InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3201. |
Solve : do i still need a firewall/antivirus?? |
|
Answer» I used to always rock avast and zone alarm. I would never even consider running a system without a top notch AV installed and always resident. Yeah I am installing some now. What do you mean by "always resident"?also wth?? i am running super ANTISPYWARE, and it says i got tracking cookies from my gmail and stuff? and youtube?? I TRUSTED YOU!!! SNAPE I TRUSTED YOU!!!!!Resident = loading at boot and always running / active in the backgroundi want to do these few things, what order should i do them? first gonna update all my software, then turn off internet and restart PC then virus scan 1. malwayre bytes scan 2. superantispyware scan 3. run ccleaner 4. ccleaner registry fix is that a good order to do these?1) DO NOT EVER use any registry cleaners / utilities - including the ccleaner registry cleaner MODULE. The best of them do absolutely nothing. The worst of them will leave your system unusable. 2) Ccleaner does nothing you can't do yourself. It certainly is not in any way, shape, or form an anti-malware utility. As for the rest, there is no "good order" or "bad order". Run the scans however you like.Quote from: Allan on May 07, 2012, 09:44:54 AM 1) DO NOT EVER use any registry cleaners / utilities - including the ccleaner registry cleaner module. The best of them do absolutely nothing. The worst of them will leave your system unusable. cool thanks - i like to update all my programs, then restart in safemode- run scans - then reboot hey also why did trusted sites like google send me malicious tracking cookies? Makes me not trust google as much, thinking of transferring my accounts to something less mainstream.They're not malicious - their just tracking cookies - for marketing purposes. Pretty much everyone does it these DAYS. Disable third party cookies in your browser options. |
|
| 3202. |
Solve : Computer Fails To Start Up AFTER Threats Removed. HELP!? |
|
Answer» It's getting better. Starts up faster. STILL does not copy/PASTE without me hitting Ctrl+C a dozen times.ESETscan just finished. Still does not copy/paste without me hitting Ctrl+C a dozen times.Is that the only method you use to copy and paste? Does right-clicking work? If that's the only method that doesn't work, you could try another key board.Right click SELDOM works. The keystrokes Ctrl+u,i,p etc. work with no issues. It's only copy/paste. Quote Right click seldom works. The keystrokes Ctrl+u,i,p etc. work with no issues. It's only copy/paste.I don't believe that this is a malware problem. We should do some cleanup. Download this program and run it Uninstall ComboFix .It will remove ComboFix for you ******************************************** To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. *********************************************** Clean out your temporary INTERNET files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run UNINTERRUPTED until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. *********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 3203. |
Solve : Is this threat a false positive by avg 2012 free?? |
|
Answer» PLZ stay with me just a bit longer, wild tangent does not exist in WIN 7 'programs and features' (formerly known as 'add/remove programs'0. I would like to read your referenced articles first if they give instructions on how to remove wt in windows 7. ThanksOK. I read the Wild Tangent article. I always side on the ere of caution. The WT games ie poker star (I figured out how to uninstall all 20) where apart of Hewlett Packards initial install. NEVER the less they are gone. I did find an unsolicited wt file and got rid of it as well. I still need to finish complying with your final instructions.... so as for now, I appreciate all your help; I believe my pc is well. Before you close this post I have one last curiosity. When you detect the problems, we are not informed of the amount or type of damage that may have incurred. In other words, spyware is spyware and malware and trojans are the like. Even though the problems where removed; to what extent; if any, was the damage? My PC ran crappy, you figured out why it ran crappy. Can you discern wether the removed problems were intended to just destroy just the pc, attack me personally to gain my identity and worse to hurt others. If the answer doesn't take away you from your priorities, please opine. Again, thanks for all that you do. When I tried to use combofix.uninstall, it first looked like it worked. Then a pop up refered that I was trying to uninstall combofix from a windows xp version or something like that and maybe it didn't work. Confusing. If removing combofix is important, is there an uninstaller for Win7?Quote When you detect the problems, we are not informed of the amount or type of damage that may have incurred. In other words, spyware is spyware and malware and trojans are the like. Even though the problems where removed; to what extent; if any, was the damage? My PC ran crappy, you figured out why it ran crappy. Can you discern wether the removed problems were intended to just destroy just the pc, attack me personally to gain my identity and worse to hurt others.It's really difficult to say how much damage without sitting in front of the COMPUTER. Some malware does no damage at all; it just collects information about you and your surfing habits. Others such as scareware or ransomeware will freeze up your computer until you pay a fee to unlock it. This can be fixed btw without PAYING. Others try to get your banking information and such. Quote If removing combofix is important, is there an uninstaller for Win7?Download this program and run it Uninstall ComboFix .It will remove ComboFix for you |
|
| 3204. |
Solve : Removing BearShare applications? |
|
Answer» Hello |
|
| 3205. |
Solve : How can I get rid of sality.nba virus ?? |
|
Answer» what should I do now ?Download Combofix from any of the links below, and save it to your desktop.
Click I Agree to start the program. ComboFix will then extract the necessary files and you will see this: As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7 It will allow you to boot up into a special recovery/repair mode that will allow us to more easily HELP you should your computer have a problem after an attempted removal of malware. If you did not have it installed, you will see the prompt below. Choose YES. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt). Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so. Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.ComboFix 12-03-27.03 - Saeid 03/27/2012 23:59:08.2.4 - x86 Microsoft Windows 7 Ultimate 6.1.7601.1.1256.981.1033.18.3063.1710 [GMT 4.5:30] Running from: c:\users\Saeid\Desktop\ComboFix.exe AV: Kaspersky Anti-Virus *Disabled/Updated* {2EAA32A5-1EE1-1B22-95DA-337730C6E984} SP: Kaspersky Anti-Virus *Disabled/Updated* {95CBD341-38DB-14AC-AF6A-08054B41A339} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-02-27 to 2012-03-27 ))))))))))))))))))))))))))))))) . . 2012-03-27 19:37 . 2012-03-27 19:37--------d-----w-c:\users\Default\AppData\Local\temp 2012-03-27 08:01 . 2012-03-27 08:01--------d-----w-C:\_OTL 2012-03-27 07:36 . 2012-03-14 02:156582328----a-w-c:\programdata\Microsoft\Windows Defender\Definition Updates\{54D7E092-BDA8-4721-A5D1-B16B8F591AC9}\mpengine.dll 2012-03-26 08:05 . 2012-03-26 08:05--------d-----w-c:\users\Saeid\AppData\Roaming\SUPERAntiSpyware.com 2012-03-26 08:04 . 2012-03-26 08:05--------d-----w-c:\program files\SUPERAntiSpyware 2012-03-26 08:04 . 2012-03-26 08:04--------d-----w-c:\programdata\SUPERAntiSpyware.com 2012-03-26 07:35 . 2012-03-26 07:35--------d-----w-c:\program files\CCleaner 2012-03-26 07:35 . 2012-03-26 07:35--------d-----w-c:\program files\Google 2012-03-25 07:20 . 2012-03-25 07:20--------d-----w-c:\users\Saeid\AppData\Roaming\Malwarebytes 2012-03-25 07:20 . 2012-03-25 07:20--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2012-03-25 07:20 . 2012-03-25 07:20--------d-----w-c:\programdata\Malwarebytes 2012-03-25 07:20 . 2011-12-10 10:5420464----a-w-c:\windows\system32\drivers\mbam.sys 2012-03-24 05:45 . 2012-03-24 05:4510920----a-w-C:\aolconnfix.exe 2012-03-23 17:58 . 2012-03-23 17:58--------d-----w-c:\program files\AOL Toolbar 2012-03-23 17:58 . 2012-03-23 17:58--------d-----w-c:\programdata\AOL Toolbar 2012-03-23 17:58 . 2012-03-23 17:58--------d-----w-c:\program files\Common Files\Software Update Utility 2012-03-23 17:57 . 2012-03-23 22:01--------d-----w-c:\program files\AOL 9.5 2012-03-23 17:57 . 2012-03-23 17:59--------d-----w-c:\program files\Common Files\aol 2012-03-19 19:06 . 2012-03-19 19:09--------d-----w-c:\users\Saeid\AppData\Local\Facebook 2012-03-18 21:59 . 2012-03-18 21:592106216----a-w-c:\program files\Mozilla Firefox\D3DCompiler_43.dll 2012-03-18 21:59 . 2012-03-18 21:591998168----a-w-c:\program files\Mozilla Firefox\d3dx9_43.dll 2012-03-18 21:59 . 2012-03-18 21:59592824----a-w-c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-18 21:59 . 2012-03-18 21:59548864----a-w-c:\program files\Mozilla Firefox\msvcp80.dll 2012-03-18 21:59 . 2012-03-18 21:59479232----a-w-c:\program files\Mozilla Firefox\msvcm80.dll 2012-03-18 21:59 . 2012-03-18 21:5944472----a-w-c:\program files\Mozilla Firefox\mozglue.dll 2012-03-18 21:59 . 2012-03-18 21:59626688----a-w-c:\program files\Mozilla Firefox\msvcr80.dll 2012-03-15 09:45 . 2012-02-03 03:542343424----a-w-c:\windows\system32\win32k.sys 2012-03-15 09:45 . 2012-02-10 05:381077248----a-w-c:\windows\system32\DWrite.dll 2012-03-15 09:37 . 2012-01-25 05:3258880----a-w-c:\windows\system32\rdpwsx.dll 2012-03-15 09:37 . 2012-01-25 05:32129536----a-w-c:\windows\system32\rdpcorekmts.dll 2012-03-15 09:37 . 2012-01-25 05:278192----a-w-c:\windows\system32\rdrmemptylst.exe 2012-03-15 09:37 . 2012-02-17 05:34919040----a-w-c:\windows\system32\rdpcorets.dll 2012-03-15 09:37 . 2012-02-17 05:34826880----a-w-c:\windows\system32\rdpcore.dll 2012-03-15 09:37 . 2012-02-17 04:14183808----a-w-c:\windows\system32\drivers\rdpwd.sys 2012-03-15 09:37 . 2012-02-17 04:1324576----a-w-c:\windows\system32\drivers\tdtcp.sys 2012-03-04 16:16 . 2012-03-04 16:16--------d-----w-c:\users\Saeid\AppData\Local\Behnevis Common 2012-03-04 16:16 . 2012-03-22 17:32--------d-----w-c:\program files\Behnevis for MS Word 2012-03-04 16:15 . 2012-03-04 16:15--------d-----w-c:\program files\Conduit 2012-03-04 16:15 . 2012-03-04 16:15--------d-----w-c:\users\Saeid\AppData\Local\Conduit . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-02-29 14:50 . 2011-11-15 18:04414368----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-23 04:48 . 2011-11-15 16:44237072------w-c:\windows\system32\MpSigStub.exe 2012-01-17 13:33 . 2011-12-06 12:55189248----a-w-c:\windows\system32\PnkBstrB.exe 2012-01-17 13:33 . 2011-12-06 12:5475136----a-w-c:\windows\system32\PnkBstrA.exe 2012-03-18 21:59 . 2011-11-15 18:0497208----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension] @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}" [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}] 2011-05-30 14:5021864----a-w-c:\program files\Internet Download Manager\IDMShellExt.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Nimbuzz"="c:\program files\Nimbuzz\Nimbuzz.exe" [2011-12-01 11713024] "Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-18 4363504] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424] "IDMan"="c:\program files\Internet Download Manager\IDMan.exe" [2011-11-14 3437976] "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-12-23 1594664] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-06-01 98304] "RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-02-16 87336] "PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2008-10-13 50472] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352] "IAStorIcon"="c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2010-06-08 284696] "HostManager"="c:\program files\Common Files\AOL\1332525462\ee\AOLSoftware.exe" [2009-07-20 41264] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] "Broadcom Wireless Manager UI"="c:\program files\Dell\DW WLAN Card\WLTRAY.exe" [2010-02-02 5249024] "BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-02-28 75048] "Babylon Client"="c:\program files\Babylon\Babylon-Pro\Babylon.exe" [2011-08-22 3265136] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2010-11-10 35736] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-11-10 932288] . c:\users\Saeid\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2009-12-29 795936] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2011-05-04 17:54551296----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVP] 2011-04-24 19:45202296----a-w-c:\program files\Kaspersky Lab\Kaspersky Internet Security 2012\avp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_32;Microsoft .NET FRAMEWORK NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2010-11-20 15872] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2010-12-01 197224] R3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2010-01-12 257568] R3 Synth3dVsc;Synth3dVsc;c:\windows\system32\drivers\synth3dvsc.sys R3 SysProtDrv.sys;SysProtDrv.sys;c:\users\Saeid\Desktop\SysProt\SysProtDrv.sys [2012-03-26 44288] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 52224] R3 tsusbhub;tsusbhub;c:\windows\system32\drivers\tsusbhub.sys R3 VGPU;VGPU;c:\windows\system32\drivers\rdvgkmd.sys R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-11-22 1343400] R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-06 11520] R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2009-07-23 47128] R4 RsFx0103;RsFx0103 Driver;c:\windows\system32\DRIVERS\RsFx0103.sys [2009-03-29 239336] R4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);c:\program files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [2009-03-29 366936] S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2011-12-18 721904] S1 kl2;kl2;c:\windows\system32\DRIVERS\kl2.sys [2011-03-04 11352] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys [2011-03-10 23856] S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2011-07-22 12880] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2011-07-12 67664] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-13 48128] S2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [2011-08-11 116608] S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2011/11/15 19:17];c:\program files\CyberLink\PowerDVD9\000.fcl [2009-02-28 16:10 87536] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2010-06-01 176128] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-06-08 13336] S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [2011-07-06 89376] S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2012-01-13 652360] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys [2009-11-02 14808] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-03 2320920] S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2010-06-01 5586432] S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2010-06-01 209920] S3 BcmVWL;Broadcom Virtual Wireless;c:\windows\system32\DRIVERS\bcmvwl32.sys [2010-02-02 17144] S3 btusbflt;Bluetooth USB Filter;c:\windows\system32\drivers\btusbflt.sys [2010-03-30 45352] S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2010-03-30 29472] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys [2010-02-26 132480] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys [2009-11-02 19984] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011-12-10 20464] S3 vwifimp;Microsoft Virtual WiFi Miniport Service;c:\windows\system32\DRIVERS\vwifimp.sys [2009-07-13 14336] . . Contents of the 'Scheduled Tasks' folder . 2012-03-27 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task 01a8d408-7896-4588-a444-c4f59eb8fffb.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . 2012-03-26 c:\windows\Tasks\SUPERAntiSpyware Scheduled Task f88d71fa-faee-4ea3-9250-22371e658c90.job - c:\program files\SUPERAntiSpyware\SASTask.exe [2011-05-04 17:52] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.aol.com mStart Page = about:blank uInternet Settings,ProxyOverride = local uInternet Settings,ProxyServer = 127.0.0.1:11536 IE: Download all links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm IE: Translate this web page with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm IE: Translate with Babylon - c:\program files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm TCP: DhcpNameServer = 192.168.1.1 192.168.1.1 TCP: Interfaces\{EB069C30-DB0F-4DAE-83D4-466F9A5FEFE4}: NameServer = 8.4.4.8,3.2.2.3 FF - ProfilePath - c:\users\Saeid\AppData\Roaming\Mozilla\Firefox\Profiles\qaurd1x0.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=55555 FF - prefs.js: browser.search.selectedEngine - DAEMON Search FF - prefs.js: browser.startup.homepage - hxxp://www.aol.com FF - prefs.js: network.proxy.ftp - 127.0.0.1 FF - prefs.js: network.proxy.ftp_port - 11536 FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 11536 FF - prefs.js: network.proxy.socks - 127.0.0.1 FF - prefs.js: network.proxy.socks_port - 11536 FF - prefs.js: network.proxy.ssl - 127.0.0.1 FF - prefs.js: network.proxy.ssl_port - 11536 FF - prefs.js: network.proxy.type - 0 FF - user.js: protocol-handler.warn-external.dnUpdate - false . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}] "ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_USERS\S-1-5-21-1338443668-846065355-974167902-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:21,88,68,61,66,d5,35,e4,b7,c5,6a,2f,15,55,a4,7a,45,55,3b,d5,75,31,69, cc,2d,4a,31,52,d8,3e,6e,cf,5b,5f,0c,2e,c9,48,50,70,5a,49,98,2a,26,be,a6,e6,\ "??"=hex:fe,94,16,33,a2,f0,68,4b,6b,9d,81,d8,7c,85,bb,9d . [HKEY_USERS\S-1-5-21-1338443668-846065355-974167902-1000_Classes\CLSID\{01680c4a-b31f-45d3-8be1-b859b4623e35}] @Denied: (Full) (Everyone) @Allowed: (Read) (RestrictedCode) "Model"=dword:00000028 "Therad"=dword:00000015 "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a, 1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\ . [HKEY_USERS\S-1-5-21-1338443668-846065355-974167902-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}] @Denied: (Full) (Everyone) "scansk"=hex(0):1b,d8,92,eb,22,77,b1,b4,34,91,07,25,ff,2e,77,3c,bb,80,33,ab,b8, d7,2f,07,46,07,e5,b1,19,39,ef,99,67,03,07,de,17,77,9b,1a,00,00,00,00,00,00,\ . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'Explorer.exe'(3148) c:\program files\Babylon\Babylon-Pro\Captlib.dll c:\program files\WIDCOMM\Bluetooth Software\btmmhook.dll . Completion time: 2012-03-28 00:10:17 ComboFix-quarantined-files.txt 2012-03-27 19:40 ComboFix2.txt 2012-03-27 19:14 . Pre-Run: 49,012,285,440 bytes free Post-Run: 48,951,115,776 bytes free . - - End Of File - - 68D5ADAE3F7FD65BAE8430E4B9A21E2C pardon me, in drive (C), I click on Documents and Settings folder and show an error that say is not accessible and there is a lock on it and also in drive (D) system volume information folder, it has a same problem otherwise in drive (C) I had this problem and it seems that has been fixed now Is it normal ?Download HostsXpert •Unzip HostXpert to your Desktop •Open up the HostXpert program. •Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled. •Click Create Back Up •Then click on Restore Microsoft's Host Files •Close the HostXpert program ******************************************* Quote pardon me, in drive (C), I click on Documents and Settings folder and show an error that say is not accessible and there is a lock on itIt was probably caused by an infection. SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
Is this error normal ?SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\sprf.sys Service Name: --- Module Base: 84AB6000 Module End: 84BB7000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\a26x65ir.SYS Service Name: --- Module Base: 96F9B000 Module End: 96FD3000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_iaStor.sys Service Name: --- Module Base: 91216000 Module End: 913CB000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_dumpfve.sys Service Name: --- Module Base: 9654B000 Module End: 9655C000 Hidden: Yes ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Qoobox\BackEnv\AppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cache.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cookies.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Desktop.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Favorites.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\History.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Music.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\NetHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Personal.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Pictures.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\PrintHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Programs.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Recent.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SendTo.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SetPath.bat Status: Access denied Object: C:\Qoobox\BackEnv\StartMenu.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\StartUp.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SysPath.dat Status: Access denied Object: C:\Qoobox\BackEnv\Templates.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\VikPev00 Status: Access denied Object: C:\System Volume Information\WindowsImageBackup\Catalog\BackupGlobalCatalog Status: Access denied Object: C:\System Volume Information\WindowsImageBackup\Catalog\GlobalCatalog Status: Access denied Object: C:\System Volume Information\WindowsImageBackup\Catalog Status: Access denied Object: C:\System Volume Information\WindowsImageBackup\SPPMetadataCache\{07cef2ff-c079-4635-a68e-99dc61f91b6f} Status: Access denied Object: C:\System Volume Information\WindowsImageBackup\SPPMetadataCache Status: Access denied Object: C:\Windows\CSC\v2.0.6\namespace Status: Access denied Object: C:\Windows\CSC\v2.0.6\pq Status: Access denied Object: C:\Windows\CSC\v2.0.6\sm Status: Access denied Object: C:\Windows\CSC\v2.0.6\temp Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession7.etl Status: Access denied Object: C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTUBPM.etl Status: Access denied Please download SystemLook from one of the links below and save it to your desktop. Link # 1 Link # 2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double-click SystemLook.exe to run it. Copy the contents of the following codebox into the main textfield. Code: [Select]:filefind a26x65ir.SYS Click the Look button to start the scan. Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt ******************************************* I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these STEPS)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt SystemLook 30.07.11 by jpshortstuff Log created at 11:07 on 29/03/2012 by Saeid Administrator - Elevation successful ========== filefind ========== Searching for "a26x65ir.SYS" No files found. -= EOF =-[emailprotected] as downloader log: all ok esets_scanner_update returned -1 esets_gle=36882 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=a71137f0d49da94288a404b30554ff76 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-03-29 11:21:52 # local_time=2012-03-29 03:51:52 (+0330, Iran Daylight Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1280 16777215 100 0 11646693 11646693 0 0 # compatibility_mode=5893 16776573 100 94 180509 84641902 0 0 # compatibility_mode=8192 67108863 100 0 10863 10863 0 0 # scanned=148384 # found=4 # cleaned=4 # scan_time=7601 C:\Program Files\Babylon\Babylon-Pro\Utils\MyBabylonTB.exea variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C C:\Program Files\Babylon\BabylonToolbar\1.4.19.5\BabylonToolbarApp.dlla variant of Win32/Toolbar.Babylon application (cleaned by deleting - quarantined)00000000000000000000000000000000C C:\Program Files\Babylon\BabylonToolbar\1.4.19.5\BabylonToolbarsrv.exeprobably a variant of Win32/Toolbar.Babylon application (cleaned by deleting - quarantined)00000000000000000000000000000000C D:\Software\Nero 9.4.13.2b.rarprobably a variant of Win32/Agent.KQNXJLO trojan (deleted - quarantined)00000000000000000000000000000000C [emailprotected] as downloader log: all ok esets_scanner_update returned -1 esets_gle=53251 # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=a71137f0d49da94288a404b30554ff76 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-03-29 03:21:11 # local_time=2012-03-29 07:51:11 (+0330, Iran Daylight Time) # country="United States" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1280 16777215 100 0 11655368 11655368 0 0 # compatibility_mode=5893 16776573 100 94 189184 84650577 0 0 # compatibility_mode=8192 67108863 100 0 19538 19538 0 0 # scanned=216225 # found=8 # cleaned=8 # scan_time=13285 H:\english file aminuuuu\base\video learning, babylon-maccaro, picture dictionary\AutoPlay\Docs\5\babylon-Maccro\01-Babylon Pro v8.0.10 (r16)\Babylon8_setup.exea variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C H:\Programs\cnet_fences_public_exe.exea variant of Win32/InstallCore.D application (cleaned by deleting - quarantined)00000000000000000000000000000000C H:\Programs\SweetImSetup.exea variant of Win32/SweetIM.B application (cleaned by deleting - quarantined)00000000000000000000000000000000C H:\Programs\Babylon Pro\Babylon9 Setup www.FDL.ir.exea variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C H:\SAEID-PC\Backup Set 2011-11-27 222550\Backup Files 2011-11-27 222550\Backup files 1.zipa variant of Win32/Adware.MediaFinder.A application (deleted - quarantined)00000000000000000000000000000000C H:\SAEID-PC\Backup Set 2011-11-27 222550\Backup Files 2011-11-27 222550\Backup files 8.zipa variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C H:\software\BabylonPro-902(www.vatandownload.com).rara variant of Win32/Toolbar.Babylon application (deleted - quarantined)00000000000000000000000000000000C H:\software\Office 2010 Activator (www.Downloadha.com).rarWin32/HackKMS.A application (deleted - quarantined)00000000000000000000000000000000C here are the logs, what should I do now? thanks alotIf there are no other issues, we can do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************* To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
**************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla BASED browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe SURFING!SuperDave, I think I have a problem, as I said in a reply, system volume information folder is not accessible in my all drives, except drive E, I still have this problem ! I don't know what's this, I have no idea these folders aren't exist before ! wow, it seems that this problem solved too, Grazie ! I truly appreciate your time and effortYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3206. |
Solve : Gateway Blue Screen? |
|
Answer» When I start up computer I get message that something is wrong with my computer and two options: repair or start normallly. Repair LEADS to a blue SCREEN that says to run chkdsk /f which when I run says device is not ready. All the other chkdsk demands say the same thing. Safe mode does not work and I dont care about saving my information. Alls I want to do is be able to reinstall windows vista but when i boot from the cd it does not see my dvd. I have windows vista 32What is the make and MODEL of your computer? |
|
| 3207. |
Solve : How to do the DOS attack?? |
|
Answer» Please anyone who can HELP me? |
|
| 3208. |
Solve : Antivirus Test Labs? |
|
Answer» I am searching for buy a proper Antivirus software for myself. i searched about the comparisons on the Internet. I found out that there are some test labs that their results can be useful such as av-test.org and others. |
|
| 3209. |
Solve : SVCHOST.exe or Newfolder.exe? |
|
Answer» thyxxxxxxx GUYS!!!!!! |
|
| 3210. |
Solve : What are these eroors in Event Viewer? |
| Answer» HI, Can someone tell me what these Errors are in EVENT viewer Volmgr, VSS, Windows media player sharing? I picked them up because My computer keeps crashing to DESKTOP out of the games I run? How do I get rid of them. Thanks!! | |
| 3211. |
Solve : how can I get rid of sality.nba??? |
|
Answer» Quote I did every thing you said in earlier posts. but the problem seems exist. there is a lock SHAPE in some folders such "DOCUMENT and settings" and "system recovery. i can't enter these folders with the massage: "ACCESS IS DENIED" 1) Right-click the folder or drive that has a lock icon and select "Properties". 2) Click on the "Security" tab, then select "Edit..." to change permissions. Click "Add.." 3) In the text field for "Object NAME", enter in "Users" (without quotations). Hit "OK". 4) "Apply", "OK", and voila, the padlock next to the icons should be gone. |
|
| 3212. |
Solve : Problem with "welcome to nginx" and website logins? |
|
Answer» Quote I changed it back to att.my.yahoo.com to see if the nginx still comes up and it does.This and this is what I know about nginx We should do some cleanup StartupLite Download StartupLite by MalwareBytes to your Desktop. Doubleclick StartupLite.exe to launch the program. Ensure the Disable box is checked. Click Continue. A pop up message will tell you the unecessary startup items in your list have been disabled and ask you to restart your computer. Re-start your computer. ******************************************************** To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
*********************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have SAVED all your WORK before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few SECONDS to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************* Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a FREE Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! When I try to run TFC, my PC freezes. I've let it sit for over 30 minutes and the desktop goes away but just freezes up. Malwarebytes captured this in it's log tonight and I had it quarantined: 2012/04/04 06:46:06 -0500PEARSON-HOME-PCAdministratorMESSAGEExecuting scheduled update: Daily 2012/04/04 06:46:54 -0500PEARSON-HOME-PCAdministratorMESSAGEScheduled update executed successfully: database updated from version v2012.03.31.14 to version v2012.04.04.02 2012/04/04 06:46:54 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting database refresh 2012/04/04 06:47:00 -0500PEARSON-HOME-PCAdministratorMESSAGEDatabase refreshed successfully 2012/04/04 19:54:33 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection 2012/04/04 19:54:57 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully 2012/04/04 19:55:00 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection 2012/04/04 19:55:05 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully 2012/04/04 20:11:52 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection 2012/04/04 20:12:19 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully 2012/04/04 20:12:22 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection 2012/04/04 20:12:26 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully 2012/04/04 20:14:58 -0500PEARSON-HOME-PCAdministratorDETECTIONC:\Documents and Settings\Administrator\My Documents\Downloads\B.tmpTrojan.Dropper.PGenQUARANTINE 2012/04/04 20:25:21 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection 2012/04/04 20:25:39 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully 2012/04/04 20:25:42 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection 2012/04/04 20:25:46 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully 2012/04/04 20:33:11 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection 2012/04/04 20:33:37 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully 2012/04/04 20:33:40 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection 2012/04/04 20:34:00 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully 2012/04/04 20:34:00 -0500PEARSON-HOME-PCAdministratorMESSAGEStopping IP protection 2012/04/04 20:34:00 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection stopped 2012/04/04 21:19:29 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting protection 2012/04/04 21:19:52 -0500PEARSON-HOME-PCAdministratorMESSAGEProtection started successfully 2012/04/04 21:19:55 -0500PEARSON-HOME-PCAdministratorMESSAGEStarting IP protection 2012/04/04 21:20:20 -0500PEARSON-HOME-PCAdministratorMESSAGEIP Protection started successfully When I go that downloads folder I do not see this b.temp file, I went into Malwarebytes and deleted it there. At this point I'm ready to dump Chrome and go back to Explorer unless you have any other ideas. I thank you for your time over these past few weeks! Quote When I try to run TFC, my PC freezes. I've let it sit for over 30 minutes and the desktop goes away but just freezes up.TFC will do that sometimes. Just do a disk cleanup instead. Double-click on My Computer, right-click on the C drive and select Disk cleanup. Quote At this point I'm ready to dump Chrome and go back to Explorer unless you have any other ideas.I don't know too much about Chrome but FireFox is reputed to be a safer browser.Ok I'll do the disk cleanup. Thanks again for all your help!You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3213. |
Solve : "..." not a valid Win32 application, The application or DLL not valid windows im? |
|
Answer» Hi SD, Also, under My Computer, C is my hard drive, but there is also a D drive labeled HP_RecoveryYes, that's the recovery console we're trying to get into. Quote After writing all this, I found this site on line that appears to say to ignore the error message for Windows 2000 (but it doesn't say for XP): should I just ignore the error message ?I would say just ignore the warning as MS stated in their article. But first, you should save all your important data just in case we have to use the Recovery disks. Wow--that was QUICK! No problems. Here's the log from MBRcheck: MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version:Windows XP Professional Windows Information:Service Pack 3 (build 2600) Logical Drives Mask:0x00000f1c Kernel Drivers (total 143): 0x804D7000 \WINDOWS\system32\ntkrnlpa.exe 0x806E5000 \WINDOWS\system32\hal.dll 0xF7A3C000 \WINDOWS\system32\KDCOM.DLL 0xF794C000 \WINDOWS\system32\BOOTVID.dll 0xF740D000 ACPI.sys 0xF7A3E000 \WINDOWS\system32\DRIVERS\WMILIB.SYS 0xF73FC000 pci.sys 0xF753C000 isapnp.sys 0xF754C000 ohci1394.sys 0xF755C000 \WINDOWS\system32\DRIVERS\1394BUS.SYS 0xF7950000 compbatt.sys 0xF7954000 \WINDOWS\system32\DRIVERS\BATTC.SYS 0xF7B04000 pciide.sys 0xF77BC000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS 0xF7A40000 viaide.sys 0xF7A42000 intelide.sys 0xF756C000 MountMgr.sys 0xF73DD000 ftdisk.sys 0xF7A44000 dmload.sys 0xF73B7000 dmio.sys 0xF77C4000 PartMgr.sys 0xF757C000 VolSnap.sys 0xF739F000 atapi.sys 0xF758C000 disk.sys 0xF759C000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS 0xF737F000 fltmgr.sys 0xF736D000 sr.sys 0xF75AC000 PxHelp20.sys 0xF7356000 KSecDD.sys 0xF72C9000 Ntfs.sys 0xF729C000 NDIS.sys 0xF7282000 Mup.sys 0xF6D60000 kl1.sys 0xF76FC000 \SystemRoot\system32\DRIVERS\intelppm.sys 0xF631D000 \SystemRoot\system32\DRIVERS\ati2mtag.sys 0xF6309000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF7914000 \SystemRoot\system32\DRIVERS\usbohci.sys 0xF62E5000 \SystemRoot\system32\DRIVERS\USBPORT.SYS 0xF791C000 \SystemRoot\system32\DRIVERS\usbehci.sys 0xF770C000 \SystemRoot\system32\DRIVERS\imapi.sys 0xF771C000 \SystemRoot\system32\DRIVERS\cdrom.sys 0xF772C000 \SystemRoot\system32\DRIVERS\redbook.sys 0xF62C2000 \SystemRoot\system32\DRIVERS\ks.sys 0xF7924000 \SystemRoot\System32\Drivers\GEARAspiWDM.sys 0xF629A000 \SystemRoot\system32\DRIVERS\HDAudBus.sys 0xF792C000 \SystemRoot\system32\DRIVERS\fdc.sys 0xF6286000 \SystemRoot\system32\DRIVERS\parport.sys 0xF773C000 \SystemRoot\system32\DRIVERS\i8042prt.sys 0xF7934000 \SystemRoot\system32\DRIVERS\PS2.sys 0xF793C000 \SystemRoot\system32\DRIVERS\kbdclass.sys 0xF7A78000 \SystemRoot\system32\DRIVERS\arkbcfltr.sys 0xF7944000 \SystemRoot\system32\DRIVERS\point32.sys 0xF77D4000 \SystemRoot\system32\DRIVERS\mouclass.sys 0xF7A7A000 \SystemRoot\system32\DRIVERS\armoucfltr.sys 0xF7814000 \SystemRoot\system32\DRIVERS\aracpi.sys 0xF6241000 \SystemRoot\system32\DRIVERS\HSXHWBS2.sys 0xF614A000 \SystemRoot\system32\DRIVERS\HSX_DP.sys 0xF6094000 \SystemRoot\system32\DRIVERS\HSX_CNXT.sys 0xF781C000 \SystemRoot\System32\Drivers\Modem.SYS 0xF6080000 \SystemRoot\system32\DRIVERS\Rtnicxp.sys 0xF774C000 \SystemRoot\system32\DRIVERS\nic1394.sys 0xF7A28000 \SystemRoot\system32\DRIVERS\arpolicy.sys 0xF7C8D000 \SystemRoot\system32\DRIVERS\audstub.sys 0xF775C000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0xF7A2C000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0xF6069000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0xF776C000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0xF777C000 \SystemRoot\system32\DRIVERS\raspptp.sys 0xF7824000 \SystemRoot\system32\DRIVERS\TDI.SYS 0xF6058000 \SystemRoot\system32\DRIVERS\psched.sys 0xF778C000 \SystemRoot\system32\DRIVERS\msgpc.sys 0xF782C000 \SystemRoot\system32\DRIVERS\ptilink.sys 0xF7834000 \SystemRoot\system32\DRIVERS\raspti.sys 0xF6000000 \SystemRoot\system32\DRIVERS\rdpdr.sys 0xF779C000 \SystemRoot\system32\DRIVERS\termdd.sys 0xF7A7C000 \SystemRoot\system32\DRIVERS\swenum.sys 0xF5FA2000 \SystemRoot\system32\DRIVERS\update.sys 0xF6D30000 \SystemRoot\system32\DRIVERS\mssmbios.sys 0xF77AC000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF763C000 \SystemRoot\system32\DRIVERS\usbhub.sys 0xF7A7E000 \SystemRoot\system32\DRIVERS\USBD.SYS 0xF1A0B000 \SystemRoot\system32\drivers\RtkHDAud.sys 0xF19E7000 \SystemRoot\system32\drivers\portcls.sys 0xF766C000 \SystemRoot\system32\drivers\drmk.sys 0xF1970000 \SystemRoot\system32\DRIVERS\klif.sys 0xF7A8A000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF7C12000 \SystemRoot\System32\Drivers\Null.SYS 0xF7A8C000 \SystemRoot\System32\Drivers\Beep.SYS 0xF7C14000 \SystemRoot\System32\Drivers\ATMhelpr.SYS 0xF784C000 \SystemRoot\System32\drivers\vga.sys 0xF7A8E000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF7A90000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF7854000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF785C000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF6040000 \SystemRoot\system32\DRIVERS\rasacd.sys 0xF7864000 \SystemRoot\system32\DRIVERS\kl2.sys 0xF6030000 \SystemRoot\system32\DRIVERS\usbscan.sys 0xF1915000 \SystemRoot\system32\DRIVERS\ipsec.sys 0xF18BC000 \SystemRoot\system32\DRIVERS\tcpip.sys 0xF1894000 \SystemRoot\system32\DRIVERS\netbt.sys 0xF1815000 \SystemRoot\System32\vsdatant.sys 0xF17EF000 \SystemRoot\system32\DRIVERS\ipnat.sys 0xF6513000 \SystemRoot\system32\DRIVERS\wanarp.sys 0xF5F9E000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF6503000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF786C000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF7874000 \SystemRoot\system32\DRIVERS\arhidfltr.sys 0xF64F3000 \SystemRoot\system32\DRIVERS\arp1394.sys 0xF787C000 \SystemRoot\system32\DRIVERS\usbprint.sys 0xF5F92000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xF17CD000 \SystemRoot\System32\drivers\afd.sys 0xF64E3000 \SystemRoot\system32\DRIVERS\netbios.sys 0xF17AB000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys 0xF7884000 \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS 0xF1730000 \SystemRoot\system32\DRIVERS\rdbss.sys 0xF1698000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0xF64D3000 \SystemRoot\System32\Drivers\Fips.SYS 0xF788C000 \SystemRoot\system32\DRIVERS\USBSTOR.SYS 0xF1674000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF165C000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF7AC0000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF19CB000 \SystemRoot\System32\drivers\Dxapi.sys 0xF78B4000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xF7C3A000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\ati2dvag.dll 0xBF055000 \SystemRoot\System32\ati2cqag.dll 0xBF09A000 \SystemRoot\System32\atikvmag.dll 0xBF0D0000 \SystemRoot\System32\ati3duag.dll 0xBF362000 \SystemRoot\System32\ativvaxx.dll 0xBF4BA000 \SystemRoot\System32\ATMFD.DLL 0xEF490000 \??\C:\WINDOWS\system32\drivers\mbam.sys 0xEF428000 \SystemRoot\system32\DRIVERS\ndisuio.sys 0xF789C000 \??\C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys 0xEEE67000 \SystemRoot\system32\drivers\wdmaud.sys 0xEF3B4000 \SystemRoot\system32\drivers\sysaudio.sys 0xEECFC000 \SystemRoot\system32\DRIVERS\mrxdav.sys 0xEEB53000 \SystemRoot\System32\Drivers\HTTP.sys 0xEEAD3000 \SystemRoot\system32\DRIVERS\srv.sys 0xEEB4F000 \SystemRoot\system32\DRIVERS\mdmxsdk.sys 0xEE713000 \SystemRoot\System32\Drivers\Cdfs.SYS 0x7C900000 \WINDOWS\system32\ntdll.dll Processes (total 56): 0 System Idle Process 4 System 548 C:\WINDOWS\system32\smss.exe 620 csrss.exe 648 C:\WINDOWS\system32\winlogon.exe 692 C:\WINDOWS\system32\services.exe 704 C:\WINDOWS\system32\lsass.exe 860 C:\WINDOWS\system32\ati2evxx.exe 876 C:\WINDOWS\system32\svchost.exe 948 svchost.exe 1016 C:\WINDOWS\system32\svchost.exe 1104 svchost.exe 1160 svchost.exe 1204 C:\Program Files\CheckPoint\ZoneAlarm\vsmon.exe 1472 C:\WINDOWS\system32\ati2evxx.exe 1564 C:\WINDOWS\explorer.exe 1868 C:\Program Files\CheckPoint\ZAForceField\ISWSVC.exe 2004 C:\WINDOWS\system32\spoolsv.exe 164 C:\Program Files\CheckPoint\ZAForceField\ForceField.exe 1044 svchost.exe 1100 C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe 1176 C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 1304 C:\WINDOWS\arservice.exe 1340 C:\Program Files\Microsoft\BingBar\SeaPort.EXE 1416 C:\Program Files\Bonjour\mDNSResponder.exe 1348 C:\WINDOWS\ehome\ehrecvr.exe 1732 C:\WINDOWS\ehome\ehSched.exe 1884 C:\Program Files\Java\jre6\bin\jqs.exe 2056 C:\Program Files\Common Files\LightScribe\LSSrvc.exe 2164 C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe 2296 svchost.exe 2352 C:\WINDOWS\system32\svchost.exe 2440 C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe 2504 mcrdsvc.exe 2584 C:\WINDOWS\system32\wuauclt.exe 3000 C:\WINDOWS\system32\dllhost.exe 3264 alg.exe 3280 wmiprvse.exe 3352 C:\WINDOWS\ehome\ehtray.exe 3368 C:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe 3428 C:\WINDOWS\arpwrmsg.exe 3596 C:\WINDOWS\ehome\ehmsas.exe 3776 C:\Program Files\iTunes\iTunesHelper.exe 4008 C:\Program Files\CheckPoint\ZoneAlarm\zatray.exe 4072 C:\Program Files\Microsoft IntelliPoint\ipoint.exe 208 C:\Program Files\Common Files\Java\Java Update\jusched.exe 584 C:\Program Files\real\realplayer\Update\realsched.exe 1488 C:\PROGRA~1\ScanSoft\PAPERP~1\PPWEBCAP.EXE 2816 C:\Program Files\iPod\bin\iPodService.exe 2932 C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe 2952 C:\Program Files\Yahoo!\Messenger\Ymsgr_tray.exe 3248 C:\Program Files\CheckPoint\ZoneAlarm\MailFrontier\mantispm.exe 3748 C:\hp\KBD\kbd.exe 3880 C:\WINDOWS\system\hpsysdrv.exe 1528 C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe 2236 C:\Documents and Settings\HP_Administrator\Desktop\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000038`11f9bc00 (FAT32) PhysicalDrive0 Model Number: WDCWD2500JS-60NCB1, Rev: 10.02E02 Size Device Name MBR Status -------------------------------------------- 232 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: DA38B874B7713D1B51CBC449F4EF809B0DEC644 A Done!Ok, the MBR has been fixed. That's a major step. SysProt Antirootkit Download SysProt Antirootkit from the link below (you will find it at the bottom of the page under attachments, or you can get it from one of the mirrors). http://sites.google.com/site/sysprotantirootkit/ Unzip it into a folder on your desktop.
Here's the scan (thank you for all this help, BTW): SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: F15A0000 Module End: F15B8000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: F7AC2000 Module End: F7AC4000 Hidden: Yes ****************************************************************************************** ****************************************************************************************** SSDT: Function Name: ZwAdjustPrivilegesToken Address: F18D466E Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwClose Address: F18D4F02 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwConnectPort Address: F177A2F4 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateEvent Address: F18D57D0 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwCreateFile Address: F17745CA Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateKey Address: F179358A Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateMutant Address: F18D56A8 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwCreateNamedPipeFile Address: F18D4274 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwCreatePort Address: F177AA80 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateProcess Address: F178DE4E Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateProcessEx Address: F178E23C Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateSection Address: F17976F6 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwCreateSemaphore Address: F18D5902 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwCreateSymbolicLinkObject Address: F18D758C Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwCreateThread Address: F18D4BA0 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwCreateWaitablePort Address: F177ABB6 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDebugActiveProcess Address: F18D6F36 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwDeleteFile Address: F17751E0 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDeleteKey Address: F1794E3C Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDeleteValueKey Address: F17947B2 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwDeviceIoControlFile Address: F18D5178 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwDuplicateObject Address: F178CD8A Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwEnumerateKey Address: F18D3FAC Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwEnumerateValueKey Address: F18D4056 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwFsControlFile Address: F18D4F84 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwLoadDriver Address: F176FE88 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwLoadKey Address: F1795794 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwLoadKey2 Address: F179599C Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwMapViewOfSection Address: F1797A5E Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwNotifyChangeKey Address: F18D41A2 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwOpenEvent Address: F18D5872 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwOpenFile Address: F1774DF2 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwOpenKey Address: F18D36BE Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwOpenMutant Address: F18D5740 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwOpenProcess Address: F1790160 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwOpenSection Address: F18D75B6 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwOpenSemaphore Address: F18D59A4 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwOpenThread Address: F178FD8A Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwProtectVirtualMemory Address: F17A4090 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwQueryKey Address: F18D4100 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwQueryMultipleValueKey Address: F18D3D28 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwQuerySection Address: F18D7958 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwQueryValueKey Address: F18D3978 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwQueueApcThread Address: F18D72A6 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwRenameKey Address: F179672A Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwReplaceKey Address: F1796060 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwReplyPort Address: F18D5D2E Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwReplyWaitReceivePort Address: F18D5BF4 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwRequestWaitReplyPort Address: F1779EC4 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwRestoreKey Address: F17970FC Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwResumeThread Address: F18D7E30 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwSaveKey Address: F18D332A Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwSecureConnectPort Address: F177A59C Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetContextThread Address: F18D4DBE Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwSetInformationFile Address: F17755A4 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetInformationObject Address: F17A3F7C Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetInformationToken Address: F18D6586 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwSetSecurityObject Address: F1796C6A Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetSystemInformation Address: F176F648 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSetValueKey Address: F1793F72 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwSuspendProcess Address: F18D7B7C Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwSuspendThread Address: F18D7CA4 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwSystemDebugControl Address: F178EEA4 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwTerminateProcess Address: F178EC20 Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwTerminateThread Address: F18D4956 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwUnloadDriver Address: F177029C Driver Base: F1759000 Driver End: F17D8000 Driver Name: \SystemRoot\System32\vsdatant.sys Function Name: ZwUnmapViewOfSection Address: F18D780E Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys Function Name: ZwWriteVirtualMemory Address: F18D4AE0 Driver Base: F18B4000 Driver End: F1903000 Driver Name: \SystemRoot\system32\DRIVERS\klif.sys ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Qoobox\BackEnv\AppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cache.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cookies.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Desktop.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Favorites.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\History.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Music.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\NetHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Personal.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Pictures.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\PrintHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Programs.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Recent.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SendTo.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SetPath.bat Status: Access denied Object: C:\Qoobox\BackEnv\StartMenu.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\StartUp.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SysPath.dat Status: Access denied Object: C:\Qoobox\BackEnv\Templates.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\VikPev00 Status: Access denied Quote has my information been vulnerable during this infection/invasion? In otherwords, paying bills on-line (at secure sites) or entering private info on the same sites, is there any chance that info has been compromised?Well, you did have a rootkit which could have compromised your computer. Here's what you should do just to be safe. Do you have ZoneAlarm Firewall? It appears your system is infected with a rootkit. A rootkit is a powerful piece of malware, that allows hackers full control over your computer for means of sending attacks over the Internet, or using your computer to generate revenue. Malware experts have recommended that we make it clear that with the system under control of a hacker, your computer might become impossible to clean 100%. Many rootkits can hook into the Windows 32-bit kernel, and patch several APIs to hide new registry keys and files they install. They can disable your antivirus and SECURITY tools to prevent detection and removal. This type of exploit allows them to steal sensitive information like passwords, personal and financial data which is sent back to the hacker. To learn more about these types of infections, you can refer to: What danger is presented by rootkits? Rootkits and how to combat them r00tkit Analysis: What Is A Rootkit If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references: How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? What Should I Do If I've Become A Victim Of Identity Theft? Identity Theft Victims Guide - What to do It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired so you can never be sure that you have completely removed a rootkit. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove rootkits cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully: When should I re-format? How should I reinstall? Help: I Got Hacked. Now What Do I Do? Help: I Got Hacked. Now What Do I Do? Part II Where to draw the line? When to recommend a format and reinstall? Guides for format and reinstall: how-to-reformat-and-reinstall-your-operating-system-the-easy-way However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat. If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful. Should you have any questions, please feel free to ask. ***************************************************** I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Hi Dave, Well, now that I’m thoroughly sick, I have questions, and I hope you can help and don’t mind continuing to help me . I run Zone Alarm Security Suite and the teatimer program (is it SAS, or Spybot? I’ve had it on my computer since you helped me a couple of years ago.) I also have WOT. I periodically update and run CCleaner, SAS, Spybot, Spyware Blaster, MBAM, although unfortunately I’ll admit it’s probably been 6 months. Why didn’t ZA or teatimer catch this stuff coming in? Do you think they prevented anything going out? I tried reading all the links you provided; frankly, I was way in over my head and didn’t understand a good deal of it. I got the idea that rootkits can sometimes be purposely installed for legitimate use. In December I had problems logging into one of the servers at work through the internet, and the tech people said they had to remotely access my computer to fix the problem. They sent me an “invitation” I had to accept so they could gain remote access. Is there any chance that’s where the rootkits came from and they’re harmless? Is there any way to tell where they came from and what they did--or are doing? I read also that malware can be downloaded to your computer through image files. Unfortunately, I have downloaded LOTS of image files--I draw as a hobby and when I see a picture I like, I download it to use as a reference. I have hundreds of pictures. I backed them all up to CD along with my other files when I did the back-ups this week. Would they have been scanned when downloaded? Would something have shown up if there was something in them? Could they/should they be scanned now on the CD? (I’d like to keep them if I could, but if there’s any chance they’ll do harm, I won’t keep them--but is it safe to get my other files off the disk now?) Are there any other types of files malware could now be hiding in--word or excel files, for example.. I read that the only way to be sure my computer is clean is to reformat completely and reinstall the disks. I’m not sure I could handle that, even if I bought the disks (could it be done from the recovery disks, or does reformatting require original installation disks?) Besides, how safe is it really for how long--if this stuff got in once, why couldn’t it get in again the first time I went on-line? Is it really a fail-safe? I don’t save/remember passwords, not even in Outlook for e-mail; I don’t keep password lists on my computer--but I do have a document I save to flash-drive with passwords. Is it possible my passwords are compromised anyway--could the info be stolen when I had the file open while working in it? Same with account #s--the only time they’re on my computer is when I type them in on a “secure” site. Wouldn’t that require a program to log keystrokes, and is there any way to tell if that happened? (I e-filed my taxes, all our taxes, on-line about a month ago. I shudder to think that I typed in social security #s and everything. Is this info vulnerable?) One of the articles mentioned something about changing passwords if you use a router. We have a router; this computer is attached to the router through a line, but my daughter’s laptop is wireless. This computer is the administrator for the router. Is her computer in danger? Do I need to change the password? (And if I do, how do I know it’s safe to do it now?) I had ZA off for about a day when it seemed to be causing the problem (I exited from the task tray; does that turn off the firewall too, or just the antivirus?) It’s been back on most of the time since then though. But teatimer resident is still off--I turned it off when your instructions said to. Should I turn it back on yet? ZA scanned while ESET was scanning, and it came up with 4 items--but when I looked at them, it appeared they were all items quarantined by TDSSKiller. I’m assuming they’re nothing to worry about now. Is that correct? Last thing: In prepping ESET to scan, the instructions said to check “scan archives”. When I checked that box, there was another box above it checked, the one for fix problems. Since the instructions didn’t say to check that box, I unchecked it. Should I have left it checked? Should I run ESET again with it checked? My big fear is having done the income taxes and paying bills on-line, wondering how much of a possibility there is that my information was compromised. I thought as I was on a secure site there was nothing to worry about. Is there no way to determine if anything was stolen? I apologize for all the questions; this really just has me sick. Here’s the scan; I appreciate anything you can do to help or any information you can give me. [emailprotected] as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=ee88f3395f713448af264009a4a0aa3e # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-04-06 02:22:58 # local_time=2012-04-05 10:22:58 (-0500, Eastern Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 71250665 71250665 0 0 # compatibility_mode=8192 67108863 100 0 70886976 70886976 0 0 # compatibility_mode=9217 16776533 100 13 2026307 11854075 0 0 # scanned=153944 # found=4 # cleaned=0 # scan_time=20021 C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0002.dtaWin64/Olmarik.AD trojan (unable to clean)00000000000000000000000000000000I C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0004.dtaWin64/Olmarik.AG trojan (unable to clean)00000000000000000000000000000000I C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0005.dtaa variant of Win32/Rootkit.Kryptik.KS trojan (unable to clean)00000000000000000000000000000000I C:\TDSSKiller_Quarantine\30.03.2012_14.48.11\mbr0000\tdlfs0000\tsk0006.dtaWin64/Olmarik.AF trojan (unable to clean)00000000000000000000000000000000I Quote I run Zone Alarm Security Suite and the teatimer program (is it SAS, or Spybot?Is your Zone Alarm Security Suite firewall enabled? TeaTimer belongs to Spybot. Quote Why didn’t ZA or teatimer catch this stuff coming in? Do you think they prevented anything going out?If your Firewall is like mine I would imagine it caught the out-going traffic. Quote They sent me an “invitation” I had to accept so they could gain remote access. Is there any chance that’s where the rootkits came from and they’re harmless? Is there any way to tell where they came from and what they did--or are doing?It's almost impossible to determine where the rootkit came from. Quote I read also that malware can be downloaded to your computer through image files. Unfortunately, I have downloaded LOTS of image files--I draw as a hobby and when I see a picture I like, I download it to use as a reference. I have hundreds of pictures. I backed them all up to CD along with my other files when I did the back-ups this week. Would they have been scanned when downloaded? Would something have shown up if there was something in them? Could they/should they be scanned now on the CD? (I’d like to keep them if I could, but if there’s any chance they’ll do harm, I won’t keep them--but is it safe to get my other files off the disk now?)I really depends where you downloaded them from. I really can't say if they had been scanned but I would imagine they were. They should be scanned before replacing them on your computer. Scan them with your AV and also MBAM. Quote Are there any other types of files malware could now be hiding in--word or excel files, for example..Not likely unless you received a file from someone who was infected. Quote I read that the only way to be sure my computer is clean is to reformat completely and reinstall the disks. I’m not sure I could handle that, even if I bought the disks (could it be done from the recovery disks, or does reformatting require original installation disks?) Besides, how safe is it really for how long--if this stuff got in once, why couldn’t it get in again the first time I went on-line? Is it really a fail-safe?That's really the safest way to go and it is fail-safe Quote I don’t save/remember passwords, not even in Outlook for e-mail; I don’t keep password lists on my computer--but I do have a document I save to flash-drive with passwords. Is it possible my passwords are compromised anyway--could the info be stolen when I had the file open while working in it? Same with account #s--the only time they’re on my computer is when I type them in on a “secure” site. Wouldn’t that require a program to log keystrokes, and is there any way to tell if that happened? (I e-filed my taxes, all our taxes, on-line about a month ago. I shudder to think that I typed in social security #s and everything. Is this info vulnerable?)That could only be done if a keylogger was put on your computer and there was no evidence of that. Quote One of the articles mentioned something about changing passwords if you use a router. We have a router; this computer is attached to the router through a line, but my daughter’s laptop is wireless. This computer is the administrator for the router. Is her computer in danger? Do I need to change the password? (And if I do, how do I know it’s safe to do it now?)Some modems do have passwords on them and some don't. I probably wouldn't hurt to change it. Quote I had ZA off for about a day when it seemed to be causing the problem (I exited from the task tray; does that turn off the firewall too, or just the antivirus?) It’s been back on most of the time since then though. But teatimer resident is still off--I turned it off when your instructions said to. Should I turn it back on yet?I'm not sure how ZoneAlarm works. You should turn on teatimer again. Quote ZA scanned while ESET was scanning, and it came up with 4 items--but when I looked at them, it appeared they were all items quarantined by TDSSKiller. I’m assuming they’re nothing to worry about now. Is that correct?As soon as TDSSKiller is removed, they will be gone. Quote My big fear is having done the income taxes and paying bills on-line, wondering how much of a possibility there is that my information was compromised. I thought as I was on a secure site there was nothing to worry about. Is there no way to determine if anything was stolen?I highly doubt it especially if you have the ZoneAlarm Firewall enabled. Let's do some cleanup To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ***************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like FIREFOX. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Hi Superdave, I can't thank you ENOUGH, both for helping me and for having the patience to answer all my questions (and address my fears!). I ran the scans you recommended. I have just a couple more questions: I have been running Zone Alarm suite, spybot, and SAS for a couple of years; I update them periodically (I have to get back onto a schedule again, I admit) and also do scans with MBAM, CCleaner, Spyware Blaster...should I keep doing all of this, or are any of them not really necessary? I was thinking I should add TFC (or is CCleaner enough), ESET, Securia occasionally...should I? Should I also be running anything else on a regular basis (like TDSSkiller?) or are these better left to only when there are problems and someone who actually knows what they're doing is supervising their use? Should I now delete all of the programs we used in this fix and their logs from my desktop, or just move them to a folder and keep them? Secunia listed 4 instances of Java; I checked Java's website and they said delete older versions, so I'm just updating the latest. Are we all done now, and would it be OK to defrag? With all the stuff I've removed, I'm sure it needs it. Again, Thank you for all you've done; I can't imagine how I would have handled this without you. As I said, this computer is my livelihood and my family's sole income and source of security. What you've done is extremely important. Thank you again!Quote I have been running Zone Alarm suite, spybot, and SAS for a couple of years; I update them periodically (I have to get back onto a schedule again, I admit) and also do scans with MBAM, CCleaner, Spyware Blaster...should I keep doing all of this, or are any of them not really necessary?It's probably not necessary but if you have the time it wouldn't hurt. Quote I was thinking I should add TFC (or is CCleaner enough), ESET, Securia occasionally...should I?Wouldn't hurt. Quote Should I also be running anything else on a regular basis (like TDSSkiller?) or are these better left to only when there are problems and someone who actually knows what they're doing is supervising their use?No, that's not necessary. Quote Should I now delete all of the programs we used in this fix and their logs from my desktop, or just move them to a folder and keep them?Not necessary. You probably won't need them again. Quote Are we all done now, and would it be OK to defrag? With all the stuff I've removed, I'm sure it needs it.It's a good idea to do that about once a month. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3214. |
Solve : Computer processing noises are driving me crazy? |
|
Answer» It may just be my computer, but in the last 5 or 6 months it seems like it is getting more and more bogged down and the constant processing / clicking noise is driving me crazy. Before I spent any money upgrading ram or anything, I would like to have my logs checked to make sure there isn't something else going on.
Click I Agree to start the program. ComboFix will then extract the necessary files and you will see this: As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. This will not occur in Windows Vista and 7 It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. If you did not have it installed, you will see the prompt below. Choose YES. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will CONTINUE it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt). Leave your computer alone while ComboFix is running. ComboFix will restart your computer if malware is found; allow it to do so. Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.Thank you for taking a look. Here is the log from ComboFix. ComboFix 12-04-07.02 - Mike 04/07/2012 7:24.16.2 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.998.323 [GMT -5:00] Running from: c:\documents and settings\Mike\Desktop\AV Tools\ComboFix.exe AV: Kaspersky Anti-Virus *Disabled/Updated* {2C4D4BC6-0793-4956-A9F9-E252435469C0} FW: COMODO Firewall *Enabled* {043803A3-4F86-4ef6-AFC5-F6E02A79969B} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\documents and settings\All Users\Application Data\TEMP . . ((((((((((((((((((((((((( Files Created from 2012-03-07 to 2012-04-07 ))))))))))))))))))))))))))))))) . . 2012-04-05 04:53 . 2012-04-05 05:10418464----a-w-c:\windows\system32\FlashPlayerApp.exe 2012-03-22 19:56 . 2012-03-22 19:56592824----a-w-c:\program files\Mozilla Firefox\gkmedias.dll 2012-03-22 19:56 . 2012-03-22 19:5644472----a-w-c:\program files\Mozilla Firefox\mozglue.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-04-05 05:10 . 2011-07-02 01:4770304----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2012-03-11 21:13 . 2011-06-30 14:3897760----a-w-c:\windows\system32\drivers\inspect.sys 2012-03-11 21:13 . 2011-06-30 14:3831704----a-w-c:\windows\system32\drivers\cmdhlp.sys 2012-03-11 21:13 . 2011-06-30 14:38494968----a-w-c:\windows\system32\drivers\cmdGuard.sys 2012-03-11 21:13 . 2011-06-30 14:3818056----a-w-c:\windows\system32\drivers\cmderd.sys 2012-03-11 21:13 . 2011-12-24 01:1333984----a-w-c:\windows\system32\cmdcsr.dll 2012-03-11 21:13 . 2011-06-30 14:37301224----a-w-c:\windows\system32\guard32.dll 2012-02-04 23:59 . 2012-02-04 23:5969632----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut5_75E8EDD2A1E346219D6D5DDBB46E7CDE.exe 2012-02-04 23:59 . 2012-02-04 23:5953248----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut4_E636F7D111FF4BB7A8037F8F16F3DE73.exe 2012-02-04 23:59 . 2012-02-04 23:5953248----a-r-c:\documents and settings\AIDAN.MICHAEL\Application Data\Microsoft\Installer\{E636F7D1-11FF-4BB7-A803-7F8F16F3DE73}\NewShortcut1_E636F7D111FF4BB7A8037F8F16F3DE73.exe 2012-02-03 09:22 . 2009-09-21 20:291860096----a-w-c:\windows\system32\win32k.sys 2012-01-11 19:06 . 2012-02-16 02:123072------w-c:\windows\system32\iacenc.dll 2012-01-09 16:20 . 2009-09-21 20:40139784----a-w-c:\windows\system32\drivers\rdpwd.sys 2012-03-22 19:56 . 2011-09-01 23:5297208----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AVP"="c:\program files\Kaspersky Lab\Kaspersky Anti-Virus 2011\avp.exe" [2010-11-03 365336] "COMODO Internet Security"="c:\program files\COMODO\COMODO Internet Security\cfp.exe" [2012-03-11 6749512] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-01-13 460872] . c:\documents and settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2004-10-15 65588] NETGEAR WG111v3 Smart Wizard.lnk - c:\program files\NETGEAR\WG111v3\WG111v3.exe [2008-7-1 2326528] Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904] . [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-10-12 113024] . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "AppInit_DLLs"=c:\windows\system32\guard32.dll . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE] @="" . [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Squeezebox Server Tray Tool.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Squeezebox Server Tray Tool.lnk backup=c:\windows\pss\Squeezebox Server Tray Tool.lnkCommon Startup . [HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^OpenOffice.org 3.0.lnk] path=c:\documents and settings\Mike\Start Menu\Programs\Startup\OpenOffice.org 3.0.lnk backup=c:\windows\pss\OpenOffice.org 3.0.lnkStartup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2012-01-03 07:37843712----a-w-c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\APSDaemon] 2011-09-27 13:2259240----a-w-c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe] 2008-08-21 12:0015360----a-w-c:\windows\system32\ctfmon.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EEventManager] 2009-12-03 15:12976320----a-w-c:\program files\Epson Software\Event Manager\EEventManager.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FUFAXSTM] 2009-12-03 05:00847872----a-w-c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2006-10-29 15:1786016----a-r-c:\windows\system32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2006-10-29 15:1798304----a-r-c:\windows\system32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelAudioStudio] 2006-07-13 20:349134080----a-w-c:\program files\Intel Audio Studio\IntelAudioStudio.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2006-10-29 15:1781920----a-r-c:\windows\system32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] 2011-10-24 20:28421888----a-w-c:\program files\QuickTime\QTTask.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2011-04-08 17:59254696----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Epson Software\\Event Manager\\EEventManager.exe"= "c:\\Program Files\\EpsonNet\\EpsonNet Setup\\tool09\\ENEasyApp.exe"= "c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"= . [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "9000:TCP"= 9000:TCP:Squeezebox Server 9000 tcp (UI) "9001:TCP"= 9001:TCP:Squeezebox Server 9001 tcp (UI) "9002:TCP"= 9002:TCP:Squeezebox Server 9002 tcp (UI) "9003:TCP"= 9003:TCP:Squeezebox Server 9003 tcp (UI) "9004:TCP"= 9004:TCP:Squeezebox Server 9004 tcp (UI) "9005:TCP"= 9005:TCP:Squeezebox Server 9005 tcp (UI) "9006:TCP"= 9006:TCP:Squeezebox Server 9006 tcp (UI) "9007:TCP"= 9007:TCP:Squeezebox Server 9007 tcp (UI) "9008:TCP"= 9008:TCP:Squeezebox Server 9008 tcp (UI) "9009:TCP"= 9009:TCP:Squeezebox Server 9009 tcp (UI) "9010:TCP"= 9010:TCP:Squeezebox Server 9010 tcp (UI) "9100:TCP"= 9100:TCP:Squeezebox Server 9100 tcp (UI) "8000:TCP"= 8000:TCP:Squeezebox Server 8000 tcp (UI) "10000:TCP"= 10000:TCP:Squeezebox Server 10000 tcp (UI) "9090:TCP"= 9090:TCP:Squeezebox Server 9090 tcp (UI) "3483:UDP"= 3483:UDP:Squeezebox Server 3483 udp "3483:TCP"= 3483:TCP:Squeezebox Server 3483 tcp . R1 cmdGuard;COMODO Internet Security Sandbox Driver;c:\windows\system32\drivers\cmdGuard.sys [6/30/2011 9:38 AM 494968] R1 cmdHlp;COMODO Internet Security Helper Driver;c:\windows\system32\drivers\cmdhlp.sys [6/30/2011 9:38 AM 31704] R1 kl2;kl2;c:\windows\system32\drivers\kl2.sys [6/9/2010 4:43 PM 11352] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2010 1:25 PM 12880] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67664] R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [6/29/2010 12:48 PM 116608] R2 EAPPkt;Realtek EAPPkt Protocol;c:\windows\system32\drivers\EAPPkt.sys [10/9/2007 4:13 PM 38144] R3 klim5;Kaspersky Anti-Virus NDIS Filter;c:\windows\system32\drivers\klim5.sys [5/7/2010 11:06 AM 32856] R3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\drivers\klmouflt.sys [11/2/2009 7:27 PM 19472] R3 RTL8187B;NETGEAR WG111v3 54Mbps Wireless USB 2.0 Adapter Vista Driver;c:\windows\system32\drivers\wg111v3.sys [12/28/2007 6:02 PM 287232] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/4/2012 11:53 PM 253600] . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ADOBEFLASHPLAYERUPDATESVC . Contents of the 'Scheduled Tasks' folder . 2012-04-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-05 05:10] . 2012-04-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official uInternet Settings,ProxyOverride = TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\documents and settings\Mike\Application Data\Mozilla\Firefox\Profiles\uk3k73oz.default\ FF - user.js: yahoo.homepage.dontask - true . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-04-07 07:31 Windows 5.1.2600 Service Pack 3 NTFS . detected NTDLL code modification: ZwClose . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- . - - - - - - - > 'winlogon.exe'(868) c:\program files\SUPERAntiSpyware\SASWINLO.DLL c:\windows\system32\WININET.dll . - - - - - - - > 'explorer.exe'(304) c:\windows\system32\WININET.dll c:\program files\Windows Desktop Search\deskbar.dll c:\program files\Windows Desktop Search\en-us\dbres.dll.mui c:\program files\Windows Desktop Search\dbres.dll c:\program files\Windows Desktop Search\wordwheel.dll c:\program files\Windows Desktop Search\en-us\msnlExtRes.dll.mui c:\program files\Windows Desktop Search\msnlExtRes.dll c:\windows\system32\ieframe.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . Completion time: 2012-04-07 07:33:09 ComboFix-quarantined-files.txt 2012-04-07 12:33 ComboFix2.txt 2011-07-06 22:16 ComboFix3.txt 2011-07-02 03:47 ComboFix4.txt 2011-04-08 03:38 . Pre-Run: 58,909,536,256 bytes free Post-Run: 58,930,921,472 bytes free . - - End Of File - - D10E599F924B7B5F6570E2E1C1F4E353 I seriously doubt that your computer is infected. I suspect that the noise you hear is some of the hardware going bad; either your harddrive or one of the fans. You could open the box and see if you can isolate the noise. I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Okay that's good news, and I seriously hope I'm not wasting your time. I explained my situation to a reliable source who said it sounded like a bug. I do sincerely appreciate your help. Here is the ESET log. Thank you. [emailprotected] as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=17e1e7d750000e45a6e1160e9aef7e3e # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-04-07 09:23:17 # local_time=2012-04-07 04:23:17 (-0600, Central Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 73272399 73272399 0 0 # compatibility_mode=768 16777215 100 0 52699339 52699339 0 0 # compatibility_mode=1024 16777215 100 0 45287938 45287938 0 0 # compatibility_mode=1280 16777175 100 0 18655359 18655359 0 0 # compatibility_mode=3073 16777213 80 71 1012073 9320834 0 0 # compatibility_mode=8192 67108863 100 0 0 0 0 0 # scanned=71721 # found=0 # cleaned=0 # scan_time=2000 Quote I explained my situation to a reliable source who said it sounded like a bug.I haven't seen an infection that would make noises on the computer. I can't see anything bad on your computer. You will have to open the box and try to see what is making the noise. Please let me know what you find. |
|
| 3215. |
Solve : Computer acting weird and no Internet Access? |
|
Answer» You should contact your Internet Service Provider to set up a connection.i contacted them they state the issue is with Internet Explorer not RESPONDING and the virus may have wiped out my drivers?They were unable to help,not sure what i am going to do now?Ok. Let's try to create a NEW connection. Click Start, Control Panel, Network connections and click "create a new connection". You will get the connection Wizard. Click NEXT and select Connect to the internet. Click choose from a list of ISP's and click next. Since I don't know your ISP you will have to search for it. The next drop-down box has two options. The first is Get online with MSN(only GOOD in US.) and the second is Select from a list of ISP's. |
|
| 3216. |
Solve : Computer classroom always virus infected.? |
|
Answer» Every one, we are computer classroom adminitrator, because all COMPUTERS are USED for all students. |
|
| 3217. |
Solve : major problems with computer speed. Need big time help? |
|
Answer» That looks good. If there are no other issues, we can do some cleanup.
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a MINUTE or two. * Please LET TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. **************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & DESTROY. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Okay. I have completed everything. Computer runs so much better than before. Thanks for all of your help! Sincerely. Now can I uninstall any of the programs you had me install throughout this cleanup process? Also, would you suggest me incresing my RAM? I only have 2GB. Quote would you suggest me incresing my RAM? I only have 2GB.Vista only requires 1 Gb so you should be good with 2. Quote Now can I uninstall any of the programs you had me install throughout this cleanup process?YES. You should consider keeping SAS and MBAM. Update them and run them on a regular basis. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3218. |
Solve : Windows 7 Computer Turns Off Every Time ANY Folder Is Opened? |
|
Answer» I Have Windows 7 Gateway SX2851 |
|
| 3219. |
Solve : Computer turning off and desktop icons not showing? |
|
Answer» Specs: Gateway 835 GM Windows XP Intel Pentium D CPU, 2.80 GHz 1.0GB RAM, Intel 82945G I cleaned off my fan and it still happened.You only have ONE fan??!! Hopefully you have more. Try cleaning them all out then use the computer with the side OFF so it's open to the air. Check all your fans are working as they should. I don't know why your desktop icons should vanish like that unless, as you say, it's because of malware operating. When the icons disappear what happens then? Does your computer shut down? Do you have a blank desktop but otherwise all seeming to work OK? What? Quote I ran AVGI assume you are referring to the AVG free antivirus program scan. If so then try this to start with... Download Ewido/AVG Anti Spyware from here …. http://www.ewido.net/en/ It has a fully working 30 day trial period. Install it and update it to the latest definitions. Do NOT use it yet. Now boot to safe mode. Here’s a “how to” if you’re not sure .. http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 When in safe mode run a full system scan with AVGAS and let it fix what it wants to. REMEMBER TO SAVE THE SCAN REPORT and also remember where you saved it. [FOOTNOTE > this is a good program to use as an “on demand” scanner even after the trial period is over. Keep it updated and use it to scan your computer from time to time]. ------------------------------------------------------------------------------------------------------ If this doesn’t succeed in fixing the problem download a self-extracting copy of HijackThis from here ……. http://downloads.malwareremoval.com/hijackthis_sfx.exe Save it to your Desktop. Double-click on the file hijackthis_sfx.exe file and it will self-extract into its own folder …… C:\Program Files\HijackThis Go to this folder and run the hijackthis.exe file. From the menu click on "Do a system scan and save a logfile". Copy and paste both the AVG AS scan report and the HJT logfile to this thread. More specific removal instructions will follow for any maware revealed. OJ Well I cleaned off the one in the back. It had dust all over it. When the icons disappear and I go into "desktop" via the start menu I get "windows cannot access the desktop because another program is using this process". That's not word for word what it says but is basically doesn't help matters. The only thing present is my trash can. No files will open either until after I restart. I'm going to run that program in safemode and see if it detects anything. Then I'll post the hijackthis log. Thank you for your help.No problems yet. I will check back if I have any. Thanks for the help! |
|
| 3220. |
Solve : **UPDATE ON WINFIXER FAMILY OF MALWARE**? |
|
Answer» The scum that write this stuff are being brought to BOOK ... |
|
| 3221. |
Solve : need help finding and deleting a link for a virus? |
|
Answer» we have been trying to find a link for days now. we think it may be a virus from an EMAIL. our computer will slow down, freeze up, and states " internet explorer CAUSED an error, and also says SHPRRPRT.DLL." we have tried to find this link or file but everything says that "link/file" is not found or will not let us OPEN a program to find it. PLEASE HELP!!!!! What antivirus and antispyware protection are you using? Try it ALL in safe mode with system restore turned off and post back.war3006....... |
|
| 3222. |
Solve : AVG Free Edition? |
|
Answer» I have the AVG Free Edition 7.1 which is no longer supported by Grisoft. I'm having difficulty uninstalling it. I tried to DELETE the files as well as remove it from the Add/Remove program but it will not allow me to uninstall. There was a WARNING to the effect that it failed initialization. I don't want it in my PC any longer because the support was somewhat lousy. It won't even acknoledge the license number given to me. Anyone got any ideas how to delete this monster altogether? ThanksTry using ccleaner.AVG Free edition has been updated to version 7.5, and their free antivirus product is still FREE it is a misunderstanding that the product is no longer available but it is FREE ans available from here:- |
|
| 3223. |
Solve : OMG PLEASE HELP ME PLEASE!!? |
|
Answer» ok, im on my laptop and i had a bunch of apps running, and i was very frustrated, so i just turned it off, well, then i turned it BACK on and this black screen keeps SAYING that i can reboot my comp, but it is running very SLOW, and sometimes my computer works but it is super slow, and i think i have a virus, but how do i get rid of it pLEASE HLEP MEPlease see below.Sometimes it helps to turn the computer off, unplug it (to MAKE sure everything is off). Wait a minute or two then plug it in and reboot.Turn the light off.... |
|
| 3224. |
Solve : Help please XP! Analyst of Hijackthis? |
|
Answer» Hello everyone! If anyone could help me I'd really appreciate it. ....I'm wondering...why don't you have the Windows XP Service Pack 2 installed? Both of these things can help with your protection.Well spotted, CBMatt, BUT there is one big problem. NEVER install SP2 on a machine which is, or may be, infected with malware. It will heap trouble on trouble. First, evonna_21, you MUST install SP1a. Get it here .... http://www.microsoft.com/windowsxp/downloads/updates/sp1/default.mspx THEN rescan with HJT and post a fresh log for review. OJThanks for everyone's advice I installed service pack 1 computer went dead. uninstalled computer still slow.Do you still have your Dell WIndows CD?Hey, Im pretty new at this too as you can probably tell but, maybe your over thinking the problem. It could be fairly simple. I dont know if this will help you at all but anytime my laptop starts to slow down, I look at my desktop. I always make sure its fairly clean. I only have a few things on my desktop. So why dontyou try getting rid of some of the stuff on there and see if that helps. Hope this helps, -Melissa-evonna_21 .... I don't know what has been going wrong for you. SP1 and SP1a wouldn't cause this problem on their own. I can only guess there is a bigger problem. If you CARRY on browsing the web on this computer without Service Packs your machine will be a magnet to malware. All sorts of nasties will get in. Follow GX1_Man's advice. Do you have that disk? If not ... please keep the computer OFFLINE, rescan with HJT and post a fresh log (using a different computer, obviously). I'll see what can be done to try and fix the computer without Service Packs. OJ |
|
| 3225. |
Solve : AD-AWARE SE PROBLEM? |
|
Answer» Heu Guys |
|
| 3226. |
Solve : Sandboxie 2.79.3 Beta? |
|
Answer» Any opinions or views on Sandboxie 2.79.3 Beta? I have seen it as a download on majorgeeks and wondered if it was WORTH installing it, but don't WANT to make the same mistake as I did with spyware terminator which caused more problems than it cured. |
|
| 3227. |
Solve : log of my computer anti spyware results? |
|
Answer» Can someone analyze these results for me? |
|
| 3228. |
Solve : IE7 Running Slow? |
|
Answer» So if u could let me know which problems to fix from my scan recently posted, that would be very helpful
************** After this, and what you said in your last post, your computer is clean. Remember to update AVG AS from time to time and scan your computer to keep it relatively clean. ************** If you are certain you have no more trouble you should clear out all old System Restore points then immediately create a new one so you have something to fall back on should anything go awry again. Also remember to make SR points on a regular basis. More on System Restore ... http://www.microsoft.com/windowsxp/using/helpandsupport/getstarted/ballew_03may19.mspx What may have lead up to your infection and help keep your computer free of malware … http://www.castlecops.com/t7736-So_how_did_I_get_infected_in_the_first_place.html http://www.help2go.com/Tutorials/Protect_Your_PC/Avoid_Web_Browser_Hijackers.html There is a little duplication but these tutorials are both well WORTH reading. If you do suffer an infection again you should run first Ccleaner to clean out your system. Get Ccleaner here but ensure you install it WITHOUT the optional Yahoo Toolbar download (you must untick/uncheck the relevant box on download) … http://www.ccleaner.com/ Also run through this before posting another HijackThis log … http://www.help2go.com/Tutorials/Protect_Your_PC/Get_Rid_of_Spyware%2C_Adware%2C_and_Web_Browser_Hijackers.html Best wishes. OJ |
|
| 3229. |
Solve : Aplication close unexpected..pls help me? |
|
Answer» Dear Experts, |
|
| 3230. |
Solve : Best Fire Wall?? |
|
Answer» Advice please? Is Zone Alarm free a good fire wall? Is Jetico BETTER, or is there ANOTHER free one that you would recommend? Thanks for any advice. LINK to Jetico download (from Majorgeeks) below. |
|
| 3231. |
Solve : Freezing at start-up? |
|
Answer» When ever I start up my computer I have to keep moving the mouse for about 5 minutes. When I do sit there and move the mouse it will work fine, its just a pain. When I first start it up it will APPEAR at the log-in screen and then from there I can access my account and go to the desktop. But, when I start up and it first gets to the log in screen if I am not sitting there and moving the computer will freeze. My computer makes those noises inside it when I am starting it up and when it freezes it becomes completely silent and nothing will work. I have to them turn it off and boot it back up. I haven't a foggiest what this COULD be. If anyone could help explain this to me, that would be excellent! [highlight]I'm not exactly sure what you mean by "copy"[/highlight] but they are two different problems that happened at two different times, so I made two different threads. I uninstalled SC4 and deleted all the plugins and the freezing up problem seemed to stop, but the icon one hasn't been fixed yet. What our dear patio means is...is this a legitimate copy of SC4 that you bought, or is it one that you downloaded and found a serial number for? If it's the latter, then that can cause a lot of trouble. Even looking for cracks/serials/keygens for games will often get you bugged.Quote Quote[highlight]I'm not exactly sure what you mean by "copy"[/highlight] but they are two different problems that happened at two different times, so I made two different threads. I uninstalled SC4 and deleted all the plugins and the freezing up problem seemed to stop, but the icon one hasn't been fixed yet. Thank you for translating. No, this is a real copy of the game. I have the box, and CD case and serial number and all of that jazz. |
|
| 3232. |
Solve : How to find a backdoor? |
|
Answer» This is a fairly simple question (I think) what is the easiest way to find a backdoor? If you want to learn how a hacker operates you will need to master at least one programming language first. good read i found that a while backawsome, thanks so much guys. What language would you recommend starting with. Im awsome with HTML and XHTML. Iv also heard of Perl and C++ but I dont know where to start.Have a read throught that article I posted. This is the extract on the author's view on programs ... http://www.catb.org/~esr/faqs/hacker-howto.html#skills1 OJOk thats perfect thanks so much again |
|
| 3233. |
Solve : Newdotnet infection - how?? |
|
Answer» that suxs I already emailed them last NIGHT asking about it. Funny, but true . . . You'd think if they were after a GOOD reputation for customer service they'd at least try to use proper spelling and punctuation. Anyway, I'm thinking of taking business elsewhere, turns out my contract is over so I can leave, if they let me. |
|
| 3234. |
Solve : HJT? |
|
Answer» I was wondering...where can I find a good HJT tutorial? It's such a useful program and we're all using it pretty frequently, so it'd be nice to know how to read the logs better. I can kinda get the main gist by looking at them and can sometimes spot things that shouldn't be there, but I don't quite fully understand everything involved.You could have a look, >here<, >here<, >here<, or >here<. Hope that helps. |
|
| 3235. |
Solve : Virus or I did something wrong? |
|
Answer» Windows XP running Norton AV 2007. |
|
| 3236. |
Solve : Win32/Rustock.gen!C virus HELP!!? |
|
Answer» i got the Win32/Rustock.gen!C according to windows after sending a error report. it KEEPS restarting my computer, and wont let me update. i had it for a while probably because i was not able to update for a while. recently i cant even stay on normal mode for more than a minute , it just turns off. im on safe mode right now. how do i remove it, nothing works. pleas help.DLoad; INSTALL; update and run AVG Anti-Spyware and Stinger in safe mode with SYSTEM restore turned off. still doesnt work. everytime i try to install updates my computer turns off.. =( This means you did what was suggested and still have the same issues ? ?Due to lack of feedback, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3237. |
Solve : Please have a look? |
|
Answer» I am not experiencing any problems at the moment so no rush, there's not much activity tonight. Might be tonight for you buts good morning for me skyblueWell, it's finally morning for me now (3 AM). And I've still got so much left to do before I can go to bed!As this issue appears to be resolved, I am closing this topic. If you are the original poster and you would like this topic to be re-opened for any reason, PM me or another moderator and it can be arranged. If you are not the original poster and you require help, please start a New Topic with information about your computer and your problem. |
|
| 3238. |
Solve : Big infection! Can't stop it!? |
|
Answer» At the beginning it just not responded when I would go to the propertys of a harddrive. but in the begining the person who Installed the whole PC (din't knew anything about PC's at that time) has splited the drive. This says it all. How would you like your machine setup ? ? 25G sounds a bit high for just the OS and Programs...No the person how did it is a computer specialist and a good friend of my dad I really trust him. But when I go to the properties of every folder and I count them together I have 12gig on that drive ?! how is this possible? Here is whats on the drive and the documents and settings of all users are changed to the E: drive.Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM allright I 'll not do it again.You haven't disabled anything too important. But next time, you could end up disabling something vital, and that wouldn't be good. Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM I checked you link I think the problem with me was that my firewall (including ports was restted when I used System restore.)If you disconnect from the internet and disable your firewall, do you still get any errors? Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PM And I don't know how to remove the regestry as I don't know the full path.First, backup your registry with a program like ERUNT... In CCleaner, if you right-click on the entry, you'll be given the option to open it in Regedit. After doing so, you can delete the APPROPRIATE entry. However, I suspect this will have the same results as fixing it with CCleaner.Quote from: CBMatt on June 17, 2007, 09:39:17 PM Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PMI don't have that problem anymore I don't know why it stopped but it looks like it fixed itselfI checked you link I think the problem with me was that my firewall (including ports was restted when I used System restore.)If you disconnect from the internet and disable your firewall, do you still get any errors? Quote from: CBMatt on June 17, 2007, 09:39:17 PM Quote from: Jonas Wauters on June 17, 2007, 12:54:45 PMTried it. No luck.And I don't know how to remove the regestry as I don't know the full path.First, backup your registry with a program like ERUNT... In CCleaner, if you right-click on the entry, you'll be given the option to open it in Regedit. After doing so, you can delete the appropriate entry. However, I suspect this will have the same results as fixing it with CCleaner. any other suggestions are more than welcome thanks for helping me but I think that I 'll have to do a format C: (If there is no other way) Jonas So, the errors have stopped then? Is that registry entry the only concern? If it's not giving you problems, I would just leave it alone until we can find some more information about it. It may be a bit annoying, but it should be harmless.No I still can't right click on a hardrive. then the explorer freeses. I've Dloaded and ran Eusing Free Registry Cleaner That found much more regesty errors but the explorer process I still freesing. Jonas The C drive contains much more than I've putted on it when I stop the $C Sharing The I get the error Message are you sure you want to stop there are still FOLDERS who are shared But I didn't share anything on that drive or is this error message normal? Jonas I'm afraid this might be a bit out of my range. You could back up your important data and reformat, but I would wait to see what patio has to say first.As I'm looking I can see that My C: drive is getting full again whitout I save anything on it. How is this possible is my computer hacked? What can I do about it? I can't access the secutery settings to look if there is anything wrong because the explore process freese when I try it! If I only format the C drive will this be enought to stop all this troble? Jonas Formatting solves all Windows-related problems. However, if it is a hardware issue, it will eventually return. I don't really see this as being a hardware issue, though.Yes but I have 3internal and one external hard drive. And those 3 internal hard drives are actually the same but are splitted when Win XP was first installed sow.. what about only formatting C: drive good idea?? Than I won't lose any data Jonas To be perfectly honest, Jonas, I'm not entirely sure. It's not my field of expertise...you may want to take your question over to the Hardware section to see what they have to say there. |
|
| 3239. |
Solve : Need the most advanced spyware? |
|
Answer» Hello all! Personally I use Microsoft Security Essentials. Asking what is the "best" is only going to start arguments. If AVG Free has stopped 3 "spy attacks" perhaps you need to review your browsing and downloading habits? I'm thinking of putting Microsoft Security Essentials on a old laptop I have is it easy to setup/update etcQuote from: mystic1 on August 04, 2011, 05:00:12 AM I'm thinking of putting Microsoft Security Essentials on a old laptop I have is it easy to setup/update etc Very easy to install and update, in fact you can set it to update automatically. Will give it a go then, thanks for the reply Hi Pennie. You should have a layered approach to malware, spyware, etc. While you should only run one AV program and one Firewall program, you can run more than one malware programs. I would suggest that you turn on Windows Defender. You can also install ThreatFire and also look at some of the suggestions I've posted below. You can also install Malwarebytes Anti-Malware (link and instructions below) and SuperAntiSpyware ( linked below with instructions.) These are not full-time scanners unless you pay for them but you can run them anytime you feel like doing so to keep your computer clean. You can download Malwarebytes Anti-Malware from here. Double Click mbam-setup.exe to install the application.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. ************************************************************************* SUPERAntiSpyware If you already have SUPERAntiSpyware be sure to check for updates before scanning! Download SuperAntispyware Free Edition (SAS) * Double-click the icon on your desktop to run the installer. * When asked to Update the program definitions, click Yes * If you encounter any problems while downloading the updates, manually download and unzip them from here * Next click the Preferences button. •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts * Click the Scanning Control tab. * Under Scanner Options make sure only the following are checked: •CLOSE browsers before scanning •Scan for tracking cookies •Terminate memory threats before quarantining •Please leave the others unchecked •Click the Close button to leave the control center screen. * On the main screen click Scan your computer * On the left check the BOX for the drive you are scanning. * On the right choose Perform Complete Scan * Click Next to start the scan. Please be patient while it scans your computer. * After the scan is complete a summary box will appear. Click OK * Make sure everything in the white box has a check next to it, then click Next * It will quarantine what it found and if it asks if you want to reboot, click Yes •To retrieve the removal information please do the following: •After reboot, double-click the SUPERAntiSpyware icon on your desktop. •Click Preferences. Click the Statistics/Logs tab. •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log. •It will open in your default text editor (preferably Notepad). •Save the notepad file to your desktop by clicking (in notepad) File > Save As... * Save the log somewhere you can easily find it. (normally the desktop) * Click close and close again to exit the program. **************************************************** SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.Quote from: SuperDave on August 04, 2011, 04:11:49 PM Hi Pennie. You should have a layered approach to malware, spyware, etc. While you should only run one AV program and one Firewall program, you can run more than one malware programs. I would suggest that you turn on Windows Defender. You can also install ThreatFire and also look at some of the suggestions I've posted below. This is one of the reason I joined this forum for finding sites/tips like the one's you've suggested feeling like I'm learning more each time I visit this site mystic1, did you really need to quote all that? And did your post really add anything? This is not a chat room. |
|
| 3240. |
Solve : Bots on my devices? |
|
Answer» My laptop has a bot and I suspect my iTouch and Dsi to have one to. My laptop won't even GO on the interent anymore. All of these DEVICES had recieved warnings to from comcast SAYING malicious software detected. I have very little knowledge of these things and am going insane. So patience would be suggested.... |
|
| 3241. |
Solve : Imesh problems - please help? |
|
Answer» Quote The Imesh search bar has also finally gone (yay) so not sure if that means all is ok now??Yes. Your computer is clean. Let's do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
***************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ENSURE a complete cleaning. ***************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- GO to Microsoft Windows Update and get all critical updates. ---------- I SUGGEST using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Ahhhh much better Thank you so much for all of your help Dave I really appreciate it!!Quote from: Lulylu on July 31, 2011, 09:29:04 PM Ahhhh much betterYou're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3242. |
Solve : Checking out downloaded file? |
|
Answer» HEY guys, I just downloaded a rar file for a program, and unzipped it to get a .exe file. Before i run it, tho, I want to know if it's virus free. I already scanned it with my antivirus program, but is there ANYTHING ELSE I can do? I'm using a laptop running windows VISTA, and I have AVG free edition 2011 P.S. sorry for the noobish postWhat is the file and from where did you obtain it? |
|
| 3243. |
Solve : sending emails at 2 am? |
|
Answer» Here is the Jotti again -
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt it is doing the eset scan right now - i neglected to follow through with all of your instructions and am doing so now. thank you i will post the scan results as SOON as it is finished. (just for info - i do not think the computer has sent any 'unauthorized' emails in the last few days) I would still like to know if there is ANYTHING in here that should not be there.Eset displayed that no threats were found - there is no list of found threats so I have nothing to put here. 70714 files scanned - scan time 2 hours and 4 minutes and 5 seconds--- I clicked "finished"Ok. I'm quite sure that your computer is clean. We can now do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
If this doesn't remove ComboFix, please let me know. Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a COMPLETE cleaning. **************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Thank you very much Dave. Since I did remove anything etc. is there a reason the computer was sending out the emails that you may know of? Thank you again so much for your help.Quote Since I did remove anything etc. is there a reason the computer was sending out the emails that you may know of?ComboFix did removed some malware which may have been causing the problem You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3244. |
Solve : Foreign factory infection computer products, more? |
|
Answer» A little more from the CIA computor security retiree. |
|
| 3245. |
Solve : Imported computers infected at factory? |
|
Answer» I know not Linux and did do a hijackit and saw nothing to be worried about in the search. |
|
| 3246. |
Solve : Windows is not letting me access logs from Malwarebytes Anti-malware? |
|
Answer» After scanning with Malwarebytes Anti- malware a message will pop up saying : Windows cannot access the specified device , path , or FILE . You may not have the appropriate permissions to access item . : ...................................... |
|
| 3247. |
Solve : nod32 update? |
|
Answer» how can i update my nod32 @ where can i get updated files? thank yoy all.If you have an Internet connection on your computer with Nod32, just open the Nod32 then CLICK on "Update now". See SAMPLE screen-shot. |
|
| 3248. |
Solve : Hijacked cookies.sqlite in Thunderbird? |
|
Answer» I ran that scan, and it crashed again:
MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version:Windows 7 Home Premium Edition Windows Information:Service Pack 1 (build 7601), 32-bit Base Board Manufacturer:MICRO-STAR INTERNATIONAL CO.,LTD BIOS Manufacturer:American Megatrends Inc. System Manufacturer:MICRO-STAR INTERNATIONAL CO.,LTD System Product Name:MS-7360 Logical Drives Mask:0x00003c3d Kernel Drivers (total 160): 0x82C42000 \SystemRoot\system32\ntoskrnl.exe 0x82C0B000 \SystemRoot\system32\halmacpi.dll 0x80BAF000 \SystemRoot\system32\kdcom.dll 0x89404000 \SystemRoot\system32\mcupdate_GenuineIntel.dll 0x89489000 \SystemRoot\system32\PSHED.dll 0x8949A000 \SystemRoot\system32\BOOTVID.dll 0x894A2000 \SystemRoot\system32\CLFS.SYS 0x894E4000 \SystemRoot\system32\CI.dll 0x8958F000 \SystemRoot\system32\drivers\Wdf01000.sys 0x89600000 \SystemRoot\system32\drivers\WDFLDR.SYS 0x8960E000 \SystemRoot\system32\drivers\ACPI.sys 0x89656000 \SystemRoot\system32\drivers\WMILIB.SYS 0x8965F000 \SystemRoot\system32\drivers\msisadrv.sys 0x89667000 \SystemRoot\system32\drivers\pci.sys 0x89691000 \SystemRoot\system32\drivers\vdrvroot.sys 0x8969C000 \SystemRoot\System32\drivers\partmgr.sys 0x896AD000 \SystemRoot\system32\drivers\volmgr.sys 0x896BD000 \SystemRoot\System32\drivers\volmgrx.sys 0x89708000 \SystemRoot\system32\drivers\pciide.sys 0x8970F000 \SystemRoot\system32\drivers\PCIIDEX.SYS 0x8971D000 \SystemRoot\System32\drivers\mountmgr.sys 0x89733000 \SystemRoot\system32\drivers\atapi.sys 0x8973C000 \SystemRoot\system32\drivers\ataport.SYS 0x8975F000 \SystemRoot\system32\drivers\amdxata.sys 0x89768000 \SystemRoot\system32\drivers\fltmgr.sys 0x8979C000 \SystemRoot\system32\drivers\fileinfo.sys 0x89833000 \SystemRoot\System32\Drivers\Ntfs.sys 0x89962000 \SystemRoot\System32\Drivers\msrpc.sys 0x8998D000 \SystemRoot\System32\Drivers\ksecdd.sys 0x899A0000 \SystemRoot\System32\Drivers\cng.sys 0x899FD000 \SystemRoot\System32\drivers\pcw.sys 0x89A0B000 \SystemRoot\system32\drivers\eufs.sys 0x89A14000 \SystemRoot\System32\Drivers\Fs_Rec.sys 0x89A1D000 \SystemRoot\system32\drivers\ndis.sys 0x89AD4000 \SystemRoot\system32\drivers\NETIO.SYS 0x89B12000 \SystemRoot\System32\Drivers\ksecpkg.sys 0x89C1B000 \SystemRoot\System32\drivers\tcpip.sys 0x89D65000 \SystemRoot\System32\drivers\fwpkclnt.sys 0x89D96000 \SystemRoot\system32\drivers\volsnap.sys 0x89DD5000 \SystemRoot\System32\Drivers\spldr.sys 0x89DDD000 \SystemRoot\System32\drivers\rdyboost.sys 0x89E0A000 \SystemRoot\System32\Drivers\mup.sys 0x89E1A000 \SystemRoot\System32\drivers\hwpolicy.sys 0x89E22000 \SystemRoot\System32\DRIVERS\fvevol.sys 0x89E54000 \SystemRoot\system32\drivers\eubakup.sys 0x89E5F000 \SystemRoot\system32\DRIVERS\disk.sys 0x89E70000 \SystemRoot\system32\DRIVERS\CLASSPNP.SYS 0x89EC7000 \SystemRoot\system32\drivers\cdrom.sys 0x89EE6000 \SystemRoot\System32\Drivers\aswSnx.SYS 0x89F56000 \SystemRoot\System32\Drivers\Null.SYS 0x89F5D000 \SystemRoot\System32\Drivers\Beep.SYS 0x89F64000 \SystemRoot\System32\drivers\vga.sys 0x89F70000 \SystemRoot\System32\drivers\VIDEOPRT.SYS 0x89F91000 \SystemRoot\System32\drivers\watchdog.sys 0x89F9E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0x89FA6000 \SystemRoot\system32\drivers\rdpencdd.sys 0x89FAE000 \SystemRoot\system32\drivers\rdprefmp.sys 0x89FB6000 \SystemRoot\System32\Drivers\Msfs.SYS 0x89FC1000 \SystemRoot\System32\Drivers\Npfs.SYS 0x89FCF000 \SystemRoot\system32\DRIVERS\tdx.sys 0x89FE6000 \SystemRoot\system32\DRIVERS\TDI.SYS 0x89FF2000 \SystemRoot\System32\Drivers\aswTdi.SYS 0x89B37000 \SystemRoot\System32\DRIVERS\netbt.sys 0x89B69000 \SystemRoot\system32\drivers\afd.sys 0x89C00000 \SystemRoot\System32\Drivers\aswRdr.SYS 0x89C05000 \SystemRoot\system32\DRIVERS\wfplwf.sys 0x89BC3000 \SystemRoot\system32\DRIVERS\pacer.sys 0x89C0C000 \SystemRoot\system32\DRIVERS\netbios.sys 0x89BE2000 \SystemRoot\system32\DRIVERS\serial.sys 0x89800000 \SystemRoot\system32\DRIVERS\wanarp.sys 0x89813000 \SystemRoot\system32\DRIVERS\VBoxUSBMon.sys 0x897AD000 \SystemRoot\system32\DRIVERS\VBoxDrv.sys 0x8981C000 \SystemRoot\system32\drivers\termdd.sys 0x897CA000 \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS 0x8C41E000 \SystemRoot\system32\DRIVERS\rdbss.sys 0x8C45F000 \SystemRoot\system32\drivers\nsiproxy.sys 0x8C469000 \SystemRoot\system32\drivers\mssmbios.sys 0x8C473000 \??\C:\Windows\system32\drivers\eudskacs.sys 0x8C47B000 \SystemRoot\System32\drivers\discache.sys 0x8C487000 \SystemRoot\System32\Drivers\dfsc.sys 0x8C49F000 \SystemRoot\system32\DRIVERS\blbdrive.sys 0x8C4AD000 \SystemRoot\System32\Drivers\aswSP.SYS 0x8C4F7000 \SystemRoot\system32\DRIVERS\tunnel.sys 0x8C518000 \SystemRoot\system32\DRIVERS\intelppm.sys 0x9142C000 \SystemRoot\system32\DRIVERS\nvlddmkm.sys 0x91E27000 \SystemRoot\System32\Drivers\nvBridge.kmd 0x91E29000 \SystemRoot\System32\drivers\dxgkrnl.sys 0x91EE0000 \SystemRoot\System32\drivers\dxgmms1.sys 0x91F19000 \SystemRoot\system32\drivers\usbuhci.sys 0x91F24000 \SystemRoot\system32\drivers\USBPORT.SYS 0x91F6F000 \SystemRoot\system32\drivers\usbehci.sys 0x91F7E000 \SystemRoot\system32\drivers\HDAudBus.sys 0x91F9D000 \SystemRoot\system32\DRIVERS\Rt86win7.sys 0x91FC2000 \SystemRoot\system32\DRIVERS\el90XND5.SYS 0x91FE8000 \SystemRoot\system32\DRIVERS\serenum.sys 0x91FF2000 \SystemRoot\system32\DRIVERS\fdc.sys 0x91400000 \SystemRoot\system32\drivers\i8042prt.sys 0x91418000 \SystemRoot\system32\drivers\kbdclass.sys 0x8C52A000 \SystemRoot\system32\drivers\mouclass.sys 0x8C537000 \SystemRoot\system32\drivers\CompositeBus.sys 0x8C544000 \SystemRoot\system32\DRIVERS\AgileVpn.sys 0x8C556000 \SystemRoot\system32\DRIVERS\HssDrv.sys 0x8C566000 \SystemRoot\system32\DRIVERS\rasl2tp.sys 0x8C57E000 \SystemRoot\system32\DRIVERS\ndistapi.sys 0x8C589000 \SystemRoot\system32\DRIVERS\ndiswan.sys 0x8C5AB000 \SystemRoot\system32\DRIVERS\raspppoe.sys 0x8C5C3000 \SystemRoot\system32\DRIVERS\raspptp.sys 0x8C5DA000 \SystemRoot\system32\DRIVERS\rassstp.sys 0x91425000 \SystemRoot\system32\DRIVERS\taphss.sys 0x8C5F1000 \SystemRoot\system32\DRIVERS\VBoxNetFlt.sys 0x91FFD000 \SystemRoot\system32\drivers\swenum.sys 0x8C60B000 \SystemRoot\system32\drivers\ks.sys 0x8C63F000 \SystemRoot\system32\DRIVERS\EuDisk.sys 0x8C670000 \SystemRoot\system32\drivers\umbus.sys 0x8C67E000 \SystemRoot\system32\drivers\usbhub.sys 0x8C6C2000 \SystemRoot\system32\DRIVERS\flpydisk.sys 0x8C6CC000 \SystemRoot\System32\Drivers\NDProxy.SYS 0x8C6DD000 \SystemRoot\system32\drivers\HdAudio.sys 0x8C72D000 \SystemRoot\system32\drivers\portcls.sys 0x8C75C000 \SystemRoot\system32\drivers\drmk.sys 0x8C775000 \SystemRoot\system32\drivers\usbccgp.sys 0x8C78C000 \SystemRoot\system32\drivers\USBD.SYS 0x8C78E000 \SystemRoot\System32\Drivers\usbvideo.sys 0x8C7B2000 \SystemRoot\system32\drivers\usbaudio.sys 0x8C7C6000 \SystemRoot\system32\drivers\USBSTOR.SYS 0x8C7DD000 \SystemRoot\System32\Drivers\crashdmp.sys 0x8C7EA000 \SystemRoot\System32\Drivers\dump_dumpata.sys 0x8C7F5000 \SystemRoot\System32\Drivers\dump_atapi.sys 0x8C400000 \SystemRoot\System32\Drivers\dump_dumpfve.sys 0x92D00000 \SystemRoot\System32\win32k.sys 0x8C411000 \SystemRoot\System32\drivers\Dxapi.sys 0x89E95000 \SystemRoot\system32\DRIVERS\monitor.sys 0x92F60000 \SystemRoot\System32\TSDDD.dll 0x92F90000 \SystemRoot\System32\cdd.dll 0x89EA0000 \SystemRoot\system32\drivers\luafv.sys 0x9902E000 \??\C:\Windows\system32\drivers\aswMonFlt.sys 0x99066000 \SystemRoot\System32\Drivers\aswFsBlk.SYS 0x99069000 \SystemRoot\system32\drivers\WudfPf.sys 0x99083000 \SystemRoot\system32\DRIVERS\lltdio.sys 0x99093000 \SystemRoot\system32\DRIVERS\rspndr.sys 0x990A6000 \SystemRoot\system32\drivers\HTTP.sys 0x9912B000 \SystemRoot\system32\DRIVERS\bowser.sys 0x99144000 \SystemRoot\System32\drivers\mpsdrv.sys 0x99156000 \SystemRoot\system32\DRIVERS\mrxsmb.sys 0x99179000 \SystemRoot\system32\DRIVERS\mrxsmb10.sys 0x991B4000 \SystemRoot\system32\DRIVERS\mrxsmb20.sys 0x991E7000 \SystemRoot\system32\drivers\peauth.sys 0x9927E000 \SystemRoot\System32\Drivers\secdrv.SYS 0x99288000 \SystemRoot\System32\DRIVERS\srvnet.sys 0x992A9000 \SystemRoot\System32\drivers\tcpipreg.sys 0x992B6000 \SystemRoot\System32\DRIVERS\srv2.sys 0x99306000 \SystemRoot\System32\DRIVERS\srv.sys 0x99358000 \SystemRoot\system32\DRIVERS\WUDFRd.sys 0x993E3000 \SystemRoot\system32\DRIVERS\asyncmac.sys 0x99000000 \SystemRoot\System32\Drivers\fastfat.SYS 0x99379000 \SystemRoot\system32\DRIVERS\cdfs.sys 0x77950000 \Windows\System32\ntdll.dll 0x47E60000 \Windows\System32\smss.exe 0x77B90000 \Windows\System32\apisetschema.dll 0x00D70000 \Windows\System32\autochk.exe Processes (total 61): 0 System Idle Process 4 System 320 C:\Windows\System32\smss.exe 428 csrss.exe 484 C:\Windows\System32\wininit.exe 496 csrss.exe 536 C:\Windows\System32\services.exe 568 C:\Windows\System32\lsass.exe 576 C:\Windows\System32\lsm.exe 696 C:\Windows\System32\winlogon.exe 724 C:\Windows\System32\svchost.exe 808 C:\Windows\System32\nvvsvc.exe 848 C:\Windows\System32\svchost.exe 956 C:\Windows\System32\svchost.exe 988 C:\Windows\System32\svchost.exe 1020 C:\Windows\System32\svchost.exe 1156 C:\Windows\System32\svchost.exe 1216 C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe 1240 C:\Windows\System32\nvvsvc.exe 1312 C:\Windows\System32\svchost.exe 1396 C:\Program Files\AVAST Software\Avast\AvastSvc.exe 1796 C:\Windows\System32\dwm.exe 1820 C:\Windows\explorer.exe 1984 C:\Windows\System32\spoolsv.exe 2016 C:\Windows\System32\svchost.exe 360 C:\Windows\System32\taskhost.exe 1016 C:\Program Files\a-squared Free\a2service.exe 1460 C:\Program Files\EASEUS\Todo Backup 2.0\bin\Agent.exe 660 C:\Program Files\Expat Shield\bin\openvpnas.exe 1784 C:\Program Files\Expat Shield\HssWPR\hsssrv.exe 2124 C:\Program Files\Expat Shield\bin\hsswd.exe 2156 C:\Program Files\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe 2224 C:\Windows\System32\svchost.exe 2264 C:\Windows\System32\UAService7.exe 2664 C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe 3004 WUDFHost.exe 3448 C:\Program Files\AVAST Software\Avast\AvastUI.exe 3456 C:\Program Files\Common Files\Java\Java Update\jusched.exe 3464 C:\Program Files\Windows Sidebar\sidebar.exe 3472 C:\Program Files\Skype\Phone\Skype.exe 3516 C:\Program Files\uTorrent\uTorrent.exe 3544 C:\Program Files\eMule\emule.exe 3748 C:\Windows\System32\SearchIndexer.exe 4048 C:\Program Files\Windows Media Player\wmpnetwk.exe 4084 C:\Windows\System32\svchost.exe 2788 C:\Windows\System32\svchost.exe 4484 C:\Program Files\Expat Shield\bin\openvpntray.exe 5240 C:\Windows\System32\svchost.exe 5864 C:\Windows\System32\svchost.exe 3668 C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE 4412 C:\Windows\System32\audiodg.exe 5404 C:\Program Files\MediaMonkey\MediaMonkey.exe 5972 C:\Program Files\Windows Media Player\wmplayer.exe 5768 C:\Windows\System32\wuauclt.exe 4440 C:\Program Files\Mozilla Firefox\firefox.exe 4536 C:\Windows\System32\SearchProtocolHost.exe 6116 C:\Windows\System32\SearchFilterHost.exe 4140 C:\Windows\explorer.exe 5376 C:\Users\Stuart\Downloads\MBRCheck.exe 2928 C:\Windows\System32\conhost.exe 3276 C:\Windows\System32\dllhost.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`06500000 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x00000009`ca500000 \\.\E: --> \\.\PhysicalDrive0 at offset 0x0000000e`ac500000 (NTFS) PhysicalDrive0 Model Number: ST3500418AS, Rev: CC35 Size Device Name MBR Status -------------------------------------------- 465 GB \\.\PhysicalDrive0 Windows 7 MBR code detected SHA1: 4379A3D43019B46FA357F7DD6A53B45A3CA8FB7 9 Done!Those last scans were to check out the MBR which could have caused the problem with Kernal_Stack_Inpage_Error but it checked out ok. How's the computer RUNNING now?It's running, it does still freeze from time to time, but I can't spot a pattern as to why it's freezing - I could be using Skype, clicking on a Bookmark in Firefox, or MediaMonkey could be playing a song while I'm in the kitchen and the needle starting skipping, as it were. The only WAY out is Ctrl+Alt+Del and a bit of patience until it comes back. I haven't dared to use Thunderbird all week, but I finally opened it this morning, downloaded my mail etc, and on closing it got a Calendar error (could not write to the calendar) which I've not seen before, so there may still be something lurking. The alternative I guess is a hardware error, the PC's 3 years old, but the only indication I have of a failure is the on-board ethernet socket stopped working about 3 months ago, so I stuck a PCI card in and it's been fine since. Quote I could be using Skype, clicking on a Bookmark in Firefox, or MediaMonkey could be playing a song while I'm in the kitchen and the needle starting skipping, as it were.Did it just start doing that? I don't see any infections on your computer so I have to surmise that it's a software or hardware problemNo, it was doing that before I started this thread, that was the freezing I was talking about in my first post. Thank you SO much for your time and effort Dave, I'm gonna invest in a new mobo and perhaps reinstall 7, see if that irons out the creases. You're welcome. Sorry I couldn't be more helpful. I will lock this thread. If you need it re-opened, please send me a pm.Latest update, new motherboard and reinstalled W7 fresh and it's working fine. Obviously a hardware problem and not malware. Cheers! |
|
| 3249. |
Solve : My Windows 7 Computer is infected with Win7 Security 2011? |
|
Answer» Here's the log
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin SCANNING your computer. Please be patient as this can take some time. •When the scan COMPLETES, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt ESET Log [recovering disk space - old attachment deleted by admin]Ok. That looks good. If there are no other issues, we can do some cleanup. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
To remove all of the tools we used and the files and folders they created do the following: Double click OTL.exe.
************************************************** Clean out your TEMPORARY internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ******************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - WEB of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Well Dave, everything seems to be good on my user. The "New Itouch" user is still corrupt. I can't open iTunes. Any ideas? Quote from: radioflyer91355 on July 10, 2011, 06:07:01 PM Well Dave, everything seems to be good on my user. The "New Itouch" user is still corrupt. I can't open iTunes. Any ideas?You should start a new thread for this one and we can take a look. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 3250. |
Solve : Uninvited guests...Exploit:Win32/pdfjsc.PC and VIRtool:JS/Obfuscator.BN? |
|
Answer» Quote from: SuperDave on June 28, 2011, 04:42:42 PM Are you trying to repair two computers at once?I do have two towers, but this one, the Dell Dimension B110 is the tower I am PRESENTLY commnicating from. It is the 'Ole Faithful in my household. The AMD tower is the tower I RECENTLY purchased, that you have assistied me with. Let us proceed then with the task at hand. Just tell me what it is that you require. I am using a Belkin KVM switch, which both units use but are kept seperated and are not presently sharing files or functioning togeter as a network group. Please advise as to how you wish to proceed. It isn't over until it's over.I've finished running scans on that computer. If there are no other issues, we can do some cleanup. Please let me know and we can do the cleanup.Quote from: SuperDave on June 28, 2011, 04:42:42 PM
I would be glad to have your continued support. Do you still feel that the other tower should be looked at as well? I would feel better knowing that both systems are absolutely infestation free; prior to networking the two together and sharing files. I will check back here tomorrow assuming that you would like to proceed. Thank you for your TIME and patience on my behalf.Quote Do you still feel that the other tower should be looked at as well?If you're having problems with it, please start a new thread. Ok. Let's do some cleanup on this one. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************ Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. *********************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any UPDATES are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!I initiated the process that you provided for the final cleanup. The temporary internet files and temp files that were "cleaned out" were limited to only what the DISKCLEANUP in SYSTEM TOOLS offers in the menu of choice. I do not believe this fulfills the scope of your intentions for the final cleanup regarding these files/folders. I have 13 different temp folders; containing hundreds of files spread between 3 different directories that include the WINDOWS OS, and Program Files. In addition, it turns out that that they are case senitive; 6 are uppercase and 5 are lowercase spellings of the same. Temporary internet files are relatively easy to assess, yet I have 3 of those as well in my "list" while not completely confident in which files for sure are seperated then get the AX. Long story short.....I am proceeding on the premise that i am not going to wipeout my system, because i didn't put all my eggs in one basket. I beleive there are file/folders that are directly relatedto some of the operations performed laft week. At any rate...I will send the info tomorrow. Thank you, Brent I apologize for being away from this thread for so long. I have been swamped with summer terms workload and really have not had the time to devote to the final details. OK. Where I am now is having run the uninstall on COMBOFIX, and did a clean-up of Temporary Internet Files (limited to what is flagged by Disk Cleanup in System Tools). I have not ran the program from old timer yet. I do HAVE A QUESTION... Should there be any folders or files left anywhere in my system that pertain to COMBOFIX? If the answer is no, then something isn't right, I sill have a directory folder in my directory tree titled COMBOFIX. This is after running the unistall as directed. I have not even ran the "problem child" after discovering this and my last post. I know I marked it as solved because I feel, Dave, that ultimately you helped me solve the problem at hand. But I could use just a little more direction on the details. Can you assist? Or should I begin a new thread? Thanks in advance. Quote I have not ran the program from old timer yet. I do HAVE A QUESTION... Should there be any folders or files left anywhere in my system that pertain to COMBOFIX? If the answer is no, then something isn't right, I sill have a directory folder in my directory tree titled COMBOFIX. This is after running the unistall as directed.After you run OTL cleanup it should be all gone. |
|