InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 2601. |
Solve : kamsoft.exe? |
|
Answer» Hi, I ran the scans, and they appear to have found and removed it. I've attached the log files for checking.Well, MBAM found the infection, but it wasn't removed (the log says "No action taken"). You should try running the scan again, but this time, make sure the infection is deleted. Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. For Windows XP Systems install the Recovery Console: - If you are using Windows XP and do not already have the Recovery Console installed, please ensure your Internet connection is active (if possible) and click Yes. - If for some reason your Internet is not working click No. - If you are not using Windows XP, you will not be prompted. - When prompted to accept the EULA click OK. - Accept Microsoft's EULA (Click Yes). - When you are told that the RC is installed correctly click YES to continue scanning for malware. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.I ran the MBAM can again, and it came up clean. I've attached the log. I ran ComboFix, and the log is attached, plus a new HT log. Thanks Nick [attachment deleted by admin]Sorry for the delay. As you can imagine, the holidays have been quite busy! Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop DO NOT run it yet! Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: c:\windows\system32\vbsdfe1.dll c:\windows\system32\vbsdfe0.dll 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply along with a new HijackThis log. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze How are things running now?I've attached the latest log files for this one. McAfee displayed an infected file warning again yesterday, unfortunately I didn't get chance to make a note of the infected file. I'll see how it runs now. Cheers Nick [attachment deleted by admin]Well, your logs are looking better. However, I forgot to ask if you recognize these entries at all... O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = HQ.AUTOCAB.COM O17 - HKLM\Software\..\Telephony: DomainName = HQ.AUTOCAB.COM O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = HQ.AUTOCAB.COM Does HQ.AUTOCAB.COM sound familiar? Because McAfee is alerting you of an infected file, try scanning with McAfee and see what it picks up. It could have simply been a rogue internet file, but it doesn't hurt to look.The hq.autocab.com entries are fine, I am aware of them. McAfee came up with another warning today. It said the file was Generic PWS.ak, and the location was in the System Restore files. I turned off system restore, then REBOOTED. I'll run a scan with McAfee to see if it finds anything. Thanks for your help NickOkay, I had a feeling it might be the System Restore files and what you did is exactly what I would've instructed. That clears out the files, so the warning should stop appearing. Just make sure you turn System Restore back on and create a new restore point.Thanks for the advice. It seems OK now. I'll let you know if it throws up anymore virus warnings NickSounds like a plan. |
|
| 2602. |
Solve : Can't load Superantispyware!? |
|
Answer» OK, GOT a virus...... I was following the clean up INSTRUCTIONS on your site and when I got to load superantispyware...... it will not take it. I get a message: windows INSTALLER service COULD not be accessed.........hum! |
|
| 2603. |
Solve : Unable To download any programs? |
|
Answer» Trend Micro would not run, however Kaspersky did scan. Here is the log file:
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- How is the computer running now?Everything is working great!!!!! I just downloaded Firefox for a new browser and am going back to AVG for a virus program. Thank you for your time in helping with this problem. Have a great New Years!!! Your welcome. I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2604. |
Solve : Computer Restarts during SAS? |
|
Answer» Hey everyone. I've been trying to run the basic procedures that you instruct us to use, but I am having a problem. Something is getting in the way of SAS as it scans causing my computer to restart...the msg goes something like this.... |
|
| 2605. |
Solve : AVG Resident shield is constantly reporting tracking cookies? |
|
Answer» This is a fairly recent THING. I get these notices from AVG resident shield about tracking cookies, sometimes 9 or 10 at a time. This is a fairly recent thing. I get these notices from AVG resident shield about tracking cookies, sometimes 9 or 10 at a time.Additional info: Shortly before this began, I attempted to "tweak" my Vista. I visited "Black Viper.com". There is an extensive list of registry(?) changes given to streamline Vista. There are 3 levels suggested. I chose the middle level "tweaked". Shortly thereafter I began getting these tracking cookie notices and Firefox began crashing. I uninstalled Firefox and reinstalled it. It still crashed. LAST night I Uninstalled Firefox again and went back to Black Viper and put all of the Vista services back to the default settings. I reinstalled Firefox. So far everything looks good. No more tracking cookie notices and Firefox hasn't crashed again! Jim I, too, use black viper's list. I would say if you decide you would like to use his list again, just use the "Safe" one. I used that one, my comp has seen a speed increase, and I havent had any problems.I have found out that I can be disconnected from the net. Run Ccleaner. Every time, the AVG Resident Sheild reports several tracking cookies. The pop up windows show the location but I can't get there! C\users\account name\AppData\Roaming\Microsoft\Windows\Cookies\name of cookie I can go C\users\account name but there all I find is a list of folders like in explorer. If I go to roaming under start menu\acct name\roaming It's always empty and no way to go on to \Microsoft... Vista Business Why can't I follow the address sequence? JimRun SUPERAntiSpyware Free. It should get all of them.OK I am running SuperAntiSpyware now. Still. Is there a way to follow the PATH that I posted above? In xp it was easy, I am running Vista Business. JimHere are a few THINGS you might want to check out. Both free. Cookie Viewer - This Power Tool automatically scans your computer, looking for "cookies". It can then display the data STORED in each one and can delete them. Cookie Cruncher - Protects your hard drive from unwanted cookies.Thanks, I will check those out. I ran the SuperAntiSpyware and it found the tracking cookies. When I clicked on the button to put them away, I got the same popup from AVG Resident Shield. Several tracking cookies again. I am running the SAS again now. I got one step closer to following the path I posted above. "View hidden folders" helped. JimSorry, forgot to answer that part. Vista IE7 Cache & Cookies Folder, Temp Directory and History Location |
|
| 2606. |
Solve : o my god i dont know what i am doing? |
|
Answer» okay here goes i download the FILES that i need to install i've gotten to the PART to use the cclean but i cant get it to run on my laptop because my laptop is what is messed up and i cant get it to run Hi, people seeking help in the viruses and malware forum are advised that performing any procedures described by other members who are not malware specialists do so at their own risk. If you would like to become a malware specialist on this forum, you should read this. they follow a specific procedure here that includes the use of specific software. additionally with the information given (other threads/PMs not withstanding) one could not possibly find any conclusive evidence for the presence or absence of "a virus or other dangerous form of malware". lostoncomputers89, I assume your referring to the steps described in here? what exactly happens when you try to run CCleaner? If necessary I believe you can skip that STEP for now. The important part are the logs, so the specialists can determine exactly how to handle your particular situation.Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.
|
|
| 2607. |
Solve : C drive only opens in system 32? |
|
Answer» I opened a email that I thought was a legit one to my mistake I think it was a virus. When I go into my cpu my drives come up but I cannot open them by double clicking, the c drive opens system 32 folder when I do, and my f drive(extra HD) says cannot find '''r' makes srue you typed it correctly and try again. But I can right click and open by choosing the open option. Thanks for any help |
|
| 2608. |
Solve : Do I need to worry?? |
|
Answer» Download the OTMoveIt3 by OldTimer
First let's clean up a little but. Download Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
---------- Now register at http://forums.superantispyware.com/index.php Post the log and explain that the entries are not being deleted in this forum http://forums.superantispyware.com/viewforum.php?f=2I'm confused. I need to keep working on this, even though all my scanners say my computer is clean?Aren't you telling me that SUPERAntiSpyware keeps finding those registyr keys each time you scan?Here's what I wrote at the top of post #16, just above the OTMoveit results: SAS says I'm clean! Thank you very much for sticking with me through this. You've been terrific. Latest results below: Again, I really appreciate your help.Quote SAS says I'm clean! Thank you very much for sticking with me through this. You've been terrific. Latest results below: I totally over looked that and started reading the log Good to hear though Final suggestions. Let me know if you have any questions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown APPLICATIONS from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. Safe surfing... |
|
| 2609. |
Solve : Possible Worm Need some help? |
|
Answer» Hello i think i may have got a worm on my pc. I have nortonAntiVirus 2003 it says nothing is wrong but i think there is. My Pc has been running slower then normal. I also it pop u from random web sites. I deleted my cookies and internet hisory. Im not to sure what to do. |
|
| 2610. |
Solve : gadcom.exe virus? |
|
Answer» I've looked at other posts to try to get rid of the gadcom.exe virus on my computer but most of the things in my hijackthis log don't MATCH what was said to be cleared. I've attached a copy of the log. Which ones am I supposed to CLEAN? |
|
| 2611. |
Solve : ok, they got me....I need help? |
|
Answer» Quote from: bonehead244 on January 06, 2009, 07:56:40 AM "By the way, do you recognize this folder? Okay, probably best to leave it alone then... Your logs look a lot better. How are things running now?everything is running great, and I really, really appreciate the help.....can i make any sort of donation or anything? I do have a question also....when the system was infected i had a hard time getting to my business info.....if i get an external hard drive and keep all my important info on there would that work? I'm assuming there is no o.s. running on that type of drive that it is just for storage and if need be i can just unplug from virus computer and plug it into another computer i should be ok??Quote from: bonehead244 on January 06, 2009, 05:35:33 PM everything is running great, and I really, really appreciate the help.....can i make any sort of donation or anything?Glad to hear it. And although I appreciate the offer, a donation really isn't necessary. Quote from: bonehead244 on January 06, 2009, 05:35:33 PM I do have a question also....when the system was infected i had a hard time getting to my business info.....if i get an external hard drive and keep all my important info on there would that work?You're correct, an external drive typically doesn't have an OS. You can install one, but when you buy one new, it is completely blank and serves entirely as a storage device. I think getting an external hard drive is actually a very good idea. They are relatively cheap and hold a lot of information. And YES, you can simply plug it into another computer when needed. External hard drives can still become infected, but it is less common, and they are usually much easier to disinfect. Also, you should get a decent firewall. You're vulnerable without one, so you should look into getting either ZoneAlarm, Kerio Personal Firewall, or Comodo. They're all good free firewalls. Just be sure you only have one installed at a time! Download the firewall of your choice, disconnect from the internet, disable Windows Firewall, and install your new firewall. And since you no longer need ComboFix, go ahead and uninstall it. Go to Start > Run and type combofix /u (note the space between combofix and /u) and click OK. If that doesn't work, then download OTCleanIt.exe and save it to your Desktop.
so i deleted combofix, and i have running avast scanner.....do i still need malaware, super antispyware , cc cleaner and hijack this, or can i delete those also.....? I will get firewall as you suggest...Go ahead and remove HijackThis if you would like. I would suggest keeping the other three programs, however. They are very good to have on your computer. You should USE them every week or two to help keep your computer clean. You don't have to keep them, of course, but you're better off if you do. |
|
| 2612. |
Solve : MBAM saying my new computer has infections???? |
|
Answer» Hi and just want to say thanks first off. This is a new computer I am the first owner. I scanned it with antimalware and it says I have all of these infections. I'm just wondering if they are real or not because like I said this is a new computer and I have not been to any sites with it. Thanks again for all your help and happy holidays. I couldn't figure out how to put the SASW logs but it came back with nothing. |
|
| 2613. |
Solve : Need help...computer is infected? |
|
Answer» I noticed odd behavior ever since I let someone use my computer the other day. Now I cannot access my drives as well as a few other things are acting wierd. When I double on a any drive letter I get the message Then I opened the hidden files & deleted all "resycled folders" & .ini files on every hard drive..ini files? Do all programs work NORMALLY?Yes everything is working normally, so far. I made sure not to delete the .ini file that belonged to my external HD. The other ones didn't belong in the other drives...they weren't there before all this. Google was a big help with that. If anything acts funny I will post my logs just to be sure. Thanks Carbon.All right then. |
|
| 2614. |
Solve : Please help with removing trojans and rootkits!? |
|
Answer» I experienced some problems with my computer about a week ago when the screen started to flash as well as CONSTANT freezing. Eventually, when I tried using an application such as AIM, my computer shut itself off. When I restarted, my computer picked up that I had trojan horse downloader.delf.BTU and other adware. I am using AVG 8.0 and I've gone through countless spyware/adware programs until I was recommended to come here. I've already gone through the whole removing malware process. Attached are the logs. If there is any more information needed, I will glady offer if I can. I really would not like to have to format my hard drive and restore it with a backup CD, but I'll wait for a response. Thank you! Should I perform another scan with superantiwpyware and anti-malware? No we will run another scan for a final check. First a bit of clean up.
---------- Now run CCleaner and then restart the computer. ---------- Run this online scan. This scanner requires Internet Explorer Use the ESET Nod32 Online Scanner 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Ok. Here is the log from ESET Online Antivirus Scanner. [attachment deleted by admin]Looks good. If everything is running OK we can finish up. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Ok. Finished doing the scans and the updates. I ran a scan with Spyware Doctor and it came up with some files. Attached is a printscreen of what it found. Can these things be deleted from my computer? Other than that, the other spyware programs don't pick up anything. Thanks again! [attachment deleted by admin]Those can be deleted. After doing several scans, neither AVG or Spyware Doctor pick up anything. Looks like I am in the clear. Thanks again for all the help. It saved me from having to start from scratch. Your welcome. Safe surfing... |
|
| 2615. |
Solve : Laptop Display has horizontal lines? |
|
Answer» Hi, I've been trying to fix my computer. I have horizontal lines on the display/monitor in various colors. I have already updated my drivers 'ati" and also updated my media card READER driver. I have tried the various adjustments to my display with no results. I believe I received a VIRUS from a email. I still have the email ONE was photo's the other PART of it was a snip of music. Any information would be highly appreciated.With abuse, laptop monitors can do that. It pretty much means the connectors between the monitor and the laptop's motherboard. |
|
| 2616. |
Solve : spyware guard? |
|
Answer» Part2 of combofix
Files to delete: c:\windows\system32\drivers\e522f5d0.sys Folders to delete: C:\148370517
Avenger log: Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! Error: file "c:\windows\system32\drivers\e522f5d0.sys" not found! Deletion of file "c:\windows\system32\drivers\e522f5d0.sys" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: "C:\148370517" is not a folder! It may instead be a file. Deletion of folder "C:\148370517" failed! Status: 0xc0000103 (STATUS_NOT_A_DIRECTORY) --> use "Files to delete:" instead of "Folders to delete:" to delete an ordinary file Completed script processing. ******************* Finished! Terminate. Thanks again for your time! Mel
---------- Download
Important: Restart the computer before continuing. How is the computer running now?Hello EvilFantasy: The computer is running GREAT I am having 1 problem..... I can't get it to do my laundry Who do I talk to about that? You guys and gals are GREAT I hope you have a good Christmas/Hanaka Thanks again MelYour welcome and Happy Holidays... Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it HARDER for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2617. |
Solve : security opinion? |
|
Answer» Would AVG be a better than Kaspersky internet securty?A short answer is no. Security Suites are normally very bulky which takes up computer resources. The more common method is using layered free solutions. Avast is very LIGHT on resources and has a few functions that others don't, mainly Instant Messaging and * cough P2P Shields. |
|
| 2618. |
Solve : Please help a non-computer savvy person with laymans terms? |
|
Answer» Hi everyone, |
|
| 2619. |
Solve : trojan horge sheur2.gas? |
|
Answer» Getting closer...
Files to delete: c:\windows\Tasks\akqxrtmb.job
Exception Processing Message c0000013 Parameters 75b6bf7c 475b6bf7c 75b6bf7c and it has Cancel try againor continue as options Logfile of The Avenger Version 2.0, (c) by Swandog46 http://swandog46.geekstogo.com Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "c:\windows\Tasks\akqxrtmb.job" deleted successfully. Completed script processing. ******************* Finished! Terminate.OK this should fix the images problem. Reset Web Settings & Default Security Settings Open Internet Explorer and go to Tools > Internet Options then the Advanced tab and then the Reset button under Reset Internet Explorer Settings. Restart Internet Explorer. Is it working correctly now? ----------
. The above procedure will:
---------- 1. Double click OTMoveIt2.exe to launch it. Vista users RIGHT click and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?) 5. Once complete exit out of OTMoveIt2 ---------- Delete temporary files Go to:
When prompted select the C: drive and click OK. Check the boxes for:
Click OK or Enter ---------- Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
I did this step Click START then RUN Now type Combofix /u in the runbox Make sure there's a space between Combofix and /u Then hit Enter. . . The above procedure will: Delete: ComboFix and its associated files and folders. VundoFix backups, if present The C:\Deckard folder, if present The C:_OtMoveIt folder, if present Reset the clock settings. Hide file extensions, if required. Hide System/Hidden files, if required. Set a new, clean Restore Point. But not sure where to find OTMoveit2.exe for the next step. Doesn't it say that the first step deleted it? Sorry, here ya go. Download OTMoveIt3 by OldTimer OTMoveIt3.exe and place it on your desktop. 1. Double click OTMoveIt3.exe to launch it. If using Vista Right-Click OTMoveIt and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
kukolare.dll.tmp;C:\WINDOWS\system32;Probably Trojan.Packed.412;Renamed.; ludoyuja.dll;C:\WINDOWS\system32;Trojan.Siggen.568;Deleted.; miwajiho.dll.tmp;C:\WINDOWS\system32;Probably Trojan.Packed.412;Renamed.; 00068281.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.4660;Deleted.; 00072968.FIL;C:\$VAULT$.AVG;BackDoor.Tdss.30;Deleted.; 00297046.FIL;C:\$VAULT$.AVG;Trojan.Click.19754;Deleted.; 02665515.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.4660;Deleted.; 02666750.FIL;C:\$VAULT$.AVG;Trojan.Click.23749;Deleted.; 02666828.FIL;C:\$VAULT$.AVG;Trojan.Click.23749;Deleted.; 02666921.FIL;C:\$VAULT$.AVG;Trojan.Click.19754;Deleted.; 02666953.FIL;C:\$VAULT$.AVG;Trojan.Click.23749;Deleted.; 02667000.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.4660;Deleted.; 03300937.FIL;C:\$VAULT$.AVG;Trojan.DownLoad.4660;Deleted.; 03305218.FIL;C:\$VAULT$.AVG;Trojan.Siggen.568;Deleted.; A0000008.dll;C:\System Volume Information\_restore{C4634337-28E5-40ED-A7C7-6667EC712853}\RP1;Trojan.Siggen.568;Deleted.; That found a few more infected entries. How is the computer running now? Let me know if you have any questions. Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about BROWSER Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Wow! You must never sleep!! For that I am thankfull! You have been such an incredable help and I learned along the way. I am so glad I came upon this site! I'm working on your last few steps. The computer is already running just about like new. It had been really slow. Thanks!Your welcome. Safe surfing... |
|
| 2620. |
Solve : Computer Freeze at startup? |
|
Answer» I NOTICED a virus on my cpu a couple of days ago. I decided to GET NOD32 antivirus and as I was installing it, my computer froze. So i rebooted and when I WENT to startup, it suddenly it froze. It keeps doing that on startup and Im pretty sure its the virus. Any Fixes?Press F8 before Windows loads, enter safe mode and scan from there. Press F8 before Windows loads, enter safe mode and scan from there. Listen to Raptor. He's good but crazy...(...)THERES no way to do that because everytime i try to go into safe mode, it asks for my username and PASS.....i dont have one..Quote from: murtagh98 on December 22, 2008, 03:31:14 PM theres no way to do that because everytime i try to go into safe mode, it asks for my username and pass.....i dont have one.. Just tried pressing enter? Any account from normal mode is accessible in Safe mode. Do not pick the administrator account... I agree with the above post.Quote from: Imanuel4u on December 22, 2008, 11:55:00 PM I agree with the above post. You rock. |
|
| 2621. |
Solve : Radz services? |
|
Answer» i had followed malware removal help after finding out my computer got infected with radz. the obvious symptom of a changing homepage was fixed. unfortunately, everytime i open IE, "Yahoo!-Radz Services and Internet Cafe" appears. here are the latest logs... |
|
| 2622. |
Solve : MBAM? |
|
Answer» SINCE it was downloaded illegally is that really a concern. Or is your computer more important?I didn't know it was illegal to download the music! I thought it was a good SITE. Why do they allow you to download it then? This doesn't make any sense to me!OK! im going to get rid of it now! I do have a conscience Some of the music is on WMP! will it stay there once i uninstall MP3 rocket? And can you reccomend a good site for music downloads!(legal) Do you think this is where the problem is hiding? I thought i was on to a good thing aswell! Trust me! I guess you cant get ANYTHING for nothing!Quote Some of the music is on WMP! will it stay there once i uninstall MP3 rocket? You won't loose any music. It's stored on your Hard Drive, not on MP3 Rocket or WMP. I just wanted to make a point Quote And can you reccomend a good site for music downloads!(legal) iTunes, Amazon, Napster. You pay a fee for each download which in turn goes to the music companies and artists who own the rights to the music. Quote Do you think this is where the problem is hiding? That is very likely the source of the malware. Quote I guess you cant get anything for nothing! Very true. Nothing is ACTUALLY free. Anything that is copyright protected can't legally be downloaded for free. Even if it's a pro version of Limewire or MP3 Rocket. The music company isn't getting paid for their product so in the US and many other countries it's illegal. It's usually not the software that you have to worry about, BUT there are plenty of untrustworthy file sharing applications out there. It's what you download with it that can easily have extra unwanted baggage. That and badly configured file sharing software can open up your entire computer/network so others can see/steal everything on your PC! Be sure you know just what you are doing before hand, and the potential dangers INVOLVED in P2P/File Sharing. The Dangers Of File Sharing File-sharing dangers involve more than legal troubles |
|
| 2623. |
Solve : IE or Firefox wont work? |
|
Answer» I cannot USE IE or firefox to acess internet. I ran my AVG and it doesnt find any viruses. Same with ad -aware.so I FOLLOWED you forum and I had to download MBAM and the spyware on another computer and transfer them with a thumb drive. When i tried to open them they just wont open. I was able to get hijack this. So I am posting and awaiting to see if you could find a way to help. THANKS for what you do. Oh and when the IE does open I get sent to some DIFFERENT websites really indicating spyware or malware. |
|
| 2624. |
Solve : Looks like I've got it too...? |
|
Answer» Alright, here we go...
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.Here's the results from OTMoveIt3: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== d:\windows\Tasks\mqrhbrgx.job moved successfully. ========== COMMANDS ========== File delete failed. D:\DOCUME~1\David\LOCALS~1\Temp\etilqs_Y3L0cFM2wWZFmfj1laKf scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. D:\WINDOWS\temp\Perflib_Perfdata_55c.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12212008_202519 Files moved on Reboot... File D:\DOCUME~1\David\LOCALS~1\Temp\etilqs_Y3L0cFM2wWZFmfj1laKf not found! File move failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File D:\WINDOWS\temp\Perflib_Perfdata_55c.dat not found! D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_001_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_002_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_003_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_MAP_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\urlclassifier3.sqlite moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\XUL.mfl moved successfully. Now, as for Kaspersky Online Scanner... It downloaded, updated the database, all of that. Ran the scan, then two hours later clicked on 'Save Report As...' and nothing happened, no save prompt or anything, but it did disable the 'Save Report As...' button, so it looks like I'll have to run the scan again and hope it decides to work next time. I did notice that it found one thing in an mp3 file, specifically Trojan-Downloader.WMA.GetCodec.i If that one won't work use this one. Run this online scan. This scanner requires Internet Explorer Use the ESET Nod32 Online Scanner 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Here she be: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3712 (20081222) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.064 (20070717) # EOSSerial=fd3840ba7bace54892a86d93ad8e0055 # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2008-12-23 04:07:18 # local_time=2008-12-22 08:07:18 (-0800, Pacific Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=560628 # found=1 # scan_time=4029 D:\WINDOWS\Help\KEYGEN.EXEprobably a variant of Win32/Agent trojan (unable to clean - deleted)00000000000000000000000000000000
---------- 1. Double click If using Vista Right-Click OTMoveIt and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Amazing skill you have there, evilfantasy! My computer is running like nothing ever happened. Thank you, thank you, thank you!Your welcome. Safe surfing... |
|
| 2625. |
Solve : Lots of problems with Laptop, Windowx XP? |
|
Answer» I am supposed to run CCleaner? Because I did and it deleted a lot of stuff. Was that what I was supposed to do?No I don't need the JavaRA log. Yes running CCleaner is always good. You can run it daily to clean up unwanted junk on your hard drive.Generally, how long does the Kaspersky scan take?It will take at least an hour, possibly more. It does take a while. The Kaspersky scan didn't have anything in the Scan Report. It was blank.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.The computer is running well now. I will try those things. Also, what can I delete and what should I keep of the things I've downloaded over the past 2+ days? Everything is saved to the desktop.Keep MBAM and SAS. Update and run them now and again to make SURE nothing strange has found it's way in. Keep CCleaner, run it daily to keep the HD clean. You can uninstall or delete anything else.Ok thank you. I did the OSI scan and I have red "X"s next to... AOL Instant Messenger 5.x (though AIM 6.x is installed) Adobe Reader 8.X All of my old Adobe FLASH players, I have 10.x Should I follow the instructions to download the updates?Which is SAS?Quote from: slafa23 on December 22, 2008, 05:08:40 PM Which is SAS? SUPERAntiSpyware. --- Check in your add/remove programs for old versions of AIM and uninstall them if found. Do this to remove all unstable older versions of Flash. Download the Flash Player Uninstaller and save it to your desktop. Run the uninstaller program and then REBOOT your computer to complete the uninstall. Download and install the latest version of Flash PlayerIn my Add or Remove programs, there is... Adobe Flash Player 10 ActiveX Adobe Flash Player plugin Adobe Reader 8.1.2 Adobe Shockwave Player Which should I delete?Those are all OK. If you run the uninstaller from above then install the new version you should be OK.Ok will do! Thanks so much for all of your help! |
|
| 2626. |
Solve : Virus or malware infection?? |
|
Answer» I am running a dell inspiron 531s desktop with 2.31gHz and 1.93 GB RAM with Windows xp version 2002 service pack 3.
Open the SDFix folder and double click RunThis.bat to start the script.
[attachment deleted by admin]You have WildTangent on your computer, which I'm not particularly fond of, but it technically isn't an infection. Aside from that, I don't see much. How is your computer running now?It seems to be running fine now. I don't EVEN use wild tangent. that can be removed from the add remove programs page right?You should be able to remove it that way. If not, just let me know and I'll see if I can provide you with some instructions. I believe there may be a removal tool available, but I could be wrong about that. Also, you need to get yourself a decent firewall. I would suggest looking into Comodo, ZoneAlarm, or Kerio Sunbelt. Find one you like, download it, disconnect from the internet, disable Windows Firewall, install your new one and restart. While you're at it, go ahead and uninstall ComboFix. To this, simply go to Start > Run and type in combofix /u (note the space) and click OK. You should also clear out your System Restore points by turning it off and then turning it back on... http://support.microsoft.com/kb/310405I unistalled Combofix and have downloaded and installed Comodo Firewall. I also removed Wild Tangent. Is there anything else I need to do or am I good. Thanks again for all the help.As long as you have done all of my recommended steps, then you are good to go! |
|
| 2627. |
Solve : Symantec Customer Retention? |
|
Answer» GGGGGGGGGGGGRRRRRRRRRRRRRRRR!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! |
|
| 2628. |
Solve : Problems with Trojans.? |
|
Answer» Hi, I've recently been having PROBLEMS with some Trojans that Spybot Search and Destroy detected (All other scanners I used failed to find the problem). They were called Win32.delf and hipoug18 or something. I also found a file at C:\yt8a.exe and C:\windows\system32\yt8a.exe (which labeled it self as a system file) this was closing down my browser every time I opened a page containing "yt8a.exe". |
|
| 2629. |
Solve : tsoc trouble? |
|
Answer» I ran all recommended scans and CCleaner, defrag, fix it, and avast still pop up error with tsoc file? The file or directory\WINDOWS\tsoc.log is corrupt and unreadable. Please run Chkdsk utility. |
|
| 2630. |
Solve : 911 : I think my computer is infected. Help Please.? |
|
Answer» Hello.
Open the SDFix folder and double-click RunThis.bat to start the script.
Here are the SDFIX and HijackThis logs Thank u once again [attachment deleted by admin]You've got one of the most popular infections right now. Go ahead and copy all of the text in the code box below... Code: [Select]Windows Registry Editor Version 5.00 [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sys] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\TDSSserv.sys\modules] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{5BB35C63-98DE-64F1-688B-1347D8136C28}] [-HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{FD8F2F73-8E79-7C1A-6B2B-0702F1C25DA0}] Then open up Notepad and paste the text there. Go to File > Save As and when the window pops up, click on Save As Type and choose All Files. Save this to the desktop as tdss.reg and then close Notepad. Run the tdss.reg file and let the entries be added to your registry. Then download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop. http://download.bleepingcomputer.com/sUBs/ComboFix.exe http://subs.geekstogo.com/ComboFix.exe Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of SECURITY programs that should be disabled and how to disable them. Double-click combofix.exe and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply. NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.Here are the two new logs Thaaaaaaaaank You! [attachment deleted by admin]It's looking a lot better. How are things running now? |
|
| 2631. |
Solve : Internet connection not available but it is? |
|
Answer» I was helping a friend who had not run his AV in two years because he didn't know you were supposed to renew the subscription and never ran spyware remover. I tried to download AVG 8 but IE wouldn't go to the website (Not found) I tried downloading MCAFEE stinger, Again, couldn't open website (Not found). I finally downloaded Spybot and attempted to install in but but when the software went to int Internet for info, I would get a message "Internet connection not available" but it was. I downloaded and installed AdAware but when I went to update the defs, I would get the same message "Internet connection not available". Finally I went to my PC and downloaded AVG * and downloaded it to my Flash DRIVE and installed it and ran on His PC. Updated fine. Found several Trojans and reg viruses and they were removed. Same result when trying to update AdAware or install spybot. PC is running much better but I WANT to fix the problem with Spybot and AdAware. He is running Win XP Home and IE 6.Clik Here and Follow the Instructions...Followed the instructions and the computer is running GREAT and he has no problem connecting to all the site. Found and removed all kinds of malware, spyware, adware and viruses! THANKS!Good News indeed... |
|
| 2632. |
Solve : Having problem with malware (logs attached)? |
|
Answer» My son rcently added the ARES P2P software and afterward STARTED having adjsted backgrounds and un able to get to the internet. We had AVG 7 free addition AV up and running, did some research and found that its no longer really supported so was looking for a suite APPLICATION and installed the http://www.sunbeltsoftware.com/Home-Home-Office/VIPRE/. It initially found the |
|
| 2633. |
Solve : Vundo -Help (getting lots of pop ups.)? |
|
Answer» Was thinking I was done with all this crap but,I let my friend use my PC when I was asleep. |
|
| 2634. |
Solve : I had a lot of similar symptoms here.? |
|
Answer» Thanks to everyone for the posts and help with these symptoms. I had ALL of the following on my machine:
Open the SDFix folder and double click RunThis.bat to start the script.
FYI: I had an error message with the heading- 16 Bit MS-DOS Subsystem: C:\Progra~1\Symantec\S32EVNT1.DLL. An installable Virtual Devise Driver failed Dll initialization. Choose close to terminate the application. Close Ignore After choosing "close" every time this thing popped up in the SDFix process, it seemed to run fine. Please let me know if I need to do anything different with this. I REALLY appreciate your help and time with this. Here is the log: ============================ SDFix: Version 1.231 Run by Melissa on Sat 12/13/2008 at 09:49 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Resetting SecurityProviders Value Rebooting Checking Files : No Trojan Files Found Folder C:\Program Files\kernel - Removed Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-13 21:59:56 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\systemroot\system32\drivers\TDSSpaxt.sys" "group"="file system" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\systemroot\system32\drivers\TDSSpaxt.sys" "group"="file system" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules] "TDSSserv"="\systemroot\system32\drivers\TDSSpaxt.sys" "TDSSl"="\systemroot\system32\TDSSoeqh.dll" "tdssservers"="\systemroot\system32\TDSSosvn.dat" "tdssmain"="\systemroot\system32\TDSSnrsr.dll" "tdsslog"="\systemroot\system32\TDSSriqp.dll" "tdssadw"="\systemroot\system32\TDSScfub.dll" "tdssinit"="\systemroot\system32\TDSSfpmp.dll" "tdssurls"="\systemroot\system32\TDSSnmxh.log" "tdsspanels"="\systemroot\system32\TDSSsbhc.dll" "tdsserrors"="\systemroot\system32\TDSSthym.log" "TDSSproc"="\systemroot\system32\TDSStkdv.log" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\systemroot\system32\drivers\TDSSpaxt.sys" "group"="file system" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules] "TDSSserv"="\systemroot\system32\drivers\TDSSpaxt.sys" "TDSSl"="\systemroot\system32\TDSSoeqh.dll" "tdssservers"="\systemroot\system32\TDSSosvn.dat" "tdssmain"="\systemroot\system32\TDSSnrsr.dll" "tdsslog"="\systemroot\system32\TDSSriqp.dll" "tdssadw"="\systemroot\system32\TDSScfub.dll" "tdssinit"="\systemroot\system32\TDSSfpmp.dll" "tdssurls"="\systemroot\system32\TDSSnmxh.log" "tdsspanels"="\systemroot\system32\TDSSsbhc.dll" "tdsserrors"="\systemroot\system32\TDSSthym.log" "TDSSproc"="\systemroot\system32\TDSStkdv.log" [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TDSSserv.sys] "start"=dword:00000001 "type"=dword:00000001 "imagepath"=str(2):"\systemroot\system32\drivers\TDSSpaxt.sys" "group"="file system" scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\WINDOWS\\system32\\lpyjidcp.exe"="C:\\WINDOWS\\system32\\lpy" "C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.0" "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Disabled:America Online 9.0" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Disabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Disabled:AOL" "C:\\WINDOWS\\explorer.exe"="C:\\WINDOWS\\explorer.exe:*:Enabled:Explorer" "C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:IEXPLORE" "C:\\WINDOWS\\system32\\winlogon.exe"="C:\\WINDOWS\\system32\\winlogon.exe:*:Enabled:winlogon" "C:\\WINDOWS\\system32\\ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe:*:Enabled:ctfmon" "C:\\WINDOWS\\system32\\services.exe"="C:\\WINDOWS\\system32\\services.exe:*:Enabled:services" "C:\\WINDOWS\\system32\\drivers\\svchost.exe"="C:\\WINDOWS\\system32\\drivers\\svchost.exe:*:Disabled:svchost" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL" "C:\\Program Files\\America Online 9.0\\waol.exe"="C:\\Program Files\\America Online 9.0\\waol.exe:*:Enabled:America Online 9.0" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.0" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Finished! This particular infection will occasionally corrupt certain files, so that could be the case for your Symantec. It may require a reinstall or repair. For the time being, download ComboFix from one of the links on this page: http://www.bleepingcomputer.com/combofix/how-to-use-combofix If you can't access the page, you may need to use another computer and then transfer the file. Once it's on your computer, do the following... Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: File:: C:\WINDOWS\system32\drivers\TDSSpaxt.sys C:\WINDOWS\system32\TDSSoeqh.dll C:\WINDOWS\system32\TDSSosvn.dat C:\WINDOWS\system32\TDSSnrsr.dll C:\WINDOWS\system32\TDSSriqp.dll C:\WINDOWS\system32\TDSScfub.dll C:\WINDOWS\system32\TDSSfpmp.dll C:\WINDOWS\system32\TDSSnmxh.log C:\WINDOWS\system32\TDSSsbhc.dll C:\WINDOWS\system32\TDSSthym.log C:\WINDOWS\system32\TDSStkdv.log Registry:: [-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\TDSSserv.sys] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\TDSSserv.sys\modules] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\TDSSserv.sys\modules] [-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\TDSSserv.sys] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply along with a HijackThis log. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeThanks again for your help. ComboFix log is attached - too long to post. Hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:45:57 PM, on 12/14/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\hkcmd.exe C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\svchost.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\notepad.exe C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://products.webroot.com/disp0201.php?pc=64002&rc=3029&oc=11&ps=T&mjv=3&mnv=5&bld=198&sid=&lang=en O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - http://www.linkedin.com/cab/LinkedInContactFinderControl.cab O20 - AppInit_DLLs: karna.dat,rrozxe.dll O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- End of file - 4952 bytes [Saving space - attachment deleted by admin]Well, your HijackThis looks pretty good, but your ComboFix is another story. But no worries, I identified many bad files and we will now instruct ComboFix to remove them. Copy the text in the box below and create a new CFScript file... Code: [Select]KillAll:: Folder:: C:\Program Files\malwareremovalbot File:: C:\Program Files\malwareremovalbot\malwareremovalbot.exe C:\WINDOWS\system32\qomfeffe.dll C:\WINDOWS\system32\f0rb45pe.exe C:\WINDOWS\system32\oygl44yr.exe C:\WINDOWS\system32\r7q7v4nc.exe C:\WINDOWS\system32\sysvxd.exe C:\WINDOWS\system32\karna.dat C:\WINDOWS\system32\rrozxe.dll C:\WINDOWS\system32\geBuRKcB.dll c:\windows\Tasks\At8.job c:\windows\Tasks\At9.job c:\windows\Tasks\At10.job c:\windows\Tasks\At11.job c:\windows\Tasks\At12.job c:\windows\Tasks\At13.job c:\windows\Tasks\At14.job c:\windows\Tasks\At15.job c:\windows\Tasks\At16.job c:\windows\Tasks\At17.job c:\windows\Tasks\At18.job c:\windows\Tasks\At19.job c:\windows\Tasks\At20.job c:\windows\Tasks\At21.job c:\windows\Tasks\At22.job c:\windows\Tasks\At23.job c:\windows\Tasks\At24.job c:\windows\Tasks\At25.job c:\windows\Tasks\At26.job c:\windows\Tasks\At27.job c:\windows\Tasks\At28.job c:\windows\Tasks\At29.job c:\windows\Tasks\At30.job c:\windows\Tasks\At31.job c:\windows\Tasks\At32.job c:\windows\Tasks\At33.job c:\windows\Tasks\At34.job c:\windows\Tasks\At35.job c:\windows\Tasks\At36.job c:\windows\Tasks\At37.job c:\windows\Tasks\At38.job c:\windows\Tasks\At39.job c:\windows\Tasks\At40.job c:\windows\Tasks\At41.job c:\windows\Tasks\At42.job c:\windows\Tasks\At43.job c:\windows\Tasks\At44.job c:\windows\Tasks\At45.job c:\windows\Tasks\At46.job c:\windows\Tasks\At47.job c:\windows\Tasks\At48.job c:\windows\Tasks\At49.job c:\windows\Tasks\At50.job c:\windows\Tasks\At51.job c:\windows\Tasks\At52.job c:\windows\Tasks\At53.job c:\windows\Tasks\At54.job c:\windows\Tasks\At55.job c:\windows\Tasks\At56.job c:\windows\Tasks\At57.job c:\windows\Tasks\At58.job c:\windows\Tasks\At59.job c:\windows\Tasks\At60.job c:\windows\Tasks\At61.job c:\windows\Tasks\At62.job c:\windows\Tasks\At63.job c:\windows\Tasks\At64.job c:\windows\Tasks\At65.job c:\windows\Tasks\At66.job c:\windows\Tasks\At67.job c:\windows\Tasks\At68.job c:\windows\Tasks\At69.job c:\windows\Tasks\At70.job c:\windows\Tasks\At71.job c:\windows\Tasks\At72.job c:\windows\Tasks\MalwareRemovalBot Scheduled Scan.job Registry:: [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=- Then go ahead and follow the same instructions from my previous post. A new HijackThis log isn't necessary, but I would like to see the new ComboFix log.Thank You - Posted below is my new ComboFix log: ComboFix 08-12-14.04 - Melissa 2008-12-15 21:41:26.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.205 [GMT -7:00] Running from: c:\documents and settings\Melissa\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Melissa\Desktop\CFScript.txt * Created a new restore point FILE :: c:\program files\malwareremovalbot\malwareremovalbot.exe c:\windows\system32\f0rb45pe.exe c:\windows\system32\geBuRKcB.dll c:\windows\system32\karna.dat c:\windows\system32\oygl44yr.exe c:\windows\system32\qomfeffe.dll c:\windows\system32\r7q7v4nc.exe c:\windows\system32\rrozxe.dll c:\windows\system32\sysvxd.exe c:\windows\Tasks\At10.job c:\windows\Tasks\At11.job c:\windows\Tasks\At12.job c:\windows\Tasks\At13.job c:\windows\Tasks\At14.job c:\windows\Tasks\At15.job c:\windows\Tasks\At16.job c:\windows\Tasks\At17.job c:\windows\Tasks\At18.job c:\windows\Tasks\At19.job c:\windows\Tasks\At20.job c:\windows\Tasks\At21.job c:\windows\Tasks\At22.job c:\windows\Tasks\At23.job c:\windows\Tasks\At24.job c:\windows\Tasks\At25.job c:\windows\Tasks\At26.job c:\windows\Tasks\At27.job c:\windows\Tasks\At28.job c:\windows\Tasks\At29.job c:\windows\Tasks\At30.job c:\windows\Tasks\At31.job c:\windows\Tasks\At32.job c:\windows\Tasks\At33.job c:\windows\Tasks\At34.job c:\windows\Tasks\At35.job c:\windows\Tasks\At36.job c:\windows\Tasks\At37.job c:\windows\Tasks\At38.job c:\windows\Tasks\At39.job c:\windows\Tasks\At40.job c:\windows\Tasks\At41.job c:\windows\Tasks\At42.job c:\windows\Tasks\At43.job c:\windows\Tasks\At44.job c:\windows\Tasks\At45.job c:\windows\Tasks\At46.job c:\windows\Tasks\At47.job c:\windows\Tasks\At48.job c:\windows\Tasks\At49.job c:\windows\Tasks\At50.job c:\windows\Tasks\At51.job c:\windows\Tasks\At52.job c:\windows\Tasks\At53.job c:\windows\Tasks\At54.job c:\windows\Tasks\At55.job c:\windows\Tasks\At56.job c:\windows\Tasks\At57.job c:\windows\Tasks\At58.job c:\windows\Tasks\At59.job c:\windows\Tasks\At60.job c:\windows\Tasks\At61.job c:\windows\Tasks\At62.job c:\windows\Tasks\At63.job c:\windows\Tasks\At64.job c:\windows\Tasks\At65.job c:\windows\Tasks\At66.job c:\windows\Tasks\At67.job c:\windows\Tasks\At68.job c:\windows\Tasks\At69.job c:\windows\Tasks\At70.job c:\windows\Tasks\At71.job c:\windows\Tasks\At72.job c:\windows\Tasks\At8.job c:\windows\Tasks\At9.job c:\windows\Tasks\MalwareRemovalBot Scheduled Scan.job . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Tasks\At10.job c:\windows\Tasks\At11.job c:\windows\Tasks\At12.job c:\windows\Tasks\At13.job c:\windows\Tasks\At14.job c:\windows\Tasks\At15.job c:\windows\Tasks\At16.job c:\windows\Tasks\At17.job c:\windows\Tasks\At18.job c:\windows\Tasks\At19.job c:\windows\Tasks\At20.job c:\windows\Tasks\At21.job c:\windows\Tasks\At22.job c:\windows\Tasks\At23.job c:\windows\Tasks\At24.job c:\windows\Tasks\At25.job c:\windows\Tasks\At26.job c:\windows\Tasks\At27.job c:\windows\Tasks\At28.job c:\windows\Tasks\At29.job c:\windows\Tasks\At30.job c:\windows\Tasks\At31.job c:\windows\Tasks\At32.job c:\windows\Tasks\At33.job c:\windows\Tasks\At34.job c:\windows\Tasks\At35.job c:\windows\Tasks\At36.job c:\windows\Tasks\At37.job c:\windows\Tasks\At38.job c:\windows\Tasks\At39.job c:\windows\Tasks\At40.job c:\windows\Tasks\At41.job c:\windows\Tasks\At42.job c:\windows\Tasks\At43.job c:\windows\Tasks\At44.job c:\windows\Tasks\At45.job c:\windows\Tasks\At46.job c:\windows\Tasks\At47.job c:\windows\Tasks\At48.job c:\windows\Tasks\At49.job c:\windows\Tasks\At50.job c:\windows\Tasks\At51.job c:\windows\Tasks\At52.job c:\windows\Tasks\At53.job c:\windows\Tasks\At54.job c:\windows\Tasks\At55.job c:\windows\Tasks\At56.job c:\windows\Tasks\At57.job c:\windows\Tasks\At58.job c:\windows\Tasks\At59.job c:\windows\Tasks\At60.job c:\windows\Tasks\At61.job c:\windows\Tasks\At62.job c:\windows\Tasks\At63.job c:\windows\Tasks\At64.job c:\windows\Tasks\At65.job c:\windows\Tasks\At66.job c:\windows\Tasks\At67.job c:\windows\Tasks\At68.job c:\windows\Tasks\At69.job c:\windows\Tasks\At70.job c:\windows\Tasks\At71.job c:\windows\Tasks\At72.job c:\windows\Tasks\At8.job c:\windows\Tasks\At9.job c:\windows\Tasks\MalwareRemovalBot Scheduled Scan.job . ((((((((((((((((((((((((( Files Created from 2008-11-16 to 2008-12-16 ))))))))))))))))))))))))))))))) . 2008-12-13 21:47 . 2008-12-13 21:47577,024--a--c---c:\windows\system32\dllcache\user32.dll 2008-12-13 21:42 . 2008-12-13 21:43d--------c:\windows\ERUNT 2008-12-13 21:29 . 2008-12-13 22:04d--------C:\SDFix 2008-12-08 22:25 . 2008-12-08 22:25d--------c:\program files\Trend Micro 2008-12-08 22:22 . 2008-12-08 22:22410,984--a------c:\windows\system32\deploytk.dll 2008-12-08 22:22 . 2008-12-08 22:2273,728--a------c:\windows\system32\javacpl.cpl 2008-12-08 19:04 . 2008-12-08 19:06d--------c:\program files\Malwarebytes' Anti-Malware 2008-12-08 19:04 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-08 19:04 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys 2008-12-07 21:53 . 2008-12-07 21:53d--------c:\program files\SUPERAntiSpyware 2008-12-07 21:53 . 2008-12-07 21:53d--------c:\documents and settings\Melissa\Application Data\SUPERAntiSpyware.com 2008-12-07 21:53 . 2008-12-07 21:53d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2008-12-07 21:52 . 2008-12-07 21:52d--------c:\program files\Common Files\Wise Installation Wizard 2008-12-02 21:20 . 2008-12-02 21:20d--------c:\program files\Alwil Software 2008-12-01 01:01 . 2004-08-04 00:56380,416--a------c:\windows\system32\irprops.cpl 2008-12-01 01:01 . 2004-08-04 00:56162,304--a------c:\windows\system32\wuaucpl.cpl 2008-12-01 00:52 . 2004-07-17 11:4019,528--a------c:\windows\002405_.tmp 2008-11-30 23:54 . 2008-11-30 23:54d--------c:\program files\CCleaner 2008-11-30 19:37 . 2004-02-10 10:50155,648--a------c:\windows\system32\igfxres.dll 2008-11-30 19:22 . 2004-08-03 23:04156,672--a--c---c:\windows\system32\dllcache\winzm.ime 2008-11-30 19:22 . 2004-08-03 23:04156,672--a--c---c:\windows\system32\dllcache\winsp.ime 2008-11-30 19:22 . 2004-08-03 23:04156,672--a--c---c:\windows\system32\dllcache\winpy.ime 2008-11-30 19:22 . 2004-08-03 23:0479,360--a--c---c:\windows\system32\dllcache\winar30.ime 2008-11-30 19:22 . 2003-07-16 13:2369,120--a--c---c:\windows\system32\dllcache\wingb.ime 2008-11-30 19:22 . 2004-08-03 23:0465,536--a--c---c:\windows\system32\dllcache\winime.ime 2008-11-30 19:22 . 2003-07-16 13:5141,600--a--c---c:\windows\system32\dllcache\weitekp9.dll 2008-11-30 19:22 . 2003-07-16 13:5131,232--a--c---c:\windows\system32\dllcache\weitekp9.sys 2008-11-30 19:20 . 2003-07-16 13:2210,129,408--a--c---c:\windows\system32\dllcache\hwxkor.dll 2008-11-30 19:19 . 2003-07-16 13:2213,463,552--a--c---c:\windows\system32\dllcache\hwxjpn.dll 2008-11-30 19:18 . 2001-08-17 22:362,134,528--a--c---c:\windows\system32\dllcache\EXCH_smtpsnap.dll 2008-11-30 19:18 . 2001-08-17 22:36175,104--a--c---c:\windows\system32\dllcache\EXCH_smtpadm.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt0804.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt0412.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt0411.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt040d.dll 2008-11-30 19:18 . 2003-07-16 13:2319,456--a--c---c:\windows\system32\dllcache\agt0404.dll 2008-11-30 19:18 . 2003-07-16 13:2319,456--a--c---c:\windows\system32\dllcache\agt0401.dll 2008-11-30 19:18 . 2001-08-17 22:365,632--a--c---c:\windows\system32\dllcache\EXCH_adsiisex.dll 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\WindowsShell.Manifest 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\system32\wuaucpl.cpl.manifest 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\system32\sapi.cpl.manifest 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\system32\ncpa.cpl.manifest 2008-11-30 19:06 . 2008-11-30 19:06488-rah-----c:\windows\system32\logonui.exe.manifest 2008-11-30 19:03 . 2004-08-04 00:56949,248--a------c:\windows\system32\msdtctm.dll 2008-11-30 19:02 . 2004-08-04 00:561,251,840--a------c:\windows\system32\comsvcs.dll 2008-11-30 18:26 . 2003-07-16 13:391,086,182-ra------c:\windows\SETE8.tmp 2008-11-30 18:26 . 2003-07-16 13:3013,608-ra------c:\windows\SETF4.tmp 2008-11-30 18:26 . 2003-07-16 13:547,046-ra------c:\windows\SET106.tmp 2008-11-30 16:35 . 2004-08-03 23:076,400--a------c:\windows\system32\drivers\splitter.sys 2008-11-30 16:34 . 2004-08-03 22:5957,472--a------c:\windows\system32\drivers\redbook.sys 2008-11-30 16:34 . 2004-08-03 23:0752,864--a------c:\windows\system32\drivers\dmusic.sys 2008-11-30 16:32 . 2004-08-04 00:56130,048--a------c:\windows\system32\ksproxy.ax 2008-11-30 16:32 . 2004-08-04 00:564,096--a------c:\windows\system32\ksuser.dll 2008-11-30 16:31 . 2004-08-04 01:0140,840--a------c:\windows\system32\drivers\termdd.sys 2008-11-30 16:26 . 2008-11-30 16:26d---s----c:\windows\system32\config\systemprofile\History 2008-11-22 18:22 . 2008-11-22 18:22d--------c:\program files\Western Digital 2008-11-22 18:21 . 2008-11-22 18:21d--------c:\program files\Common Files\eSellerate 2008-11-22 18:19 . 2008-12-02 20:19d---s----c:\documents and settings\All Users\Application Data\Memeo 2008-11-22 18:15 . 2008-11-22 18:15d--------c:\program files\Western Digital Technologies 2008-11-17 17:04 . 2008-11-17 17:04d--------c:\documents and settings\Melissa\Application Data\MalwareRemovalBot . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-09 05:22---------d-----wc:\program files\Java 2008-12-03 05:46---------d-----wc:\documents and settings\All Users\Application Data\avg8 2008-12-02 00:54---------d-----wc:\program files\Common Files\Symantec Shared 2008-11-23 01:22---------d--h--wc:\program files\InstallShield Installation Information 2008-11-17 23:072,002----a-wc:\windows\Sysvxd.exe 2008-11-15 22:34---------d-----wc:\program files\Windows Live Safety Center 2008-11-11 22:59---------d-----wc:\documents and settings\Melissa\Application Data\NLOP . ------- Sigcheck ------- 2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855c:\windows\ServicePackFiles\i386\ip6fw.sys 2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855c:\windows\SoftwareDistribution\Download\6ca7b3a8efd5a9b6f87fff395a2eb989\ip6fw.sys 2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys 2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0c:\windows\system32\drivers\ip6fw.sys . ((((((((((((((((((((((((((((( [emailprotected]_23.31.45.98 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-16 04:48:2616,384----atwc:\windows\Temp\Perflib_Perfdata_56c.dat + 2008-12-16 04:48:4416,384----atwc:\windows\Temp\Perflib_Perfdata_6f8.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-07-23 15:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\system32\\services.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 110160] R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944] R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024] R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560] S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408] . Contents of the 'Scheduled Tasks' folder 2008-12-15 c:\windows\Tasks\At3.job - c:\windows\system32\f0Rb45Pe.exe [] 2008-12-15 c:\windows\Tasks\At4.job - c:\windows\system32\f0Rb45Pe.exe [] 2008-12-15 c:\windows\Tasks\At5.job - c:\windows\system32\f0Rb45Pe.exe [] 2008-12-15 c:\windows\Tasks\At6.job - c:\windows\system32\f0Rb45Pe.exe [] 2008-12-15 c:\windows\Tasks\At7.job - c:\windows\system32\f0Rb45Pe.exe [] 2008-12-16 c:\windows\Tasks\XoftSpySE 2.job - c:\program files\XoftSpySE\XoftSpy.exe [] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = hxxp://products.webroot.com/disp0201.php?pc=64002&rc=3029&oc=11&ps=T&mjv=3&mnv=5&bld=198&sid=⟨=en FF - ProfilePath - c:\documents and settings\Melissa\Application Data\Mozilla\Firefox\Profiles\c95nf8gi.default\ FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157 FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\Microsoft Silverlight\2.0.30523.8\npctrl.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-15 21:48:38 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(616) c:\program files\SUPERAntiSpyware\SASWINLO.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\program files\Cisco Systems\VPN Client\cvpnd.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\Alwil Software\Avast4\ashMaiSv.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Completion time: 2008-12-15 21:53:24 - machine was rebooted ComboFix-quarantined-files.txt 2008-12-16 04:53:20 ComboFix2.txt 2008-12-15 06:32:40 Pre-Run: 57,830,338,560 bytes free Post-Run: 57,821,102,080 bytes free 323--- E O F ---2008-10-27 02:53:48There are still some traces of the infection, but we've worn it down quite a bit. Let's try one more CFScript... Code: [Select]KillAll:: File:: c:\windows\Tasks\At3.job c:\windows\Tasks\At4.job c:\windows\Tasks\At5.job c:\windows\Tasks\At6.job c:\windows\Tasks\At7.job c:\windows\system32\f0Rb45Pe.exe Do the same this with this CFScript as you did with the previous two.TYVM-Sorry my machine was such an infected mess to start with. Pasted below is my new ComboFix Log: ComboFix 08-12-14.04 - Melissa 2008-12-16 21:43:31.3 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.510.222 [GMT -7:00] Running from: c:\documents and settings\Melissa\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Melissa\Desktop\CFScript.txt * Created a new restore point FILE :: c:\windows\system32\f0Rb45Pe.exe c:\windows\Tasks\At3.job c:\windows\Tasks\At4.job c:\windows\Tasks\At5.job c:\windows\Tasks\At6.job c:\windows\Tasks\At7.job . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Tasks\At3.job c:\windows\Tasks\At4.job c:\windows\Tasks\At5.job c:\windows\Tasks\At6.job c:\windows\Tasks\At7.job . ((((((((((((((((((((((((( Files Created from 2008-11-17 to 2008-12-17 ))))))))))))))))))))))))))))))) . 2008-12-13 21:47 . 2008-12-13 21:47577,024--a--c---c:\windows\system32\dllcache\user32.dll 2008-12-13 21:42 . 2008-12-13 21:43d--------c:\windows\ERUNT 2008-12-13 21:29 . 2008-12-13 22:04d--------C:\SDFix 2008-12-08 22:25 . 2008-12-08 22:25d--------c:\program files\Trend Micro 2008-12-08 22:22 . 2008-12-08 22:22410,984--a------c:\windows\system32\deploytk.dll 2008-12-08 22:22 . 2008-12-08 22:2273,728--a------c:\windows\system32\javacpl.cpl 2008-12-08 19:04 . 2008-12-08 19:06d--------c:\program files\Malwarebytes' Anti-Malware 2008-12-08 19:04 . 2008-12-03 19:5238,496--a------c:\windows\system32\drivers\mbamswissarmy.sys 2008-12-08 19:04 . 2008-12-03 19:5215,504--a------c:\windows\system32\drivers\mbam.sys 2008-12-07 21:53 . 2008-12-07 21:53d--------c:\program files\SUPERAntiSpyware 2008-12-07 21:53 . 2008-12-07 21:53d--------c:\documents and settings\Melissa\Application Data\SUPERAntiSpyware.com 2008-12-07 21:53 . 2008-12-07 21:53d--------c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com 2008-12-07 21:52 . 2008-12-07 21:52d--------c:\program files\Common Files\Wise Installation Wizard 2008-12-02 21:20 . 2008-12-02 21:20d--------c:\program files\Alwil Software 2008-12-01 01:01 . 2004-08-04 00:56380,416--a------c:\windows\system32\irprops.cpl 2008-12-01 01:01 . 2004-08-04 00:56162,304--a------c:\windows\system32\wuaucpl.cpl 2008-12-01 00:52 . 2004-07-17 11:4019,528--a------c:\windows\002405_.tmp 2008-11-30 23:54 . 2008-11-30 23:54d--------c:\program files\CCleaner 2008-11-30 19:37 . 2004-02-10 10:50155,648--a------c:\windows\system32\igfxres.dll 2008-11-30 19:22 . 2004-08-03 23:04156,672--a--c---c:\windows\system32\dllcache\winzm.ime 2008-11-30 19:22 . 2004-08-03 23:04156,672--a--c---c:\windows\system32\dllcache\winsp.ime 2008-11-30 19:22 . 2004-08-03 23:04156,672--a--c---c:\windows\system32\dllcache\winpy.ime 2008-11-30 19:22 . 2004-08-03 23:0479,360--a--c---c:\windows\system32\dllcache\winar30.ime 2008-11-30 19:22 . 2003-07-16 13:2369,120--a--c---c:\windows\system32\dllcache\wingb.ime 2008-11-30 19:22 . 2004-08-03 23:0465,536--a--c---c:\windows\system32\dllcache\winime.ime 2008-11-30 19:22 . 2003-07-16 13:5141,600--a--c---c:\windows\system32\dllcache\weitekp9.dll 2008-11-30 19:22 . 2003-07-16 13:5131,232--a--c---c:\windows\system32\dllcache\weitekp9.sys 2008-11-30 19:20 . 2003-07-16 13:2210,129,408--a--c---c:\windows\system32\dllcache\hwxkor.dll 2008-11-30 19:19 . 2003-07-16 13:2213,463,552--a--c---c:\windows\system32\dllcache\hwxjpn.dll 2008-11-30 19:18 . 2001-08-17 22:362,134,528--a--c---c:\windows\system32\dllcache\EXCH_smtpsnap.dll 2008-11-30 19:18 . 2001-08-17 22:36175,104--a--c---c:\windows\system32\dllcache\EXCH_smtpadm.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt0804.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt0412.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt0411.dll 2008-11-30 19:18 . 2003-07-16 13:2419,456--a--c---c:\windows\system32\dllcache\agt040d.dll 2008-11-30 19:18 . 2003-07-16 13:2319,456--a--c---c:\windows\system32\dllcache\agt0404.dll 2008-11-30 19:18 . 2003-07-16 13:2319,456--a--c---c:\windows\system32\dllcache\agt0401.dll 2008-11-30 19:18 . 2001-08-17 22:365,632--a--c---c:\windows\system32\dllcache\EXCH_adsiisex.dll 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\WindowsShell.Manifest 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\system32\wuaucpl.cpl.manifest 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\system32\sapi.cpl.manifest 2008-11-30 19:06 . 2008-11-30 19:06749-rah-----c:\windows\system32\ncpa.cpl.manifest 2008-11-30 19:06 . 2008-11-30 19:06488-rah-----c:\windows\system32\logonui.exe.manifest 2008-11-30 19:03 . 2004-08-04 00:56949,248--a------c:\windows\system32\msdtctm.dll 2008-11-30 19:02 . 2004-08-04 00:561,251,840--a------c:\windows\system32\comsvcs.dll 2008-11-30 18:26 . 2003-07-16 13:391,086,182-ra------c:\windows\SETE8.tmp 2008-11-30 18:26 . 2003-07-16 13:3013,608-ra------c:\windows\SETF4.tmp 2008-11-30 18:26 . 2003-07-16 13:547,046-ra------c:\windows\SET106.tmp 2008-11-30 16:35 . 2004-08-03 23:076,400--a------c:\windows\system32\drivers\splitter.sys 2008-11-30 16:34 . 2004-08-03 22:5957,472--a------c:\windows\system32\drivers\redbook.sys 2008-11-30 16:34 . 2004-08-03 23:0752,864--a------c:\windows\system32\drivers\dmusic.sys 2008-11-30 16:32 . 2004-08-04 00:56130,048--a------c:\windows\system32\ksproxy.ax 2008-11-30 16:32 . 2004-08-04 00:564,096--a------c:\windows\system32\ksuser.dll 2008-11-30 16:31 . 2004-08-04 01:0140,840--a------c:\windows\system32\drivers\termdd.sys 2008-11-30 16:26 . 2008-11-30 16:26d---s----c:\windows\system32\config\systemprofile\History 2008-11-22 18:22 . 2008-11-22 18:22d--------c:\program files\Western Digital 2008-11-22 18:21 . 2008-11-22 18:21d--------c:\program files\Common Files\eSellerate 2008-11-22 18:19 . 2008-12-02 20:19d---s----c:\documents and settings\All Users\Application Data\Memeo 2008-11-22 18:15 . 2008-11-22 18:15d--------c:\program files\Western Digital Technologies 2008-11-17 17:04 . 2008-11-17 17:04d--------c:\documents and settings\Melissa\Application Data\MalwareRemovalBot . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-09 05:22---------d-----wc:\program files\Java 2008-12-03 05:46---------d-----wc:\documents and settings\All Users\Application Data\avg8 2008-12-02 00:54---------d-----wc:\program files\Common Files\Symantec Shared 2008-11-23 01:22---------d--h--wc:\program files\InstallShield Installation Information 2008-11-17 23:072,002----a-wc:\windows\Sysvxd.exe 2008-11-15 22:34---------d-----wc:\program files\Windows Live Safety Center 2008-11-11 22:59---------d-----wc:\documents and settings\Melissa\Application Data\NLOP . ------- Sigcheck ------- 2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855c:\windows\ServicePackFiles\i386\ip6fw.sys 2004-08-03 23:00 29056 4448006b6bc60e6c027932cfc38d6855c:\windows\SoftwareDistribution\Download\6ca7b3a8efd5a9b6f87fff395a2eb989\ip6fw.sys 2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0c:\windows\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\ip6fw.sys 2008-04-13 11:53 36608 3bb22519a194418d5fec05d800a19ad0c:\windows\system32\drivers\ip6fw.sys . ((((((((((((((((((((((((((((( [emailprotected]_23.31.45.98 ))))))))))))))))))))))))))))))))))))))))) . + 2008-12-17 04:50:3216,384----atwc:\windows\Temp\Perflib_Perfdata_630.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360] "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-13 1695232] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-02-10 155648] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-02-10 118784] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-18 81000] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2008-07-23 15:28 352256 c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\WINDOWS\\system32\\services.exe"= R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-02 110160] R1 SASDIFSV;SASDIFSV;\??\c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2008-11-17 8944] R1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys [2008-11-17 55024] R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-02 20560] S3 SASENUM;SASENUM;\??\c:\program files\SUPERAntiSpyware\SASENUM.SYS [2008-11-17 7408] . Contents of the 'Scheduled Tasks' folder 2008-12-17 c:\windows\Tasks\XoftSpySE 2.job - c:\program files\XoftSpySE\XoftSpy.exe [] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = hxxp://products.webroot.com/disp0201.php?pc=64002&rc=3029&oc=11&ps=T&mjv=3&mnv=5&bld=198&sid=⟨=en FF - ProfilePath - c:\documents and settings\Melissa\Application Data\Mozilla\Firefox\Profiles\c95nf8gi.default\ FF - prefs.js: browser.startup.homepage - hxxp://go.microsoft.com/fwlink/?LinkId=69157 FF - plugin: c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeploytk.dll FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npjp2.dll FF - plugin: c:\program files\Microsoft Silverlight\2.0.30523.8\npctrl.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npdeploytk.dll . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-16 21:50:42 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(648) c:\program files\SUPERAntiSpyware\SASWINLO.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Alwil Software\Avast4\aswUpdSv.exe c:\program files\Alwil Software\Avast4\ashServ.exe c:\program files\Cisco Systems\VPN Client\cvpnd.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE c:\program files\Alwil Software\Avast4\ashMaiSv.exe c:\program files\Alwil Software\Avast4\ashWebSv.exe . ************************************************************************** . Completion time: 2008-12-16 21:55:26 - machine was rebooted ComboFix-quarantined-files.txt 2008-12-17 04:55:22 ComboFix2.txt 2008-12-16 04:53:27 ComboFix3.txt 2008-12-15 06:32:40 Pre-Run: 57,796,665,344 bytes free Post-Run: 57,786,298,368 bytes free 183--- E O F ---2008-10-27 02:53:48No need to apologize. Everything looks much better, by the way. How are things running now? Since you no longer need ComboFix, go ahead and uninstall it. Go to Start > Run and type combofix /u (note the space between combofix and /u) and click OK. If that doesn't work, then download OTCleanIt.exe and save it to your Desktop.
Then clean out your System Restore. This is to remove any infected files that have been backed up by Windows. Please follow these steps... 1. Go to Start > Programs > Accessories > System Tools > System Restore 2. Click on System Restore Settings. 3. Check Turn off System Restore and click OK. 4. Restart your computer. 5. Follow steps 1 and 2 to return to the settings, uncheck Turn off System Restore, and click OK. 6. Create a new restore point and close the program. System Restore will now be active again. If you would like to learn more about System Restore, go here.Everything is working great. The computer's speed is much better, no mysterious error messages, and all programs are working perfectly. I have a new restore point created and things look good. Just wanted to say thank you to CBMatt(Chris?) for your help through this. You are very clear and helpful with your instruction, and make people's frustrating problems much EASIER. Also with your help I have learned a lot about battling viruses through this experience. Good Job, I will recommend this site to all. Thank You again and have a wonderful holiday season. CBMatt and Chris are both appropriate when referring to me. I'll respond to either one. Heh. Thank you for the kind words, Melissa (the name is in your logs, so I assume it's correct?). I'm very glad to hear that things are going well now. |
|
| 2635. |
Solve : I have Win32.Worm.KdCrypt?? |
|
Answer» I think its attaching itself to my video drivers , because ad-aware found it , and as soon as i deleted it from my system , i rebooted and i had no drivers installed ....... |
|
| 2636. |
Solve : computer hangs during long processes? |
|
Answer» Quote I could not get a couple of the players updated Adobe Flash Player? Download the Flash Player Uninstaller and save it to your desktop. Run the uninstaller program and then reboot your computer to complete the uninstall. Download and install the LATEST version of Flash Player OK FINALLY got the clean scan from secunia. Anything ELSE you can THINK of?That should be it. Safe SURFING... |
|
| 2637. |
Solve : Virus? Don't worry - avoid Royal Hospital? |
|
Answer» Virus? Don't worry - avoid Royal Hospital. |
|
| 2638. |
Solve : quarantine and heal virus? |
|
Answer» please help. i NEED VISUAL basic source CODE for the ANTIVIRUS i am currently developing. |
|
| 2639. |
Solve : Please Help Me I Have A Virus I Cant Remove? |
|
Answer» hi i recentlly got a virus on my computer an i desperatlly need to get rid of it. i have followed all the steps befor posting this TOPIC. any help would be great. thanks. xavier20 |
|
| 2640. |
Solve : C drive display? |
|
Answer» Hey, wait a sec. Hey, wait a sec.I believe the original issue was solved. Now it is after TOPIC banter!Believe this topic is getting hit a lot because it's on the top results for related winthb.exe SEARCHES. If you've stumbled upon this thread and are encountering an issue with this file I suggest CREATING a new topic. Since the original posters issue appears to be resolved I'm locking this thread. |
|
| 2641. |
Solve : Tried your first post, and "ALL" anti-virus/Spyware/Malware downloads/inst fail? |
|
Answer» Quote Now that you're all fixed you may also want to consider UPDATING Windows to SP3 as well. I'll TRY that! I hadn't had room on my hard drive till I deleted the Nero to download SP3. Should be ABLE to do that now. RPThe SP3 installer is under 500 MB. If you have to clear out space to accomodate it, you may want to look into getting another hard drive. With Christmas just around the corner, there are all sorts of great deals. |
|
| 2642. |
Solve : Why me? please help!!? |
|
Answer» This is actually very puzzling. You have an odd case of malware and I'm having a TOUGH time pinpointing it. A good challenge.... Do you think Llimewire would have anything to do with any of this? The last log said it was either infected or warez. Either way it's best to get rid of it until we figure out what's going on. You never can be sure what your downloading on Limewire... Are the pop-ups still coming? Install a new copy of ComboFix and post the log please. Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log and a new HIJACKTHIS log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Done. Yes there are still popups, the one in particular. Regestry defender. Also my yahoo search engine is still on the fritz. I can type something to look for and it gives me ten different sites that don't have a thing to do with what I'm looking for?.. Also when I click to open this forum, it gives me the windows cannot display this webpage... again. So I have to click refresh. [Saving space - attachment deleted by admin]This is definitely a challenge, and that file came back. Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C Code: [Select]KillAll:: Folder:: C:\Lop SD File:: c:\windows\system32\dispex32.dll Registry:: [-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\34b80127509] 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freezeThis seems to work pretty good. It does say file deleted on the log so fingers crossed! Question, when I restart my computer after it says Vaio and plays a little tune, it goes to a black screen for a split second and prompts me to start with windows xp, or something else, do you think this will stop? [Saving space - attachment deleted by admin]One option is Win XP and the other is the Recovery Console right? The Recovery Console was installed by ComboFix. You now can recover your PC if something goes wrong. This next scan will take a while, usually well more than an hour so if you want to wait until tomorrow then that's fine. I'll be around. Download DrWeb CureIt & save it to your desktop. Scan with DrWeb-CureIt as follows:
ComboFix.exe\32788R22FWJFW\psexec.cfexe;C:\Documents and Settings\Carl Dant\Desktop\ComboFix.exe;Program.PsExec.171;; ComboFix.exe;C:\Documents and Settings\Carl Dant\Desktop;Archive contains infected objects;Moved.; SDFix.exe\SDFix\apps\Process.exe;C:\Documents and Settings\Carl Dant\Desktop\SDFix.exe;Tool.Prockill;; SDFix.exe;C:\Documents and Settings\Carl Dant\Desktop;Archive contains infected objects;Moved.; pifCrawl.exe;C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08};Trojan.Swizzor.based;Deleted.; aolcinst.exe\core.cab\GTDOWNAO_106.ocx;C:\Program Files\Online Services\AOL Setup\comps\coach\aolcinst.exe;Adware.Gdown;; aolcinst.exe;C:\Program Files\Online Services\AOL Setup\comps\coach;Archive contains infected objects;Moved.; A0001873.EXE;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Program.PsExec.170;; A0001922.exe\32788R22FWJFW\psexec.cfexe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13\A0001922.exe;Program.PsExec.171;; A0001922.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Archive contains infected objects;Moved.; A0001923.exe\SDFix\apps\Process.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13\A0001923.exe;Tool.Prockill;; A0001923.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Archive contains infected objects;Moved.; A0001924.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Trojan.Swizzor.based;Deleted.; A0001925.exe\core.cab\GTDOWNAO_106.ocx;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13\A0001925.exe;Adware.Gdown;; A0001925.exe;C:\System Volume Information\_restore{E28BBD50-0570-405B-9B46-4310F2CE5171}\RP13;Archive contains infected objects;Moved.; Actually all of that was either already in a quarantined folder or very low level adware, plus corrupted System Restore Points. Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
---------- How is the computer running now?Wow, looks like alot of people have problems. You guys are great! Well everything looks fine so far. Startup is a little slow, but it does say that it will be slow for a reboot or two, so we'll see. What do you know about DVD fab decrypter? Have you heard of it causing any trouble?I wouldn't trust it. See HERE ---------- Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide . ---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
| 2643. |
Solve : snapin.js Failed to Load? |
|
Answer» Okay, going to try the next step. I did GO to the Java website and found the error message I had been getting, 1500 error message. It said that this could be because of an earlier installation that had been aborted before it was finished and to install microsoft installation clean up utility to clean it but when I try to install it I get the same message and can't install. Hope this next step works.Okay, I went to Java and found the error message I had been getting... 1500 error message. It said that this is most likely caused be an earlier installation of a program that was aborted before installation was completed. It said to install Microsoft installation clean up utility and run it but when I try to install it I get the same message. I'm going to try the next step but probably won't get to it tonight. I'm burned out. I'll try tomorrow. Thanks again for all of your help.Quote from: evilfantasy on December 02, 2008, 04:12:53 PM .js is a Java file. What version of Java do you have installed? The most recent is Sun Java Runtime Environment 6 Update 11 http://www.majorgeeks.com/Sun_Java_Runtime_Environment_d4648.html .js is javascript, not java- it doesn't use the java run-time and rather is a client-side scripting solution interpreted by the browser. IE uses the Active Scripting Host to interpret all script code, which in turn uses jscript.dll to parse/interpret the javascript files. In a Similar vein, VBScript is not Visual Basic. Java files would be .java (source) and .class, (as well as .jar, and probably some I missed). The fix for this problem might be to re-register the jscript.dll file. How it would have gotten unregistered is a mystery. re-registering would be performed by running the command "regsvr32 jscript.dll" I have ran the combofix and hifack this but now it won't LET me back on the web to post the log. I am connected to the internet but it will not load a page... any page!ComboFix 08-12-02.02 - Teresa 2008-12-03 23:02:09.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.1063 [GMT -6:00] Running from: c:\users\Teresa\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2008-11-04 to 2008-12-04 ))))))))))))))))))))))))))))))) . 2008-12-03 22:32 . 2008-12-03 22:32d--------c:\windows\Sun 2008-12-02 19:23 . 2008-12-02 19:23d--------c:\users\Teresa\AppData\Roaming\Malwarebytes 2008-12-02 19:23 . 2008-12-02 19:23d--------c:\users\All Users\Malwarebytes 2008-12-02 19:23 . 2008-12-02 19:23d--------c:\programdata\Malwarebytes 2008-12-02 19:23 . 2008-12-02 19:23d--------c:\program files\Malwarebytes' Anti-Malware 2008-12-02 19:23 . 2008-10-22 16:1038,496--a------c:\windows\System32\drivers\mbamswissarmy.sys 2008-12-02 19:23 . 2008-10-22 16:1015,504--a------c:\windows\System32\drivers\mbam.sys 2008-12-02 18:36 . 2008-12-02 18:36d--------c:\program files\Trend Micro 2008-11-29 04:36 . 2008-11-29 04:36d--------c:\users\All Users\Symantec 2008-11-29 04:36 . 2008-11-29 04:36d--------c:\programdata\Symantec 2008-11-27 16:42 . 2008-11-27 16:42d--------c:\users\Teresa\AppData\Roaming\CyberLink 2008-11-26 22:28 . 2008-10-21 21:43241,152--a------c:\windows\System32\PortableDeviceApi.dll 2008-11-26 22:28 . 2008-10-21 21:43160,768--a------c:\windows\System32\PortableDeviceTypes.dll 2008-11-26 22:28 . 2008-10-21 21:4395,232--a------c:\windows\System32\PortableDeviceClassExtension.dll 2008-11-26 22:27 . 2008-08-27 21:24712,192--a------c:\windows\System32\WindowsCodecs.dll 2008-11-26 22:27 . 2008-08-27 21:24425,472--a------c:\windows\System32\PhotoMetadataHandler.dll 2008-11-26 22:27 . 2008-08-27 21:24347,136--a------c:\windows\System32\WindowsCodecsExt.dll 2008-11-26 22:06 . 2008-10-20 23:161,645,568--a------c:\windows\System32\connect.dll 2008-11-23 23:32 . 2008-12-03 22:34d--------c:\program files\Norton Security Scan 2008-11-23 23:32 . 2008-11-29 08:39d--------c:\program files\Common Files\Symantec Shared 2008-11-23 22:43 . 2008-12-01 21:02d--------c:\users\All Users\Google Updater 2008-11-23 22:43 . 2008-12-01 21:02d--------c:\programdata\Google Updater 2008-11-14 09:34 . 2008-10-16 15:131,809,944--a------c:\windows\System32\wuaueng.dll 2008-11-14 09:34 . 2008-10-16 14:561,524,736--a------c:\windows\System32\wucltux.dll 2008-11-14 09:34 . 2008-10-16 15:12561,688--a------c:\windows\System32\wuapi.dll 2008-11-14 09:34 . 2008-10-16 14:5583,456--a------c:\windows\System32\wudriver.dll 2008-11-14 09:34 . 2008-10-16 15:0951,224--a------c:\windows\System32\wuauclt.exe 2008-11-14 09:34 . 2008-10-16 15:0943,544--a------c:\windows\System32\wups2.dll 2008-11-14 09:34 . 2008-10-16 15:0834,328--a------c:\windows\System32\wups.dll 2008-11-14 09:33 . 2008-10-16 14:08162,064--a------c:\windows\System32\wuwebv.dll 2008-11-14 09:33 . 2008-10-16 13:5631,232--a------c:\windows\System32\wuapp.exe 2008-11-13 19:54 . 2008-09-09 21:251,341,440--a------c:\windows\System32\msxml6.dll 2008-11-13 19:54 . 2008-09-09 21:212,048--a------c:\windows\System32\msxml6r.dll 2008-11-13 19:46 . 2008-08-25 19:11211,456--a------c:\windows\System32\drivers\mrxsmb10.sys 2008-11-13 19:41 . 2008-09-04 22:481,194,496--a------c:\windows\System32\msxml3.dll 2008-11-13 19:41 . 2008-09-04 22:452,048--a------c:\windows\System32\msxml3r.dll 2008-11-07 15:58 . 2008-08-05 21:191,244,672--a------c:\windows\System32\mcmde.dll 2008-11-07 15:58 . 2008-08-05 21:27428,032--a------c:\windows\System32\EncDec.dll 2008-11-07 15:58 . 2008-08-05 21:21292,352--a------c:\windows\System32\psisdecd.dll 2008-11-07 15:58 . 2008-08-05 21:21217,088--a------c:\windows\System32\psisrndr.ax 2008-11-07 15:58 . 2008-08-05 21:26177,152--a------c:\windows\System32\mpg2splt.ax 2008-11-07 15:58 . 2008-08-05 21:2080,896--a------c:\windows\System32\MSNP.ax 2008-11-07 15:58 . 2008-08-05 21:1968,608--a------c:\windows\System32\Mpeg2Data.ax 2008-11-07 15:58 . 2008-08-05 21:1957,856--a------c:\windows\System32\MSDvbNP.ax . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-12-04 04:35---------d-----wc:\users\Teresa\AppData\Roaming\LimeWire 2008-12-03 01:05---------d-----wc:\program files\LimeWire 2008-11-29 15:24---------d-----wc:\program files\Common Files\Adobe 2008-11-24 04:50---------d-----wc:\program files\Google 2008-11-24 02:56---------d-----wc:\programdata\McAfee 2008-11-24 02:56---------d-----wc:\program files\McAfee 2008-11-16 21:521,368----a-wc:\users\Teresa\AppData\Roaming\wklnhst.dat 2008-10-21 03:18---------d-----wc:\programdata\Dell 2008-10-20 15:12---------d-----wc:\program files\Windows Mail 2008-10-02 03:49826,368----a-wc:\windows\System32\wininet.dll 2008-10-02 03:4956,320----a-wc:\windows\System32\iesetup.dll 2008-10-02 03:4952,736----a-wc:\windows\AppPatch\iebrshim.dll 2008-10-02 03:4826,624----a-wc:\windows\System32\ieUnatt.exe 2008-09-18 04:353,505,208----a-wc:\windows\System32\ntkrnlpa.exe 2008-09-18 04:353,470,904----a-wc:\windows\System32\ntoskrnl.exe 2008-09-18 02:032,027,520----a-wc:\windows\System32\win32k.sys 2008-08-21 22:22174--sha-wc:\program files\desktop.ini 2008-07-15 14:1676--sh--rc:\windows\CT4CET.bin 2008-09-02 22:5116,384--sha-wc:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 2008-09-02 22:5132,768--sha-wc:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 2008-09-02 22:5116,384--sha-wc:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading POINTS )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-11-23 39408] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440] "WindowsWelcomeCenter"="oobefldr.dll" [2006-11-02 c:\windows\System32\oobefldr.dll] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ECenter"="c:\dell\E-Center\EULALauncher.exe" [2008-02-28 17920] "Apoint"="c:\program files\DellTPad\Apoint.exe" [2007-09-24 159744] "OEM02Mon.exe"="c:\windows\OEM02Mon.exe" [2007-12-02 36864] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2008-01-01 405504] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-03-28 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-03-28 166424] "Persistence"="c:\windows\system32\igfxpers.exe" [2008-03-28 133656] "DELL Webcam Manager"="c:\program files\Dell\Dell Webcam Manager\DellWMgr.exe" [2007-07-27 118784] "BROADCOM Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-05-19 3444736] "Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-07-15 29744] "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384] "PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2007-12-21 184320] "Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Elements 6.0\apdproxy.exe" [2007-09-10 67488] "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-08-13 206064] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2008-07-15 50688] QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-02-22 1193240] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\NOTIFY\GoToAssist] 2008-07-15 08:29 10536 c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GOEC62~1.DLL [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{801B9625-A24B-45D4-8FBE-6420E1EAF859}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect "{00BCA362-2EB9-496E-8083-B3AEE8DCDC5F}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program "{42C42AD2-512B-493B-B732-C15ACB7E560E}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine "{A0C5762B-6DFB-429C-842D-028D124D4FF6}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server "{8B8C92C1-A8DD-4F82-A861-6F7EB28D0043}"= Disabled:UDP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server "{9EB28302-AE7A-4588-AD6A-5BF87ED34129}"= Disabled:TCP:c:\program files\Adobe\Photoshop Elements 6.0\AdobePhotoshopElementsMediaServer.exe:Adobe Photoshop Elements Media Server "{A3D04AF9-C798-4511-A5FC-DBCC9682FCC5}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire "{1C936232-0EEB-4ADA-9003-AF0B8F7AE7AB}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| R2 AdobeActiveFileMonitor6.0;Adobe Active File Monitor V6;c:\program files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe [2007-09-10 124832] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe [2008-07-15 73728] R3 OEM02Dev;Creative Camera OEM002 Driver;c:\windows\system32\DRIVERS\OEM02Dev.sys [2008-07-15 235648] R3 OEM02Vfx;Creative Camera OEM002 Video VFX Driver;c:\windows\system32\DRIVERS\OEM02Vfx.sys [2008-07-15 7424] S3 GoToAssist;GoToAssist;"c:\program files\Citrix\GoToAssist\514\g2aservice.exe" Start=service [2008-07-15 16680] *Newly Created Service* - CATCHME *Newly Created Service* - PROCEXP90 . Contents of the 'Scheduled Tasks' folder 2008-12-02 c:\windows\Tasks\Norton Security Scan for Teresa.job - c:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18] . ************************************************************************** catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-03 23:04:09 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-12-03 23:04:58 ComboFix-quarantined-files.txt 2008-12-04 05:04:55 Pre-Run: 69,888,073,728 bytes free Post-Run: 69,935,267,840 bytes free 154--- E O F ---2008-12-02 00:57:55 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:36:48 PM, on 12/2/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16757) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\DellTPad\Apoint.exe C:\Windows\OEM02Mon.exe C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe C:\Windows\System32\WLTRAY.EXE C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe C:\Program Files\Dell Support Center\bin\sprtcmd.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Program Files\LimeWire\LimeWire.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\DellTPad\ApMsgFwd.exe C:\Program Files\DellTPad\HidFind.exe C:\Program Files\DellTPad\Apntex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Dell Support Center\gs_agent\dsc.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\SearchFilterHost.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [ECenter] C:\Dell\E-Center\EULALauncher.exe O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [DELL Webcam Manager] "C:\Program Files\Dell\Dell Webcam Manager\DellWMgr.exe" /s O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe" O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 6.0\apdproxy.exe" O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O13 - Gopher Prefix: O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/pr01/resources/VistaMSNPUplden-us.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{293AEFA6-5DB0-4D09-900D-D8F667B7A710}: NameServer = 198.6.100.218 198.6.1.218 O17 - HKLM\System\CS1\Services\Tcpip\..\{293AEFA6-5DB0-4D09-900D-D8F667B7A710}: NameServer = 198.6.100.218 198.6.1.218 O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll O23 - Service: Adobe Active File Monitor V6 (AdobeActiveFileMonitor6.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Desktop Manager 5.7.801.7324 (GoogleDesktopManager-010708-104812) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 8273 bytesBC_Programmer, To do that do I go to Accessories, Command Prompt... then what do I type? Go Start > Run, type in: cmd Click OK. Run following commands, hitting Enter after each one: regsvr32 jscript.dll regsvr32 vbscript.dll regsvr32 /i mshtml.dll Restart the PC and see if it works. i tried that and it didn't work. are there any spaces when typing in the commands?Just copy each line and to paste it press ctrl and V both at the same time.After pasteing the first two commands, I got this message....The module "jscript.dll" was loaded but the call to DllRegisterServer failed with error code 0x80004005 I got this message after entering the last command...The module "mshtml.dll" was loaded but the entry-point DllRegisterServer was not found. Make sure that "mshtml.dll" is a valid DLL or OCX file then try again. |
|
| 2644. |
Solve : Big Problems....I think???? |
|
Answer» Evil, just finished the last steps... everything seems back to normal... Thankyou so much, you and this site are GREAT!!! What do you THINK about MCAFEE?? should i remove it and go with something ELSE? |
|
| 2645. |
Solve : All kinds of troule? |
|
Answer» I am frustrated.... Here is what i have.. windows xp home.. it is an HP. laptop. i have not EVEN used a quarter of it yet... now here is the troubles... i can not get any of my virus programs to connect to the internet to update.. i am using AVG free edition... i also have Malwarebytes it wont even run now. and i can not get it to uninstall to reinstall it.. i just installed AntiVirPE Classic and it found one trojian.. i deleated a bunch of files from the other owner and i can not get his profile of the system. i TRIED to get the system to run the defrag and that wont run..last nigh i was surfing and my searches were being hijacked to jump and MAXIUM.. i closed the windows before they got there. i dont use internet explorer.. i am using firefox. oh yea.. many of my windows come up with the "cant find window" Can Any one help? |
|
| 2646. |
Solve : Facebook Virus? |
|
Answer» http://www.pcworld.com/article/155017/facebook_virus_turns_your_computer_into_a_zombie.html Did you guys hear about the latest facebook virus? ANOTHER reason why I don't use it. It just MEANS more business for computer shops. KEEPS them in business. It's not so MUCH if you use Facebook or not, but if are knowledgeable enough to know it's FAKE. |
|
| 2647. |
Solve : hacked yahoo nick? |
|
Answer» can anyone tell why my brother 's yahoo's nick was hacked, he said that his yahoo' nick was unable to sign in but can sign in with the other? so how can people hack his previously nick |
|
| 2648. |
Solve : blocking advertisements? |
|
Answer» How do I BLOCK ADS that COME from the INTERNET PROTOCAL 127.0.0.1 |
|
| 2649. |
Solve : HELP ME PLEASE...log in profile is invalid.? |
|
Answer» I have a SONY VAIO with windows vista. I bought the lap top less than a year AGO, brand new. |
|
| 2650. |
Solve : a huge amount of anti-virus reaserch/study im doing? |
|
Answer» i just need links to safe download sites, virus download sites, and virus scan sites so i can do a massave RESEARCH on anti-viruses and ect. |
|