there any WINDOWS components called avi in system root,or have i correctly identified the file i am looking for?Please do not mess around in the registry. Please run this tool and post the log in your next reply |
|
| 1287. |
Solve : Computer salesmen? |
|
Answer» Right. So I went to the store and I asked "is this product av + firewall or firewall only"? So the guy looks at the back of the box for half an hour and says "uhhhmmm.. seems to be firewall only" while it was av+firewall... Why do they hire such retards as salesmen? =) that's why their salesman... I'm sure they could get much better people if they paid more then 8$ an hour or whatever they GIVE them. I'm pretty sure when one of them get's tired of the job they just hand it to the SMELLY hobo that is always standing outside the toy-store in the van full of candy. He seems like a trustworthy fellow, he'll be great to leave as the sole supervisor in a room full of young children with a camera and several ROLLS of film. Whaddya mean that's not what happens in computer stores?Minimum wage here is like 12$ dude. =P Salesman USUALLY makes 25$ an hr. The funny thing is, the other store has this one computer nerd that takes care of the whole IT department. That guy is good. He even knew out of the top of his head what an U3 OS is (for USB pen drives). =) He also helped me with my router! Not to mention he knows the differences and tech specs of every type of cable out there and in terms of compatibility too (HDMI, VGA, COAX, .. etc.). Great guy. =) Now that's support! I think all salesmen should be like that. Don't hire some noob... those types of salesman don't often last long. unless they find a more suitable job for their skills they usually go postal on their co-workers (of the type you described originally) for being so incredibly dense and useless. Or they get fired for inappropriate conduct. She came onto me, *censored*. I don't care if she was a manakin.Hahaha yes. I am also like that and I find it hard to keep 'code of conduct' to such dense people.Where do you work ? ?That's a rather private question, patio.I like to mess with them. Start asking them questions about BSD and Linux compatability. Quote from: patio on April 15, 2010, 02:55:03 PM Where do you work ? ?He's a computer salesman. Quote from: mr-bisquit on April 16, 2010, 12:30:31 PM I like to mess with them. heh, and then you know when to leave, since a lot of them will say something like "Linux, isn't that a virus?" and "if BSD ran in XP, it will run fine with windows 7" hahaha |
|
| 1288. |
Solve : Kaspersky license? |
|
Answer» Hello My Kaspersky product says "valid for 3 PC's". If I install it on my XP, then once again on Windows7 Pro, will it take 1 of the 3 licenses away or still consider it '1 computer'?The product key is GOOD for three computers. Once the license detects three computers currently have it installed, the key will no LONGER work on other computers.Okay... but will it detect it as 2 computers if installed on 2 different OS's?Do you mean you have a dual boot system or VM?Yes if installed on duel boot it will detect it as TWO different installs or even if installed on two different PC running the same OS. The idea is it allows three installs (since you have the 3 license version) on either different computers or duel boots using the same internet CONNECTION. It will identify the different OS installs and databases, not the IP Address or HashKey of the computer(s).I have dualboot. WIN7 and WinXP. I think that is unfair. If they say for 3 PC's it better be for 3 PC's!! That is so dumb... Having another install of Windows, though, means it has a Windows Product Key as well. Even though it is a dual-boot, Kaspersky software cannot properly detect it is a dual-boot. I doubt any security software will allow it as well.I used the Kasparsky. 10 computer license And used it on 10 computers. Some of them. Contains two operating system. |
|
| 1289. |
Solve : RESADERT? |
|
Answer» Ñòàáèëüíûé äîõîä.Hi |
|
| 1290. |
Solve : My computer wont boot up? |
|
Answer» I have a Dell Inspiron 530 running Windows Vista with Trend Micro antivirus software. I suspect a virus because when I turn on my COMPUTER it wont boot up. It is stuck on the main start up screen and F2 and F12 will not WORK as is the keyboard (USB) is not working. My mouse isnt lighting up. I have checked all connections. |
|
| 1291. |
Solve : viruses in restore points? |
|
Answer» If your computer's CURRENT state contains malware, can that malware find it's way into restore points ? If your computer's current state contains malware, can that malware find it's way into restore points ? Not easily, since only certain services have access to the "SYSTEM Volume Information" folder in the root of every drive that is used to save restore points; these services are able to access it because they are run under the LocalSystem Account. of course if malware is able to get access via the LocalSystem Account and is able to parse and change the proprietary and totally subject to change without notice format of the files within that folder then it COULD infect them.Do you know of any times this has happened, with anyone ? good theory Quote from: EEVIAC on April 23, 2010, 11:09:05 AM Do you know of any times this has happened, with anyone ? Can't say I have. Then again I think I can count the number of times I've used system restore on one hand. And usually when it gets to that point I end up reformatting and installing anyway. |
|
| 1292. |
Solve : windows update doesn't want to update? |
|
Answer» HELLO can someone help me? every time i turn on my computer i get a notification that there are new updates when i PRESS on it it tells that windows can't update!!! what shall i do! my windows haven't been updated for more than 8 or 9 MONTHS!Please visit this webpage for a tutorial on downloading and running ComboFix: HTTP://www.bleepingcomputer.com/combofix/how-to-use-combofix See the area: Using ComboFix, and when done, post the log back here. |
|
| 1293. |
Solve : Computer won't let me do ANYTHING? |
|
Answer» A few weeks ago i had something going on with my computer, every time i tried to open anything i would get a message saying the file was infected and to activate virus software, or something to that EFFECT, well i did a system restore and everything was fine, or so i thought, yesterday i turned on my computer and i noticed that my task bar(i think thats what it's called, the bar with the start button and clock and everything) was gone(i was able to get it back by right clicking where it should be and clicking toolbar and desktop, then unclicking desktop), and i wasn't getting an internet connection, i tried to start my netgear PROGRAM to see if i could get it WORKING with no luck, the program would open but it couldn't connect to the network(clearly it's not the internet because i'm on my husbands computer right now, with no problems with the connection) anyway, i thought maybe i still had the bug so i tried to first run mcafee, program wouldn't open, i get no response when i click on it at all, so i decided to run mbam, when i click on that i get "run time ERROR '372' failed to load 'vbalgrid' from vbalgrid6.ocx..." i ran a defrag, spybots, and cc cleaner and repaired everything that needed to be with no luck, my last resort was trying to do another system restore, i figured it fixed the problem once, it will do it again, but nope i click to run the restore and i get a message "system restore is not able to protect your computer. Please restart and then run system restore again" i have tried going into safe mode and running it, along with the virus scans all with no luck, please please please help me!!! |
|
| 1294. |
Solve : After Virus Scan?? |
|
Answer» I was just wondering....after u run a virus scan & it sends things like malaware,adaware,trojans,etc... to the vault....should I DELETE all the things in that vault? Thanks, TammiViruses .... etc are usually deleted. Sometimes making a quarantine. Antivirus often. OPERATE AUTOMATICALLY. Or give options and recommendeddelete them , there is no reason to keep them Quote from: on April 21, 2010, 07:42:36 AM Viruses .... etc are usually deleted. Yes, delete them.you : Quote delete themABSOLUTELY true Quote Viruses .... etc are usually deleted Quote Sometimes making a quarantine.i think if you want to be able to send a file to your antivirus company to have them analyze the file it found you STILL need to have it on your pc. This in turn requires quarantining so file can't spread while you take the time to submit the file. and if it's something like explorer.exe that was infected for example, it's a critical file needed to run windows, you wouldn't want to delete something like this lightly. Quote from: on April 22, 2010, 07:37:38 AM you :Absolutely true why would you want to send a virus file anywhere or to any-one when it can be analyzed here Some antivirus programs have the advantage: predicted proactive. For suspicious files behave like viruses. But they are not scheduled in the anti-virus database (collaboration between the company and the customer)The rule of thumb I use with quarantine is to wait for a while. A week or so. Sometimes legitimate files get into quarantine. If you immediately empty it then you could put yourself into a bad situation without being able to restore something. If they are in quarantine then they shoudl be able to do no harm so leaving them for an extended period is normally okay.yes, that's the safest way to do.I got a few various ways of doing this...but basically deleting them is the best way to go,after about a week...? Thanksa for so many REPLIES & the help.Really appreciated!! Tammi Quote from: tamra747 on April 21, 2010, 07:23:30 AM I was just wondering....after u run a virus scan & it sends things like malaware,adaware,trojans,etc... to the vault....should I DELETE all the things in that vault?Quote from: tamra747 on April 25, 2010, 07:33:59 AM I got a few various ways of doing this...but basically deleting them is the best way to go,after about a week...? thats right there is no reson to have them in you pc , call back any time for help |
|
| 1295. |
Solve : Virus issues? |
|
Answer» Ok i have had a few issues over the past month and have been using the ehelp guides to try and resolve these issues and all seemed ok. Now on Saturday my computer got taken over by a virus called "Vista Anti Malware 2010" and seemed to bed itself in and change a few desktop apps etc etc - it blocked me from using malware bytes and searching solutions on google and it also stopped me from doing a system restore. |
|
| 1296. |
Solve : restart windows with blue screen? |
|
Answer» hye , i m in big trouble.. |
|
| 1297. |
Solve : might be virus problem? |
|
Answer» i m using windows 7 sony vaio vgn-nw270f laptop,
don't you THINK if i install antimalware as you suggested, is going to be conflicting ? is it gonna be problematic i mean it might create some problem with system files ? It will not conflict, only because the free version of MBAM does not have realtime protection. |
|
| 1298. |
Solve : Removal of trojan virus? |
|
Answer» How do i remove trojan from my coomputer?There are programs such as |
|
| 1299. |
Solve : Folders turned into .exe files and not opening by double clicking? |
|
Answer» Ok. Let's try this one.
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt I scanned my system with ESET OnlineScan but it did not find any threat or infected files. [recovering disk space - old attachment deleted by admin] Quote I scanned my system with ESET OnlineScan but it did not find any threat or infected files.Well, that's good news. If there are no other issues, it's time for some clean-up. You can delete Security Check, RootRepeal, Panda USB, Flash Disinfector, HJT. You may keep MBAM, if you wish. Update it and run it weekly to keep your computer clean. To uninstall ComboFix
Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. Uninstall GMER Click on Start > Run and type in or copy/paste all of the Red text into the Run box. %windir%\gmer_uninstall.cmd Click OK to remove GMER. Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. GUIDE: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thanks Dave for all your assistance in removing virus and infections from my system. I am happy that all the threats have been removed however i still have one ISSUE which i am not getting rid off. All my system sub-folders are still missing and i have not got them back till now. There are just applications files left by the same names. How do i get my folders back is a concern. Also i followed the previous steps mentioned but GMER Rootkit Scanner not uninstalling by the command %windir%\gmer_uninstall.cmd getting message windows can not find and make sure you typed the name correctly and try again. Thanks again for all your help. [recovering disk space - old attachment deleted by admin]This is the first time I've used the GMER uninstall command. Just go ahead and delete it from your desktop. As for the folders and sub-folders; is the B: drive a separate drive or is it a partition of the C: drive?I have two drives in my system, B:, E: and F: are partition of a separate drives and D: is a partition of C: drive. I am facing this issue with B:, E:, F:, and D: partitions. Surprisingly my system drive C: is not affected by this issue however its partition D: is affected. Quote Surprisingly my system drive C: is not affected by this issue however its partition D: is affected.The attached picture show the B: drive, not the D: drive I don't believe that this problem is caused by malware or viruses. I feel that you should start a new thread on this forum. I'm assuming that you're running Windows 7. Please mention that you've have gone through the cleaning process on this forum. |
|
| 1300. |
Solve : desparately seeking assistance to remove trojan virus? |
|
Answer» ComboFix 10-04-17.07 - Patrick 04/24/2010 21:38:20.6.2 - x86 |
|