InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 3601. |
Solve : Mal_Otorun1 virus infecting my computer? |
|
Answer» Mal_Otorun1 virus INFECTING my computer. SOMEONE help me resolve this infection. it already infecting all my programs including AVG antivirus, Malwarebytes, Superantispyware, hijackthis, combofix. all programs do not run anymore. a suspicious folder name "classified" aldready installed in most of files and folders. please, someone guide me resolve this.. |
|
| 3602. |
Solve : evilfantasy:hope you get these 3 logs? |
|
Answer» evilfantasy' |
|
| 3603. |
Solve : help virus? |
|
Answer» i don't KNOW what going on yesterday my virus scan expired and then my computer starting shuting down on it's own i TRIED everything and did a REBOOT but now it won't run the NEW virus scan i got it keeps saying internal error and when i got to the online scans it give me an error on the PAGE and i can go to any other page but virus scanners please help thanksWhat are you using for an AV software? |
|
| 3604. |
Solve : What to do about a rootkit?? |
|
Answer» Quote from: MBAM scan Memory Processes Infected: These 3 infections will not go away, not with MBAM or SuperAntiSpyware. Twice I attempted to install HijackThis, but both times (once in safe mode) my computer crashed IMMEDIATELY after hitting "run" (which was unusual and obviously related to the program installation). So at this point I have 3 options: 1. Find a way to REMOVE the rootkit completely 2. Backup all my files and FORMAT my disk, reinstalling Windows Vista, then Windows 7 RC, and upgrade to W7 FULL next month. 3. Partition my computer. I'm not quite sure if this is possible, but I would partition the infected OS and install Windows 7 or 7 RC on the other partition. This would only be viable if I could access all the files I have now in the new partition. Option 2 seems like the best BET, because it ensures the complete removal of the rootkit and any backdoors, and I can just backup the stuff I really want and format the disk with all the excess crap I don't want (lots and lots of crap). Any advice, suggestions, or solutions?I'm the first to admit it, I'm not a virus guy. Go here and follow the directions, a specialist will be with you.Well I did follow the directions until HijackThis, which gave me problems like I said.Sorry man, I'm not an virus guy. I work really hard to keep it that way A specialist will be with you though.haha it's no problem, glad someone is posting in my thread at least I just don't want you to think that we're ignoring you. Yeah, that's it... honestly i already plan on just wiping my HD. at this point i'm just looking for my external drive and thinking about purchasing a new one. my computer has 2 years worth of crappy space consuming junk on it and i think it's a good idea.If your stuff is already backed up and you won't be copying the virus over, I don't see a reason not to. Just remember to FDISK as well. |
|
| 3605. |
Solve : am i already safe from this virus..? |
|
Answer» one time, when i was surfing the internet, a window prompt me that i have viruses on my pc that need to be repaired and it asked me to download the "PERSONAL antivirus". I accidentally downloaded it and i had learned that this "personal antivirus" is the virus itself. I cannot remove it from my pc. Now i tried to do the PC recovery on my compaq computer. Im using windows xp. I hit the F10 button to start up then i did the pc recovery that can uninstall all saved and installed programs on my computer.Now, i am using the computer now like new, i re-installed the internet,printer,office,etc. I did not see the Personal Antivirus anymore. Am I already SAFE from that virus? Was the pc recovery i did effective? or do you THINK the virus is still there? im scared now. |
|
| 3606. |
Solve : Trying to follow instructions here, but things are different????? |
Answer»
. The above procedure will:
---------- Use the ESET Online Antivirus Scanner This scanner requires Internet Explorer 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use NOTEPAD to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.# version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3917 (20090307) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.066 (20070917) # EOSSerial=b34ceeaaedab02458a1c6a33285dd51b # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2009-03-07 09:44:30 # local_time=2009-03-07 02:44:30 (-0700, Mountain Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=315486 # found=15 # scan_time=3240 C:\WINDOWS\Golden Palace Casino PT setup.exea variant of Win32/PTCasino application (unable to clean - deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\14.music.mp3a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned)20D5D04FBA44083A571DBCFAD2C38D39 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\15.crack.zipa variant of Win32/Agent.OAF trojan (deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\15.crack.zip »ZIP »crack.exea variant of Win32/Agent.OAF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\16.video.zipa variant of Win32/Agent.OAF trojan (deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\16.video.zip »ZIP »play_movie.exea variant of Win32/Agent.OAF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\17.setup.zipa variant of Win32/Agent.OAF trojan (deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\17.setup.zip »ZIP »setup.exea variant of Win32/Agent.OAF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\18.unpack.zipa variant of Win32/Agent.OAF trojan (deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\18.unpack.zip »ZIP »launch.exea variant of Win32/Agent.OAF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\19.keygen.zipa variant of Win32/Agent.OAF trojan (deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\19.keygen.zip »ZIP »keygen.exea variant of Win32/Agent.OAF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\20.serial.zipa variant of Win32/Agent.OAF trojan (deleted)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\20.serial.zip »ZIP »serial.exea variant of Win32/Agent.OAF trojan (error while cleaning - operation unavailable for this type of object - error while deleting - operation unavailable for this type of object - was a part of the deleted object)00000000000000000000000000000000 C:\WINDOWS\SYSTEM32\GroupPolicyManifest(2)\22.mpgvideo.mpga variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned)5E2F048F421471B68ACAE493051035CF Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
---------- Download OTCleanIt.exe and save it to your Desktop.
Important: Restart the computer before continuing. ---------- How is the computer running now? It seems to be okay now, but it never lasts! As always, I can't thank you enough. You guys here are really something. If you don't accept donations, you should start, because to contact Dell, HP, Microsoft, etc...most people, I believe those without warranty coverage have to pay to get help, and it is NOT cheap, and most of the time, for me, it's hard because the techs are all overseas, english is like their 8th language, etc...(I'm not being racist either, just stating that I have trouble explaining what I need help with!) I've always had the techs here reply really quickly, and my problems have always either been solved completely or I've gotten a thorough explanation as to what's going on. I'd love to be able to give BACK somehow to this site, so if there's anyway that's possible, please let me know!! THANK YOU SO MUCH FOR EVERYTHING!! HAVE A GREAT EVENING! ---------- Quote How is the computer running now? Honestly, still like crap? Just totally froze up when I was on ebay. Still seems to be slower than it should be, not like it was the last couple of days, but still not great, and the freezing up is still definitely there. Download Dial-a-Fix by djlizard, save it to the desktop then extract it to it's own folder.
How is it now?Okay, I did that step too. Nothing came up when the process was complete, no error messages or anything, but I did save the log just in case. It seems like I'm only having trouble on ebay, it is very slow there, and locks up almost immediately when I get on that site. I haven't been on the computer all day until now, and the MINUTE I got on ebay tonight it was slow. Everywhere else seems fine. I think this thing is possessed. I'm not sure if this matters much, or what it means, but the last week or so I keep getting a pop up window and a little yellow triangle on my toolbar that says my virtual memory minimum is too low. It says something about updating it, but it keeps happening, could this be part of my problem?How much RAM do you have in the computer?I just put in 1G, and had 576 before that. Here is what it says under my system information: Total Physical Memory: 1,536.00 MB Available Physical Memory: 542.48 MB Total Virtual Memory: 2.0 GB Available Virtual Memory: 1.73 GB It is back to running like crap everywhere again. This scanner works with Internet Explorer only! Scan with the BitDefender Online Scanner Click I Agree to the license and then install the ActiveX control. Please DO NOT change the Scanning Options. That will make your logs huge and we don't need to see clean files. Select Start Scan to begin. This scan can take a while so please be patient and let it complete. Once BitDefender completes the scan: Click-on the Detected Problems tab. Then select Click here to export the scan report This will save a file named bdscan.html I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later) You will have to upload the file online. The forums will not accept HTML. Go to File Dropper Click Upload Locate the file and double click it. Copy the download link and post it back here.Here is the link for the bitdefender file. <img src=http://www.filedropper.com/download_button.png width=127 height=145 border=0/> FileDropper Free File Hosting[/url]http://www.filedropper.com/bitdefender Or this one, I don't know which one I'm supposed to pick. The one in the last post is the one it said to choose for forums, etc...so I thought that would be it, but when I click on it, there's nothing there but that filedropper web page??That didn't find much. What problems are you still having?It's just running really slow still, and freezing up. Mainly still on ebay, but I think overall my internet should be faster. On ebay it takes forever to go from one page to another, and it freezes up a lot still. If I had some way of timing it, I would so I could give you an idea of just how slow it is. I truly think there is still something wrong somewhere, either that or I am paying way too much for the worst DSL service imaginable. But my aunt has the same isp and hers is much faster than mine. |
|
| 3607. |
Solve : PC became continually unresponsive while downloading SAS Update? |
|
Answer» My PC was running okay, just a bit slow, so I followed the steps given in the "Read this before requesting malware REMOVAL help" thread to clean up a bit and have the logs checked. I got as far as downloading the update to the SASpyware and my PC froze. I had to kill power to shut it down. When I restarted, I froze in different spots during start-up several times. Twice in the BIOS settings screen, 4-5 times in the Windows welcome screen and a few times after windows was loaded. I finally got it running via disconnecting my 2nd hard drive. It seems to be doing fine now but I suppose that other hard drive is trashed. It's clicking louder than normal while processing data. |
|
| 3608. |
Solve : Virus removal = internet issues? |
|
Answer» I had a virus in my system32 directory in the lsp.dll file. It took some doing but I finally got rid of the virus and in doing so had to delete the file. Now I can not access the internet. The internet is connected, but my browser says it can't find any of the websites I enter, including my usual homepage. I can't receive e-mails either. Super .... good going! Karnac is 100% right. Registry CURE software usually causes more problems than they will ever cure. |
|
| 3609. |
Solve : Spyware problem help!? |
|
Answer» I turned on my computer around 30 minutes ago, and RANDOMLY my desktop wallpaper was a MESSAGE saying something about me having spyware. Then a random program, which I have never installed in my life pops up : Systemsecurity and tells me theres 38 new virus's and the only way I can get rid of them is to PURCHASE systemsecurity. |
|
| 3610. |
Solve : Webserver Infected, and hijacked (PHP, Joomla)? |
|
Answer» Webserver has been HIJACKED, looking into RESOLVING. Any thoughts on what did this to my PRECIOUS site? |
|
| 3611. |
Solve : what is login.yahoo.com config reset_cookies_token? |
|
Answer» I get this message when I try to LOAD my mail from yahoo MESSENGER, I can't load anything from my aim either.....I don't know how to fix this....any help would be great...ThanksTry download yahoo messenger again....you MAY be MISSING a NECESSARY file ...a reinstall will fix it. |
|
| 3612. |
Solve : Spyware remover? |
|
Answer» Is anyone familiar with the SPYWARE remover "Evonsoft Computer Repair"? It is a free download from cnet.com. Is it a legitimate software? Does it work? Is it compatible with Norton? Any help WOULD be appreciated. My local computer geek shop has never heard of it!That is an UNSAFE program....avoid any program that claims to clean or FIX your registry. Try CCleaner |
|
| 3613. |
Solve : Norton Antivirus emptied? |
|
Answer» My Norton Antivirus file is a white screen . So I bought Zonelab Antivirals and spyware and uninstalled Symantec/Norton, BUT, at start up, Zone SAYS Norton still there and I must override to GET Zonelab RUNNING. How do I get Norton out of my REGISTER? Zonelab says it is Malware and won't open(Thank heaven). But how do I get rid of this thing ? I am running Windows Vista, Control panel shows no Norton but the blank file is still on my right click. Any suggestions for a very beginner?You must USE a removal tool found here. |
|
| 3614. |
Solve : Trouble extracting CleanWipe to remove Symantec, Could it be the trial WinRAR?? |
|
Answer» I have tried to remove Symantec Antivirus(Corporate Edition of Norton) from my computer without SUCCESS. After Contacting Symantec they SENT me a CleanWipe program that I downloaded. So how do I reove WINrar?Add/Remove programs. I've never had any problems with WinRAR. http://ccollomb.free.fr/unlocker/ the above will remove any-thing from your pc , download and read before using it's easy |
|
| 3615. |
Solve : TROJAN IN MY ITUNES..? |
| Answer» THANX a LOT for tryingh at LEAST.....i APPRECIATE it BRO' | |
| 3616. |
Solve : Epic Freeze Of Death - Safe Mode Not Working - Malware/Virus?? |
|
Answer» It will be worth it Alright guys, I recovered my system. Just letting you all know that it worked. So now I have a working computer! Yay! GREAT news! Thank you so much for all your help! |
|
| 3617. |
Solve : Help! My computer won't stop shutting down!? |
|
Answer» I'm really frustrated and paniced because everytime I log into my computer, it automatically shuts down and I have no control over it. It won't let me log into safemode either. I'm pretty sure I have a virus problem because I had seen fake anti-viral pop-ups before it started dying. I can't run an anti-virus scan because it only lasts about 5 seconds before shutting down. My computer simply shuts down, it isn't sudden, it seems like I shut it down but I didn't. I don't think it's an OVERHEATING problem because if I don't log in, it can go for hours and usually if it overheats it shuts down suddenly. Have you moved or bumped the case leading up to this problem?I've bumped the computer many times leading up to this and I've never had a problem. I'm in the process of cleaning it to see if that helps. I let it rest the entire night to let it cool down, but when I restarted it, it shutdown on me again. Also, it doesn't simply shut it down, it restarts it. I've also noticed that my on-access antivirus program has been disabled when I have never disabled it.If you're running over 4+ years with the same power supply there's a possibility that could be the problem......can you borrow one and swap it in and then at least we can eliminate it as a cause....It's possible there's a malware related issue as well but you have to be able to stay on long enough to run a couple of scans. |
|
| 3618. |
Solve : I need a program that will recover my microsoft word password-protected fil? |
|
Answer» :'(I have lost the password word of some very important DOCUMENTS. They are MICROSOFT word2003 password-protected files. Is there any program that can solve my PROBLEM?thank you.. |
|
| 3619. |
Solve : pease of mind? |
|
Answer» I accept it is a personel point of view regurding choise of registry CLEANER |
|
| 3620. |
Solve : Log Files Help? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.2 |
|
| 3621. |
Solve : Can't Open Any Anti-spyware, Bad Infection? |
|
Answer» I was downloading a plug-in for DivX and I just got the worst spyware of my life
New HijackThis Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:37:33 PM, on 8/15/2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe C:\Program Files\CA\eTrust\Antivirus\InoRT.exe C:\Program Files\CA\eTrust\Antivirus\InoTask.exe C:\WINDOWS\runservice.exe C:\WINDOWS\LogWatNT.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe C:\WINDOWS\explorer.exe C:\Program Files\Trend Micro\HijackThis\sniper.exe.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [XP SecurityCenter] "C:\Program Files\XPSecurityCenter\XPSecurityCenter.exe" /hide O4 - HKLM\..\Run: [buritos] buritos.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Highlight All Hyperlinks - C:\Program Files\Game Accelerator\highlightlinks.htm O8 - Extra context menu item: Highlight All Images - C:\Program Files\Game Accelerator\highlightimages.htm O8 - Extra context menu item: Highlight All Tables and Forms - C:\Program Files\Game Accelerator\highlighttable.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file) O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: ppctlcab - http://www3.ca.com/securityadvisor/pest/ppctlcab.CAB O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} - http://download.divx.com/player/DivXBrowserPlugin.cab O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust\Antivirus\InoTask.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: Event Log Watch (LogWatch) - Unknown owner - C:\WINDOWS\LogWatNT.exe -- End of file - 6114 bytesDisable Spybot's TeaTimer While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis fixes Please disable TeaTimer for now until you are clean. 1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident 2. Run Spybot S&D 3. Go to the Mode menu, and make sure Advanced Mode is selected. 4. On the left hand side, choose Tools > Resident uncheck Resident TeaTimer and OK any prompt and Restart your computer. Note: If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it. Extra note: If TeaTimer will not turn off then Uninstall Spybot until we are done with cleaning. ---------- Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) - O4 - HKLM\..\Run: [XP SecurityCenter] "C:\Program Files\XPSecurityCenter\XPSecurityCenter.exe" /hide - O4 - HKLM\..\Run: [buritos] buritos.exe - O9 - Extra button: (no name) - {85e1f530-48f4-11d9-9629-08ff2ffc9f67} - (no file) Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- Delete these files/folders, as follows: 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad.
Code: [Select]KillAll:: Folder:: C:\Program Files\XPSecurityCenter File:: C:\Documents and Settings\Christopher\Application Data\camyjasy.scr C:\Documents and Settings\Christopher\Application Data\ehakagugik.com C:\WINDOWS\system32\nidoviq.sys C:\Documents and Settings\All Users\Application Data\acid.sys C:\Documents and Settings\Christopher\Application Data\johoxi.vbs C:\WINDOWS\system32\nysozu.bin C:\WINDOWS\system32\etubaboh._dl C:\Program Files\Common Files\jocy.bat C:\WINDOWS\bavaxoqe.sys C:\WINDOWS\system32\izudab.vbs C:\Documents and Settings\All Users\Application Data\ukisysy.scr C:\Documents and Settings\All Users\Application Data\zyqukikej.reg C:\WINDOWS\qycuza.exe C:\WINDOWS\system32\_scui.cpl C:\WINDOWS\system32\winstra2.exe C:\WINDOWS\system32\winstra1.exe c:\progra~1\jumpsi~1\Glue Team Itch.exe 3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. Name the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully! ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply. Note: Do not mouseclick combofix's window while it is running. That may cause your system to freeze ---------- Next post add: New ComboFix logDisabled TeaTimer, fixed the HijackThis entries, and here is the ComboFix log; ComboFix: ComboFix 08-08-14.05 - Christopher 2008-08-15 18:23:48.3 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1178 [GMT -4:00] Running from: C:\Documents and Settings\Christopher\Desktop\Combo-Fix.exe Command switches used :: C:\Documents and Settings\Christopher\Desktop\CFScript.txt * Created a new restore point FILE :: C:\Documents and Settings\All Users\Application Data\acid.sys C:\Documents and Settings\All Users\Application Data\ukisysy.scr C:\Documents and Settings\All Users\Application Data\zyqukikej.reg C:\Documents and Settings\Christopher\Application Data\camyjasy.scr C:\Documents and Settings\Christopher\Application Data\ehakagugik.com C:\Documents and Settings\Christopher\Application Data\johoxi.vbs c:\progra~1\jumpsi~1\Glue Team Itch.exe C:\Program Files\Common Files\jocy.bat C:\WINDOWS\bavaxoqe.sys C:\WINDOWS\qycuza.exe C:\WINDOWS\system32\_scui.cpl C:\WINDOWS\system32\etubaboh._dl C:\WINDOWS\system32\izudab.vbs C:\WINDOWS\system32\nidoviq.sys C:\WINDOWS\system32\nysozu.bin C:\WINDOWS\system32\winstra1.exe C:\WINDOWS\system32\winstra2.exe . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Application Data\acid.sys C:\Documents and Settings\All Users\Application Data\ukisysy.scr C:\Documents and Settings\All Users\Application Data\zyqukikej.reg C:\Documents and Settings\Christopher\Application Data\camyjasy.scr C:\Documents and Settings\Christopher\Application Data\ehakagugik.com C:\Documents and Settings\Christopher\Application Data\johoxi.vbs C:\Program Files\Common Files\jocy.bat C:\WINDOWS\bavaxoqe.sys C:\WINDOWS\qycuza.exe C:\WINDOWS\system32\_scui.cpl C:\WINDOWS\system32\etubaboh._dl C:\WINDOWS\system32\izudab.vbs C:\WINDOWS\system32\nidoviq.sys C:\WINDOWS\system32\nysozu.bin C:\WINDOWS\system32\winstra1.exe C:\WINDOWS\system32\winstra2.exe . ((((((((((((((((((((((((( Files Created from 2008-07-15 to 2008-08-15 ))))))))))))))))))))))))))))))) . 2008-08-15 17:34 . 2008-08-15 17:34d--------C:\Program Files\Trend Micro 2008-08-07 09:45 . 2008-08-07 09:45d--------C:\Program Files\Linkword Languages 2008-07-21 15:25 . 2008-07-21 15:25d----c---C:\Python25 2008-07-21 12:06 . 2008-07-21 12:06d--------C:\Program Files\Smith Micro 2008-07-21 09:24 . 2008-07-03 14:169,875,456--a------C:\WINDOWS\system32\dzcore.dll 2008-07-21 09:24 . 2008-07-03 14:036,131,712--a------C:\WINDOWS\system32\daz-qt-mt.dll 2008-07-21 09:24 . 2008-07-03 13:562,076,672--a------C:\WINDOWS\system32\dz3delight.dll 2008-07-21 09:24 . 2008-07-03 14:031,785,856--a------C:\WINDOWS\system32\daz-qsa.dll 2008-07-21 09:24 . 2008-07-03 14:1849,152--a------C:\WINDOWS\system32\dzcarrara.dll 2008-07-21 09:24 . 2008-07-03 14:1833,280--a------C:\WINDOWS\system32\dzbryce6.dll 2008-07-21 09:24 . 2008-07-03 14:1826,624--a------C:\WINDOWS\system32\dzwrapper.dll 2008-07-21 09:23 . 2008-07-21 09:23d--------C:\Program Files\DAZ 2008-07-19 13:50 . 2008-07-19 13:50d--------C:\Documents and Settings\All Users\Application Data\FLEXnet 2008-07-19 13:43 . 2008-07-19 13:43d--------C:\Program Files\Bonjour 2008-07-19 13:29 . 2008-07-19 13:29d--------C:\Program Files\Common Files\Macrovision Shared 2008-07-18 17:59 . 2008-07-19 12:09156--a------C:\WINDOWS\Twunk001.MTX 2008-07-18 17:59 . 2008-07-19 12:093--a------C:\WINDOWS\Twain001.Mtx 2008-07-18 17:59 . 2008-07-18 17:590--a------C:\WINDOWS\Twunk002.MTX 2008-07-17 18:50 . 2008-07-17 18:55d--------C:\Documents and Settings\Christopher\Application Data\Queue Manager . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-08-15 21:59---------d-----wC:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2008-08-15 19:23---------d-----wC:\Program Files\Spybot - Search & Destroy 2008-08-15 18:5016,813----a-wC:\WINDOWS\myhawu.scr 2008-08-15 18:5015,818----a-wC:\WINDOWS\uvave.reg 2008-08-15 18:5014,688----a-wC:\Program Files\Common Files\ocucebo.inf 2008-08-15 18:5013,924----a-wC:\WINDOWS\ekiqe.vbs 2008-08-15 18:5013,844----a-wC:\Program Files\Common Files\dacyvuc._dl 2008-08-15 18:5011,980----a-wC:\Program Files\Common Files\eqycuzu._dl 2008-08-15 13:04---------d-----wC:\Documents and Settings\Christopher\Application Data\uTorrent 2008-08-14 01:15---------d--h--wC:\Program Files\InstallShield Installation Information 2008-08-13 05:45---------d-----wC:\Program Files\uTorrent 2008-07-21 19:22---------d-----wC:\Program Files\Common Files\DAZ 2008-07-19 23:01---------d-----wC:\Program Files\Common Files\Real 2008-07-19 22:55---------d-----wC:\Program Files\7-Zip 2008-07-19 17:43---------d-----wC:\Program Files\Common Files\Adobe 2008-07-17 20:34---------d-----wC:\Program Files\Java 2008-07-12 17:53---------d-----wC:\Program Files\Sims2Pack Clean Installer 2008-07-12 17:35---------d-----wC:\Program Files\Game Accelerator 2008-07-12 17:24---------d-----wC:\Program Files\CDisplay 2008-07-12 16:54---------d-----wC:\Program Files\CCleaner 2008-07-11 20:32---------d-----wC:\Program Files\GDS 2008-07-10 03:00---------d-----wC:\Program Files\DivX 2008-06-24 01:52---------d-----wC:\Documents and Settings\Christopher\Application Data\Apple Computer 2008-06-20 10:45360,320----a-wC:\WINDOWS\system32\drivers\tcpip.sys 2008-06-20 10:44138,368----a-wC:\WINDOWS\system32\drivers\afd.sys 2008-06-20 09:52225,920----a-wC:\WINDOWS\system32\drivers\tcpip6.sys 2008-04-16 00:3248,448-c--a-wC:\Documents and Settings\Christopher\Application Data\GDIPFONTCACHEV1.DAT 2005-09-03 13:4920-c--a-wC:\Program Files\Sims2Pack Clean Installer.ini 2004-06-23 18:5520,480-c--a-wC:\Program Files\ProcManager.exe . ((((((((((((((((((((((((((((( [emailprotected]_17.09.00.95 ))))))))))))))))))))))))))))))))))))))))) . - 2008-08-15 21:01:231,713--sha-wC:\WINDOWS\system32\mmf.sys + 2008-08-15 22:30:021,713--sha-wC:\WINDOWS\system32\mmf.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:56 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-09-17 02:07 8491008] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-09-17 02:07 81920] "SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 10:03 210472] "PPort11reminder"="C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-02-01 14:46 255528] "IntelliPoint"="C:\Program Files\Microsoft IntelliPoint\ipoint.exe" [2007-08-31 15:01 1037736] "nwiz"="nwiz.exe" [2007-09-17 02:07 1626112 C:\WINDOWS\system32\nwiz.exe] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 01:01:04 83360] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoChangeAnimation"= 0 (0x0) "NoStrCmpLogical"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "MemCheckBoxInRunDlg"= 0 (0x0) "NoStrCmpLogical"= 0 (0x0) "ForceClassicControlPanel"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "vidc.I420"= i263_32.drv "msacm.g723"= g723.acm "vidc.I263"= I263_32.drv [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^desktop.ini] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini backup=C:\WINDOWS\pss\desktop.iniCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak EasyShare software.lnk backup=C:\WINDOWS\pss\Kodak EasyShare software.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak software updater.lnk] path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Kodak software updater.lnk backup=C:\WINDOWS\pss\Kodak software updater.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch] --a------ 2008-03-08 10:02 2476408 C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] --a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite] --a------ 2008-01-17 12:51 486856 C:\Program Files\DAEMON Tools Lite\daemon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GameXL] --a------ 2008-03-14 19:50 233472 C:\Program Files\PowerISO\PWRISOVM.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch] --a------ 2007-01-29 22:10 46632 C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD] --a------ 2007-01-29 22:12 30248 C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PhotoShow Deluxe Media Manager] --a------ 2005-02-25 20:28 212992 C:\PROGRA~1\Ahead\NEROPH~2\data\Xtras\mssysmgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE] --a------ 2008-03-14 19:50 233472 C:\Program Files\PowerISO\PWRISOVM.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Realtime Monitor] --a--c--- 2001-08-08 10:27 376352 C:\Program Files\CA\eTrust\Antivirus\REALMON.EXE [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] --a--c--- 2005-01-12 03:01 32768 C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] --a------ 2008-06-10 04:27 144784 C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 "UpdatesDisableNotify"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "C:\\WINDOWS\\system32\\dpvsetup.exe"= "C:\\Program Files\\uTorrent\\uTorrent.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= R2 LicCtrlService;LicCtrl Service;C:\WINDOWS\runservice.exe [2007-12-06 11:32] R2 LogWatch;Event Log Watch;C:\WINDOWS\LogWatNT.exe [2000-06-08 14:15] R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 03:01] S3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2006-12-12 12:28] S3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2006-09-03 10:53] S3 idrmkl;idrmkl;C:\DOCUME~1\CHRIST~1\LOCALS~1\Temp\idrmkl.sys [] S3 pmxscan;USB ScanModule V5.1 Driver;C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-04 01:58] . Contents of the 'Scheduled Tasks' folder 2008-08-15 C:\WINDOWS\Tasks\AE21463891AAF74C.job - c:\progra~1\jumpsi~1\Glue Team Itch.exe [] 2008-08-09 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2007-01-10 15:42] 2008-08-15 C:\WINDOWS\Tasks\E7896B29962B2C8D.job - c:\progra~1\jumpsi~1\Glue Team Itch.exe [] 2008-08-15 C:\WINDOWS\Tasks\xcv.job - C:\Documents and Settings\Christopher\My Documents\xcv.bmp [] . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-08-15 18:30:39 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CA\eTrust\Antivirus\InoRpc.exe C:\Program Files\CA\eTrust\Antivirus\INORT.EXE C:\Program Files\CA\eTrust\Antivirus\InoTask.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe . ************************************************************************** . Completion time: 2008-08-15 18:40:12 - machine was rebooted ComboFix-quarantined-files.txt 2008-08-15 22:39:53 ComboFix2.txt 2008-08-15 21:10:04 ComboFix3.txt 2007-07-31 00:54:24 Pre-Run: 6,362,591,232 bytes free Post-Run: 6,364,704,768 bytes free 219--- E O F ---2008-08-15 07:07:46Looks much better. Still some work to do though. Download NoLop to your desktop from one of the links below...
---------- Download Malwarebytes' Anti-Malware (MBAM)
---------- Next post NoLop log MBAM logI ran both NoLop and Malwarebytes, here are the logs; NoLop: NoLop! Log by Skate_Punk_21 Fix running from: C:\Documents and Settings\Christopher\Desktop [8/15/2008] [6:55:16 PM] ---Infection Files Found/Removed--- C:\WINDOWS\tasks\AE21463891AAF74C.job C:\WINDOWS\tasks\E7896B29962B2C8D.job Beginning Removal... Rebooting... Removing Lop's Leftover Files/Folders... Editing Registry... **Fix Complete!** ---Listing AppData sub directories--- C:\Documents and Settings\All Users\Application Data\Adobe C:\Documents and Settings\All Users\Application Data\Ahead C:\Documents and Settings\All Users\Application Data\Aol -- EMPTY Directory C:\Documents and Settings\All Users\Application Data\Aol Downloads C:\Documents and Settings\All Users\Application Data\Aol Ocp C:\Documents and Settings\All Users\Application Data\Apple Computer C:\Documents and Settings\All Users\Application Data\Autodesk C:\Documents and Settings\All Users\Application Data\Brother C:\Documents and Settings\All Users\Application Data\Comodo C:\Documents and Settings\All Users\Application Data\Cyberlink C:\Documents and Settings\All Users\Application Data\Extreme Picture Finder C:\Documents and Settings\All Users\Application Data\Flawmessliesfunk -- EMPTY Directory C:\Documents and Settings\All Users\Application Data\Flexnet C:\Documents and Settings\All Users\Application Data\Google C:\Documents and Settings\All Users\Application Data\Grisoft C:\Documents and Settings\All Users\Application Data\Installshield C:\Documents and Settings\All Users\Application Data\Kodak C:\Documents and Settings\All Users\Application Data\Lavasoft C:\Documents and Settings\All Users\Application Data\Macromedia C:\Documents and Settings\All Users\Application Data\Macrovision C:\Documents and Settings\All Users\Application Data\Microsoft C:\Documents and Settings\All Users\Application Data\Napster C:\Documents and Settings\All Users\Application Data\Nview_profiles -- EMPTY Directory C:\Documents and Settings\All Users\Application Data\Quicktime C:\Documents and Settings\All Users\Application Data\Scansoft C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy C:\Documents and Settings\All Users\Application Data\Temp -- EMPTY Directory C:\Documents and Settings\All Users\Application Data\Viewpoint C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage C:\Documents and Settings\All Users\Application Data\Yahoo! Companion C:\Documents and Settings\Christopher\Application Data\Adobe C:\Documents and Settings\Christopher\Application Data\Ahead C:\Documents and Settings\Christopher\Application Data\Apple Computer C:\Documents and Settings\Christopher\Application Data\Brother C:\Documents and Settings\Christopher\Application Data\Comodo C:\Documents and Settings\Christopher\Application Data\Cyberlink C:\Documents and Settings\Christopher\Application Data\Daemon Tools C:\Documents and Settings\Christopher\Application Data\Divx C:\Documents and Settings\Christopher\Application Data\Help -- EMPTY Directory C:\Documents and Settings\Christopher\Application Data\Identities -- EMPTY Directory C:\Documents and Settings\Christopher\Application Data\Installshield C:\Documents and Settings\Christopher\Application Data\Intertrust C:\Documents and Settings\Christopher\Application Data\Macromedia C:\Documents and Settings\Christopher\Application Data\Microsoft C:\Documents and Settings\Christopher\Application Data\Mozilla C:\Documents and Settings\Christopher\Application Data\Queue Manager C:\Documents and Settings\Christopher\Application Data\Reallusion C:\Documents and Settings\Christopher\Application Data\Scansoft C:\Documents and Settings\Christopher\Application Data\Simple Star C:\Documents and Settings\Christopher\Application Data\Stopzilla! C:\Documents and Settings\Christopher\Application Data\Sun C:\Documents and Settings\Christopher\Application Data\Talkback C:\Documents and Settings\Christopher\Application Data\Utorrent C:\Documents and Settings\Default User\Application Data\Microsoft C:\Documents and Settings\Localservice\Application Data\Google -- EMPTY Directory C:\Documents and Settings\Localservice\Application Data\Microsoft C:\Documents and Settings\Networkservice\Application Data\Microsoft Mbamlog: Malwarebytes' Anti-Malware 1.24 Database version: 1056 Windows 5.1.2600 Service Pack 2 7:10:59 PM 8/15/2008 mbam-log-8-15-2008 (19-10-59).txt Scan type: Quick Scan Objects scanned: 40662 Time elapsed: 7 minute(s), 33 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
---------- Download OTMoveIt2 by OldTimer 1. Double click OTMoveIt2.exe to launch it. If using Vista Right-Click OTMoveIt and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
---------- Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
Important: Restart the computer before continuing. ---------- Run the Kaspersky Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to ANALYZE the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble VIEWING the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. -------------- Next post Kaspersky logRan Kaspersky, here is the log; Kaspersky log: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Saturday, August 16, 2008 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Saturday, August 16, 2008 01:11:28 Records in database: 1096789 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: A:\ C:\ D:\ E:\ Scan statistics: Files scanned: 126813 Threat name: 6 Infected objects: 7 Suspicious objects: 0 Duration of the scan: 03:15:36 File name / Threat name / Threats count C:\Program Files\ProcManager.exeInfected: not-a-virus:RiskTool.Win32.PsKill.a1 C:\temp\pootz_58.exeInfected: Trojan-Downloader.Win32.TSUpdate.f2 C:\WINDOWS\iconz.exeInfected: Trojan-Downloader.Win32.Lookme.k1 C:\WINDOWS\system32\cacore.dllInfected: not-a-virus:AdWare.Win32.Couponage.a1 C:\WINDOWS\system32\ezPopStub.exeInfected: not-a-virus:AdWare.Win32.EZula.bz1 C:\WINDOWS\woinstall.exeInfected: not-a-virus:AdWare.Win32.EZula.ak1 The selected area was scanned. |
|
| 3622. |
Solve : D and E drives not opening...showing that "disk is not formatted"........? |
|
Answer» I have a problem with OPENING my D and E drive of laptop........... when I double click on any of both drives it show disk is not formatted.....also this task of FORMATTING is not performed..........I have a lot of data in the drives.......... Are these external hard drives or are they partitions on the main HD? these are partitions in main hard driveCan you gain access to these partitions to save your data? If you can, save your data to DVD's or to your C drive and format these partitions. |
|
| 3623. |
Solve : Computer and mouse keep freezing up when I try to use anything ani virus!? |
|
Answer» Thanks BC for the explanation......hopefully she can get it to boot.Hello Karnac and BC_Programmer! BC_Programmer, you mentioned that I if have a windows CD, that I can run the recovery console from the disc and try the chkdsk from that; and to let it run overnight; just to be sure. Do I just insert the disk and it will prompt me? sorry I am by no means as gifted in this area as you and Karnac are lol!! After making sure that the boot order is set (you can access the "system setup" screen on most systems by pressing a key at startup, usually "del"; make sure your CD-ROM/DVD-ROM drive is first in the boot order. Booting into the "recovery console" isn't automatic. Silly me, I should have outlined it a little better. My apologies. MS does it better then I do, though Quote Starting the Windows Recovery Console from the Windows XP CD-ROMThank you BC_Programmer and Karnac for your help once again!! I will do my best to start the windows in the Recovery Console and I will post back and let you know how I do. This is still not clear to me by the instructions but maybe it will make more sense once I get started. Thank you!! and take care! Cherîe You can watch this video first so you know what to expect.....Recovery console is at the 15:50 mark. http://www.professormesser.com/2009/01/11/recovering-the-operating-system/Thank you Karnac, I watched it. I did the chkdsk scan from this but it didnt run very long. After it was done I ran it again and it said the volume appears to be in good condition. Should it take as long as the original one with the blue screen? Im not sure where I should go from here. Any ideas? or should I now try to download the rescue disk and try that? Thanks! CherîeBC_Programmer or Karnac, do either of you know where I would find the administrator password? somehow I did the chkdsk without it. Im wondering if this is why it didnt take very long to run. It was only about a minute. So was this the full scan? CherîeIf the administrative password is blank , try just press enter, that seems to be the default Unless BC wants to run another scan, look at burning the rescue disk and booting from it....then you can try a virus scan.Quote from: Karnac on July 31, 2009, 12:53:58 PM Unless BC wants to run another scan Nope, it's probably not a hard drive issue; must be something else. (at least we know the HD is in tip-top shape even it if all I basically did WASTE a lot of time Well hello BC_Programmer and Karnac!! I have great news! my computer is working perfectly! The bad news is Im not totally sure how LOL! Since I was having problems booting the normal way I used my CD to boot from then when it asked me in what mode I tried the last good configuration and it worked. Once I was finally on I didnt stay on too long and I would shut it down the proper way since it hadnt been shut down properly since all the freezing too place. Prior to this I took the sides off and blew some dust out in case it was overheating. After going back on the next time I downloaded a program called Advanced SystemCare not sure either of you have heard of it or not. I scans quite a few things including spyware, registry fix, privacy sweep, junk files clean, system optimization, security defense, security analyzer as well as a disk defragment. So so far so good and it now runs a lot faster than before. Feels like my computer just purged a bunch of crap and is now able to function properly. I want to thank the both of you for all your help. I really appreciate what you do for people and offering your time to those in need. take care and have a great weekend!! CherîeCherie, That's great to hear and you're most welcome.....I was thinking you might have taken it out back and popped a couple of slugs into it....Advanced System Care works well and does a quick job, but I would avoid the registry cleaner.....No program should be allowed to run in the registry....Consider downloading Web of Trust...This free program will keep you safe when you're browsing..... http://www.mywot.com/ ......... Thanks for getting back to us.Thank you Karnac! I had no idea I shouldnt let something run in my registry. Do you know why that is? and having already used it will I end up with any problems in the future? I will check that link out that you sent me. Thanks for sharing it with me. Cherîe No problem, just avoid using any cleaners or registry fixes.......Disk cleanup and defrag when needed and you'll be fine.basically programs mucking about in the registry is a bad idea- they try to mechanically understand what is stored there and determine wether they should delete it. The only section in the registry where that is possible is HKEY_CLASSES_ROOT, which stores registration information about OLE and ActiveX Objects- sometimes programs can be deleted/uninstalled and leave their registration info. Basically if the file doesn't exist the key can be deleted. (CCleaner's registry cleaner portion does this) the other keys- the ones used by programs to store data - could be anything. A prime example is a registry value that specifies, say, a filename. Most registry cleaners simply look to see if the file exists and delete the key if it doesn't exist- but what they fail to understand is that might not be the purpose of the key- it might specify a file to create, for example. In either case, a registry cleaners will never result in anything but miniscule gains in performance; and oftentimes can result in missing functionality or broken programs- sometimes issues so great that only a reinstall of windows can assure the issue is resolved. If you've used it your probably safe- it's constant usage (say, once a day) of the registry cleaners that make them prone to mistakes. That's not to say you should even use them in moderation, they are notorious troublemakers. on top of the occasional disk cleanup and defragmenter, a chkdsk once every month or so can't hurt, either. (in fact, it's best to run a chkdsk before you defragment anyway. |
|
| 3624. |
Solve : Terrible problem with TR/Crypt.XPACK.Gen - Trojan..? |
|
Answer» Hello everybody.. |
|
| 3625. |
Solve : UACD.sys Removal? |
|
Answer» Hi all-I've finally figured out what is so terribly wrong with my computer, it's got UACD.sys Hi all-I've finally figured out what is so terribly wrong with my computer, it's got UACD.sysYour HijackThis log is not attached, please attach it so an expert can help you.Thank you--I've updated my post to include it, don't know how that happened!Download ComboFix from one of the below links. You must rename it before saving it! Important! You MUST save ComboFix to your desktop. Link 1 Link 2 Link 3 Rename ComboFix to Combo-Fix before saving it to the desktop. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click on Combo-Fix.exe & follow the prompts. Vista users Right-Click on Combo-Fix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) Do not mouse-click ComboFix's window while it is running. That may cause it to stall. When the scan completes it will open a text window. Post the contents of that log in your next reply. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.Here is my Combo Fix report: ComboFix 09-06-06.01 - Lisa Read 06/06/2009 17:15.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.494.154 [GMT -7:00] Running from: c:\documents and settings\Lisa Read\Desktop\Combo-Fix.exe AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\cleanup.exe c:\docume~1\LISARE~1\LOCALS~1\Temp\IadHide5.dll c:\documents and settings\Lisa Read\Local Settings\Temp\IadHide5.dll c:\windows\system32\drivers\Msft_Kernel_nielprt_01007.Wdf c:\windows\system32\drivers\MsftWdf_Kernel_01007_Coinstaller_Critical.Wdf c:\windows\system32\rpcnet.dll c:\windows\system32\UACatargrve.dll c:\windows\system32\UACcsxooyan.dll c:\windows\system32\UACdldstpvg.dll c:\windows\system32\UACdvjaqjik.dat c:\windows\system32\uacinit.dll c:\windows\system32\UACjycdakxl.dll c:\windows\system32\UACleamfjer.log c:\windows\system32\UAClymdnowq.dll c:\windows\system32\UACnmaumxme.db c:\windows\system32\UACwwjrxydj.dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_UACd.sys ((((((((((((((((((((((((( Files Created from 2009-05-07 to 2009-06-07 ))))))))))))))))))))))))))))))) . 2009-06-05 16:34 . 2009-06-05 16:34--------d-sh--w-c:\windows\system32\config\systemprofile\IETldCache 2009-06-05 16:29 . 2009-06-05 16:29--------d-sh--w-c:\documents and settings\Lisa Read\IETldCache 2009-06-05 06:48 . 2009-06-05 06:48--------d-----w-c:\program files\Trend Micro 2009-06-05 06:22 . 2009-06-05 06:22--------d-----w-c:\program files\CCleaner 2009-06-05 06:02 . 2009-06-05 06:02574----a-w-C:\cleanup.bat 2009-06-05 06:02 . 2009-06-05 06:02135168----a-w-C:\zip.exe 2009-06-05 05:42 . 2009-06-05 05:42--------d-----w-c:\documents and settings\All Users\Application Data\Prevx 2009-06-05 05:39 . 2009-06-05 05:39--------d-----w-c:\documents and settings\Lisa Read\Application Data\PrevxCSI 2009-06-05 05:22 . 2009-06-05 06:07--------d-----w-c:\program files\Prevx 2009-06-05 05:22 . 2009-06-05 06:07--------d-----w-c:\documents and settings\All Users\Application Data\PrevxCSI 2009-06-04 06:34 . 2009-06-04 06:34--------d-----w-c:\windows\ie8updates 2009-06-04 06:33 . 2009-05-12 05:11102912-c----w-c:\windows\system32\dllcache\iecompat.dll 2009-06-04 06:29 . 2009-06-04 06:33--------dc-H--w-c:\windows\ie8 2009-06-04 06:15 . 2009-06-04 06:15152576----a-w-c:\documents and settings\Lisa Read\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-03 21:20 . 2006-02-07 15:35135168----a-w-c:\windows\system32\igfxres.dll 2009-06-03 19:36 . 2006-02-07 15:5661440----a-w-c:\windows\system32\iAlmCoIn_v4497.dll 2009-06-03 19:31 . 2009-06-03 19:31--------d-----w-c:\program files\SystemRequirementsLab 2009-05-22 01:31 . 2009-05-22 01:3113160----a-w-c:\windows\system32\Upgrd.exe 2009-05-20 23:09 . 2008-03-21 20:5714640------w-c:\windows\system32\spmsgXP_2k3.dll 2009-05-20 23:08 . 2008-12-16 20:441112288----a-w-c:\windows\system32\WdfCoInstaller01007.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-07 00:23 . 2006-07-19 16:2217408----a-w-c:\windows\system32\rpcnetp.exe 2009-06-05 08:27 . 2009-01-14 22:29296608----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-06-05 06:17 . 2006-07-20 01:33--------d--h--w-c:\program files\InstallShield Installation Information 2009-06-05 06:06 . 2009-04-28 18:41--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-06-05 06:00 . 2006-09-05 17:41--------d-----w-c:\documents and settings\All Users\Application Data\Viewpoint 2009-06-04 06:26 . 2009-04-03 23:0550688------w-c:\windows\system32\drivers\UACqmtorsbk.sys 2009-05-22 01:31 . 2008-07-10 02:0856680----a-w-c:\windows\system32\rpcnet.exe 2009-05-12 06:29 . 2006-09-06 18:34--------d-----w-c:\program files\Dl_cats 2009-05-11 04:45 . 2009-04-10 20:46--------d-----w-c:\documents and settings\Lisa Read\Application Data\TeraCopy 2009-05-07 08:03 . 2009-05-07 03:32--------d-----w-c:\documents and settings\Lisa Read\Application Data\TeamViewer 2009-05-07 03:32 . 2009-05-07 03:32--------d-----w-c:\program files\TeamViewer 2009-05-07 03:25 . 2009-05-07 03:23--------d-----w-c:\program files\CrossLoop 2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr 2009-05-01 00:13 . 2008-01-06 20:5253120-c-ha-w-c:\windows\system32\mlfcache.dat 2009-04-10 21:59 . 2009-04-10 21:59--------d-----w-c:\program files\Seagate 2009-04-10 21:38 . 2009-04-10 21:38--------d-----w-c:\documents and settings\All Users\Application Data\Seagate 2009-04-03 00:23 . 2006-08-08 05:348854----a-r-c:\documents and settings\Lisa Read\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\Uninstall_WD_Diagnos_0AB76F69E7614CFAB9B0A1906B4E9E4B.exe 2009-04-03 00:23 . 2006-08-08 05:3440960----a-r-c:\documents and settings\Lisa Read\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\WinDlg.exe_0AB76F69E7614CFAB9B0A1906B4E9E4B_3.exe 2009-04-03 00:23 . 2006-08-08 05:3410134----a-r-c:\documents and settings\Lisa Read\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\ARPPRODUCTICON.exe 2009-03-25 22:55 . 2008-01-22 01:4333280----a-w-c:\windows\system32\identprv.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector" [X] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "Google Update"="c:\documents and settings\Lisa Read\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-04 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-10 69632] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-09-30 104128] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-02 185632] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-02 289576] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-12 144792] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-05 160800] "VX6000"="c:\windows\vVX6000.exe" [2008-08-05 713744] "MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-10-28 181544] "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-23 39264] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-6-14 180224] KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\BitTorrent_DNA\\dna.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Documents and Settings\\Lisa Read\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Lisa Read\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"= R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [10/28/2008 4:42 PM 156968] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 4:29 PM 101936] S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?] S2 Viewpoint Manager Service;Viewpoint Manager Service;"c:\program files\Viewpoint\Common\ViewpointService.exe" --> c:\program files\Viewpoint\Common\ViewpointService.exe [?] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464] S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [1/11/2009 5:32 PM 2077840] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34] 2009-06-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1580818891-1343024091-1004.job - c:\documents and settings\Lisa Read\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-04 20:29] 2009-06-07 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20] . - - - - ORPHANS REMOVED - - - - SafeBoot-procexp90.Sys . ------- Supplementary Scan ------- . uStart PAGE = hxxp://www.netflix.com/MemberHome IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Trusted Zone: arubanetworks.com\securelogin Trusted Zone: stumbleupon.com FF - ProfilePath - c:\documents and settings\Lisa Read\Application Data\Mozilla\Firefox\Profiles\fliel1x8.default\ FF - plugin: c:\documents and settings\Lisa Read\Application Data\Mozilla\Firefox\Profiles\fliel1x8.default\extensions\[emailprotected]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll FF - plugin: c:\documents and settings\Lisa Read\Application Data\Mozilla\plugins\npgoogletalk.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Millisecond Software\Inquisit 2.0 Mozilla Plugin\npInquisit_20610047.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-06 17:24 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run DLBTCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll,[emailprotected]?? scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(1284) c:\docume~1\LISARE~1\LOCALS~1\Temp\IadHide5.dll c:\program files\Adobe\Acrobat 7.0\ActiveX\PDFShell.dll c:\windows\system32\wmvcore.dll c:\windows\system32\WMASF.DLL c:\windows\system32\ieframe.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKEEPER.exe c:\program files\Common Files\Symantec Shared\ccSetMgr.exe c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\program files\Symantec AntiVirus\DefWatch.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Microsoft LifeCam\MSCamS32.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\windows\system32\rpcnet.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\windows\system32\wscntfy.exe c:\program files\Symantec AntiVirus\DoScan.exe c:\windows\system32\igfxsrvc.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-07 17:37 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-07 00:37 Pre-Run: 16,691,523,584 bytes free Post-Run: 16,614,338,560 bytes free 220--- E O F ---2009-06-05 02:38 Suspicious files to scan Please go to VirSCAN.org FREE on-line scan service (If more than one file needs scanned they must be done separately and logs posted for each one) 1. Copy and paste the following file path into the Suspicious files to scan box on the top of the page. Code: [Select]c:\windows\system32\Upgrd.exe2. At the upload site, click once inside the window next to Browse. 3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. 4. Click on the Upload button. This will perform a scan across multiple different virus scanning engines. Your file will possibly be entered into a queue which normally takes less than a minute to clear. [color="Red"]Important:[/color] Wait for all of the scanning engines to complete. 5. Once the Scan is completed SCROLL down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard. 6. Paste the contents of the Clipboard in your next reply. Note: If using FireFox you will need to copy the link in the address bar and post it back here instead. The Copy to Clipboard feature will not work.http://virscan.org/report/e8541b64f8b1bb1cbd8e955aa9dfd4d2.htmlAre you sure you scanned the right file? c:\windows\system32\Upgrd.exe It says File Name : 1.htmlSorry, here it is: VirSCAN.org Scanned Report : Scanned time : 2009/06/06 23:41:38 (PDT) Scanner results: All Scanners reported not find malware! File Name : Upgrd.exe File Size : 13160 byte File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit MD5 : da67fca724b077642b4a05ae5c954cc3 SHA1 : 25dd176cc9676d133d26fa3ac975ea722c12142 4 Online report : http://virscan.org/report/66c9bd36bb6457c6e41b74697466118f.html Scanner Engine Ver Sig Ver Sig Date Time Scan result a-squared 4.5.0.1 20090606013111 2009-06-06 2.10 - AhnLab V3 2009.06.05.01 2009.06.05 2009-06-05 0.72 - AntiVir 8.2.0.180 7.1.4.65 2009-06-06 0.47 - Antiy 2.0.18 2.0.18. 0002-18-00 0.12 - Arcavir 2009 200906061305 2009-06-06 0.04 - Authentium 5.1.1 200906061841 2009-06-06 1.13 - AVAST! 4.7.4 090606-0 2009-06-06 0.00 - AVG 8.5.286 270.12.54/2159 2009-06-07 3.50 - BitDefender 7.81008.3346768 7.25847 2009-06-07 3.14 - CA (VET) 9.0.0.143 31.6.6541 2009-06-06 5.66 - ClamAV 0.95.1 9434 2009-06-06 0.01 - Comodo 3.9 1274 2009-06-06 0.71 - CP Secure 1.1.0.715 2009.06.03 2009-06-03 9.97 - Dr.Web 4.44.0.9170 2009.06.07 2009-06-07 4.73 - F-Prot 4.4.4.56 20090606 2009-06-06 1.14 - F-Secure 5.51.6100 2009.06.05.11 2009-06-05 0.07 - Fortinet 2.81-3.117 10.474 2009-06-06 0.21 - GData 19.5671/19.355 20090607 2009-06-07 4.18 - ViRobot 20090605 2009.06.05 2009-06-05 0.41 - Ikarus T3.1.01.57 2009.06.03.72814 2009-06-03 3.90 - JiangMin 11.0.706 2009.06.07 2009-06-07 2.03 - Kaspersky 5.5.10 2009.06.07 2009-06-07 0.05 - KingSoft 2009.2.5.15 2009.6.6.21 2009-06-06 0.64 - McAfee 5.3.00 5638 2009-06-06 3.05 - Microsoft 1.4701 2009.06.06 2009-06-06 4.59 - mks_vir 2.01 2009.06.05 2009-06-05 3.19 - Norman 6.01.05 6.01.00 2009-06-02 4.01 - Panda 9.05.01 2009.06.06 2009-06-06 1.78 - Trend Micro 8.700-1004 6.176.10 2009-06-06 0.03 - Quick Heal 10.00 2009.06.06 2009-06-06 1.21 - Rising 20.0 21.32.60.00 2009-06-07 0.85 - Sophos 2.87.1 4.42 2009-06-07 2.38 - Sunbelt 5173 5173 2009-06-06 0.82 - Symantec 1.3.0.24 20090606.003 2009-06-06 0.05 - nProtect 20090607.01 4203005 2009-06-07 5.39 - The Hacker 6.3.4.3 v00340 2009-06-04 0.57 - VBA32 3.12.10.6 20090606.1348 2009-06-06 1.96 - VirusBuster 4.5.11.10 10.107.4/1587341 2009-06-06 1.94 - http://virscan.org/report/66c9bd36bb6457c6e41b74697466118f.html Thank you. . You have Viewpoint installed. Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". More information: . It is suggested to remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.
----------
---------- Download ATF Cleaner by Atribune to your Desktop. Alternate download link Note: Vista users must use Run As Administrator
Note that your system will run slower for a reboot or two after having used this tool so don't panic. ---------- Use the Kaspersky Lab Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 and 8 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. If needed, this animation will guide you through the process.I wasn't able to find any of the Viewpoint programs in my Add/Remove programs...is there any other way to get rid of them? Also, I have been getting this new message that pops up every few minutes: Generic Host Process for Win32 Services has encountered a problem and needs to close. We are sorry of the inconvenience. Here's the requested report: -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Tuesday, June 9, 2009 Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Wednesday, June 10, 2009 01:00:12 Records in database: 2332781 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 53332 Threat name: 0 Infected objects: 0 Suspicious objects: 0 Duration of the scan: 02:42:51 No malware has been detected. The scan area is clean. The selected area was scanned. Download ViewpointKiller.zip
---------- Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it) When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixViewpoint Killer didn't find anything...Here is the Combofix report: ComboFix 09-06-11.04 - Lisa Read 06/11/2009 11:46.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.494.219 [GMT -7:00] Running from: c:\documents and settings\Lisa Read\Desktop\ComboFix.exe AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} * Created a new restore point WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\LISARE~1\LOCALS~1\Temp\IadHide5.dll c:\documents and settings\Lisa Read\Local Settings\temp\IadHide5.dll c:\windows\system32\rpcnet.dll . . . . failed to delete . ((((((((((((((((((((((((( Files Created from 2009-05-11 to 2009-06-11 ))))))))))))))))))))))))))))))) . 2009-06-11 18:54 . 2009-06-11 18:5456680----a-w-c:\windows\system32\rpcnet.dll 2009-06-09 22:07 . 2009-06-09 22:08--------d-s---w-C:\Combo-Fix 2009-06-07 06:42 . 2009-06-07 06:42--------d-sh--w-c:\documents and settings\Lisa Read\PrivacIE 2009-06-05 16:34 . 2009-06-05 16:34--------d-sh--w-c:\windows\system32\config\systemprofile\IETldCache 2009-06-05 16:29 . 2009-06-05 16:29--------d-sh--w-c:\documents and settings\Lisa Read\IETldCache 2009-06-05 06:48 . 2009-06-05 06:48--------d-----w-c:\program files\Trend Micro 2009-06-05 06:22 . 2009-06-05 06:22--------d-----w-c:\program files\CCleaner 2009-06-05 06:02 . 2009-06-05 06:02574----a-w-C:\cleanup.bat 2009-06-05 06:02 . 2009-06-05 06:02135168----a-w-C:\zip.exe 2009-06-05 05:42 . 2009-06-05 05:42--------d-----w-c:\documents and settings\All Users\Application Data\Prevx 2009-06-05 05:39 . 2009-06-05 05:47--------d-----w-c:\documents and settings\Lisa Read\Application Data\PrevxCSI 2009-06-05 05:22 . 2009-06-05 06:07--------d-----w-c:\program files\Prevx 2009-06-05 05:22 . 2009-06-05 06:07--------d-----w-c:\documents and settings\All Users\Application Data\PrevxCSI 2009-06-04 06:34 . 2009-06-04 06:34--------d-----w-c:\windows\ie8updates 2009-06-04 06:33 . 2009-05-12 05:11102912-c----w-c:\windows\system32\dllcache\iecompat.dll 2009-06-04 06:29 . 2009-06-04 06:33--------dc-h--w-c:\windows\ie8 2009-06-04 06:15 . 2009-06-04 06:15152576----a-w-c:\documents and settings\Lisa Read\Application Data\Sun\Java\jre1.6.0_13\lzma.dll 2009-06-03 21:20 . 2006-02-07 15:35135168----a-w-c:\windows\system32\igfxres.dll 2009-06-03 19:36 . 2006-02-07 15:5661440----a-w-c:\windows\system32\iAlmCoIn_v4497.dll 2009-06-03 19:31 . 2009-06-03 19:31--------d-----w-c:\program files\SystemRequirementsLab 2009-05-22 01:31 . 2009-05-22 01:3113160----a-w-c:\windows\system32\Upgrd.exe 2009-05-20 23:09 . 2008-03-21 20:5714640------w-c:\windows\system32\spmsgXP_2k3.dll 2009-05-20 23:08 . 2008-12-16 20:441112288----a-w-c:\windows\system32\WdfCoInstaller01007.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-06-11 18:54 . 2006-07-19 16:2217408----a-w-c:\windows\system32\rpcnetp.exe 2009-06-05 08:27 . 2009-01-14 22:29296608----a-w-c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat 2009-06-05 06:17 . 2006-07-20 01:33--------d--h--w-c:\program files\InstallShield Installation Information 2009-06-05 06:06 . 2009-04-28 18:41--------d-----w-c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-06-04 06:26 . 2009-04-03 23:0550688------w-c:\windows\system32\drivers\UACqmtorsbk.sys 2009-05-22 01:31 . 2008-07-10 02:0856680----a-w-c:\windows\system32\rpcnet.exe 2009-05-12 06:29 . 2006-09-06 18:34--------d-----w-c:\program files\Dl_cats 2009-05-11 04:45 . 2009-04-10 20:46--------d-----w-c:\documents and settings\Lisa Read\Application Data\TeraCopy 2009-05-07 08:03 . 2009-05-07 03:32--------d-----w-c:\documents and settings\Lisa Read\Application Data\TeamViewer 2009-05-07 03:32 . 2009-05-07 03:32--------d-----w-c:\program files\TeamViewer 2009-05-07 03:25 . 2009-05-07 03:23--------d-----w-c:\program files\CrossLoop 2009-05-01 18:30 . 2009-05-01 18:303366912----a-w-c:\windows\system32\GPhotos.scr 2009-05-01 00:13 . 2008-01-06 20:5253120-c-ha-w-c:\windows\system32\mlfcache.dat 2009-04-03 00:23 . 2006-08-08 05:348854----a-r-c:\documents and settings\Lisa Read\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\Uninstall_WD_Diagnos_0AB76F69E7614CFAB9B0A1906B4E9E4B.exe 2009-04-03 00:23 . 2006-08-08 05:3440960----a-r-c:\documents and settings\Lisa Read\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\WinDlg.exe_0AB76F69E7614CFAB9B0A1906B4E9E4B_3.exe 2009-04-03 00:23 . 2006-08-08 05:3410134----a-r-c:\documents and settings\Lisa Read\Application Data\Microsoft\Installer\{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}\ARPPRODUCTICON.exe 2009-03-25 22:55 . 2008-01-22 01:4333280----a-w-c:\windows\system32\identprv.dll 2009-03-25 01:33 . 2009-03-25 01:33237264----a-w-c:\documents and settings\Lisa Read\Application Data\Mozilla\plugins\npgoogletalk.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector" [X] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] "Google Update"="c:\documents and settings\Lisa Read\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2008-10-04 133104] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DLBTCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\DLBTtime.dll" [2004-11-10 69632] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-20 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "Symantec NetDriver Monitor"="c:\progra~1\SYMNET~1\SNDMon.exe" [2007-09-30 104128] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-12-02 185632] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-02 289576] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-10-12 144792] "LifeCam"="c:\program files\Microsoft LifeCam\LifeExp.exe" [2008-08-05 160800] "VX6000"="c:\windows\vVX6000.exe" [2008-08-05 713744] "MaxMenuMgr"="c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-10-28 181544] "igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208] "igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824] "igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-03-23 39264] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696] Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2006-6-14 180224] KODAK Software Updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-13 16423] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\BitTorrent_DNA\\dna.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\DNA\\btdna.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"= "c:\\Documents and Settings\\Lisa Read\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"= "c:\\Documents and Settings\\Lisa Read\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"= "c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"= "c:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"= R2 FreeAgentGoNext Service;Seagate Service;c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe [10/28/2008 4:42 PM 156968] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/27/2009 4:29 PM 101936] S0 nielprt;Nielsen Patch Service;c:\windows\system32\DRIVERS\nielprt.sys --> c:\windows\system32\DRIVERS\nielprt.sys [?] S3 NielGfx;Nielsen USB GFX;c:\windows\system32\drivers\nielgfx.sys --> c:\windows\system32\drivers\nielgfx.sys [?] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 8:33 PM 116464] S3 VX6000;Microsoft LifeCam VX-6000;c:\windows\system32\drivers\VX6000Xp.sys [1/11/2009 5:32 PM 2077840] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-06-04 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2007-08-29 19:34] 2009-06-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-1580818891-1343024091-1004.job - c:\documents and settings\Lisa Read\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-10-04 20:29] 2009-06-11 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.netflix.com/MemberHome IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 Trusted Zone: arubanetworks.com\securelogin Trusted Zone: stumbleupon.com FF - ProfilePath - . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-06-11 11:55 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'explorer.exe'(3656) c:\docume~1\LISARE~1\LOCALS~1\Temp\IadHide5.dll c:\windows\system32\ieframe.dll c:\windows\system32\OneX.DLL c:\windows\system32\eappprxy.dll c:\windows\system32\webcheck.dll c:\windows\system32\WPDShServiceObj.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Intel\Wireless\Bin\WLKEEPER.exe c:\program files\Common Files\Symantec Shared\ccSetMgr.exe c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe c:\program files\Symantec AntiVirus\DefWatch.exe c:\program files\Java\jre6\bin\jqs.exe c:\program files\Microsoft LifeCam\MSCamS32.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\windows\system32\rpcnet.exe c:\program files\Symantec AntiVirus\Rtvscan.exe c:\windows\system32\CF11289.exe c:\windows\system32\igfxsrvc.exe c:\program files\iPod\bin\iPodService.exe . ************************************************************************** . Completion time: 2009-06-11 12:10 - machine was rebooted ComboFix-quarantined-files.txt 2009-06-11 19:09 ComboFix2.txt 2009-06-07 00:37 Pre-Run: 18,495,057,920 bytes free Post-Run: 18,611,720,192 bytes free 192--- E O F ---2009-06-11 18:18 If you already have Malwarebytes be sure to update it before running the scan! Download Malwarebytes' Anti-Malware (MBAM) Alternate MBAM download link
Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.Malwarebytes' Anti-Malware 1.37 Database version: 2263 Windows 5.1.2600 Service Pack 3 6/11/2009 12:33:17 PM mbam-log-2009-06-11 (12-33-17).txt Scan type: Quick Scan Objects scanned: 82363 Time elapsed: 4 minute(s), 22 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\drivers\UACqmtorsbk.sys (Trojan.Agent) -> Quarantined and deleted successfully. |
|
| 3626. |
Solve : Spyware/Virus Problems? |
|
Answer» Today I opened up my laptop to see an error message. There is a box in the corner that shows up and goes away that says "windows security alert - application cannot be executed. The file ( wuauclt.exe, or logonui.exe ) is infected. Do you want to activate your antivirus software now?" Then in the middle of the screen a box saying the same thing shows up with only a yes or no choice. I can't open up my task manager to CLOSE the process. I booted up in safe mode and ran my spy sweeper but it didn't find anything. I am running my windows defender right now hoping something comes up. Any help would be great!Please visit this webpage for instructions for downloading and running ComboFix:
Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. 3. Please visit this webpage for instructions for downloading and running SUPERAntiSpyware (SAS) to scan and remove malware from your computer: http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial Post the log from SUPERAntiSpyware when you've accomplished that. 4. Please run a free online scan with the ESET Online Scanner
5. Post the following in your next reply:
Malwarebytes' Anti-Malware 1.44 Database version: 3662 Windows 6.0.6001 Service Pack 1 Internet Explorer 7.0.6001.18000 1/30/2010 2:20:12 PM mbam-log-2010-01-30 (14-20-12).txt Scan type: Full Scan (C:\|) Objects scanned: 238944 Time elapsed: 1 hour(s), 46 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) and.... SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 01/30/2010 at 03:24 PM Application Version : 4.33.1000 Core Rules Database Version : 4541 Trace Rules Database Version: 2353 Scan type : Complete Scan Total Scan Time : 00:57:57 Memory items scanned : 659 Memory threats detected : 0 Registry items scanned : 6732 Registry threats detected : 0 File items scanned : 32399 File threats detected : 1 Adware.Tracking Cookie C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies\[emailprotected][1].txt To manually create a new RESTORE Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Results of screen317's Security Check version 0.99.1 Windows Vista Service Pack 1 (UAC is enabled) Out of date service pack!! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! Antivirus out of date! `````````````````````````````` Anti-malware/Other Utilities Check: Spy Sweeper SUPERAntiSpyware Free Edition Java(TM) SE Runtime Environment 6 Adobe Flash Player 10 Adobe Reader 8.1.2 Out of date Adobe Reader installed! `````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSASCui.exe `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` Please consider updating to Windows Vista Service Pack 2 (SP2). Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards. It is now available via Windows Update or as a standalone installation here. == Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Antivirus/Antispyware
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|
| 3627. |
Solve : Magic Jack vulnerabilities?? |
|
Answer» I didn't know which forum topic to pick so since my question pertains to security, her it is. 11. Advertisements Quote 19. AUTOMATIC Updates Also, it may be worth noting that they are not required to provide you with emergency phone services, such as the ability to call 911. They do provide this service, but they can stop doing so at any time. You are also not guaranteed to receive incoming calls. They will attempt to provide you with a phone number, but if they are unable to do so for any reason, you will only be able to make outgoing calls... Quote 3. Internet Communications Feature |
|
| 3628. |
Solve : Problems with opening up my programs? |
|
Answer» Malwarebytes' Anti-Malware 1.44
To remove all of the tools we used and the files and folders they created, please do the FOLLOWING: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Windows Vista Service Pack 1 (UAC is enabled) Out of date service pack!! `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! AVG Free 8.5 Antivirus up to date! `````````````````````````````` Anti-malware/Other Utilities Check: Java(TM) 6 Update 5 Out of date Java installed! Adobe Flash Player 10 Adobe Reader 9 `````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSASCui.exe `````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) `````````End of Log``````````` Please consider updating to Windows Vista Service Pack 2 (SP2). Windows Vista Service Pack 2 (SP2) contains all the updates released since SP1 plus support for new types of hardware and emerging hardware standards. It is now available via Windows Update or as a standalone installation here. ===== Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. == Please download the newest version of Java from Java.com. Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs. Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them. Once old versions are gone, please install the newest version. == Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good IDEA to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and BECOME less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
I already use Mozilla and have the Firewall.No more info. Alrighty, Thank you again for everything! You're welcome. |
|
| 3629. |
Solve : UACD.sys infection? |
|
Answer» 1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. |
|
| 3630. |
Solve : Spyware and malware help logs? |
|
Answer» SUPERAntiSpyware Scan Log |
|
| 3631. |
Solve : Internet redirection persists.? |
|
Answer» I went through all of the steps and still I am getting redirected. I downloaded and installed Firefox to see if IE was corrupted, but the redirection happens on Firefox also. The computer also seems to run slow, and I hear a lot of hard disk activity. Here are my logs. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = 2) Malwarebyte Antimalware is already installed in your system.Perform a full scan with it as follows.Make sure it is updated before performing a scan. * Open Malwarebyte Antimalware.Under the "Scanner" tab, select "Perform Full Scan" and click "Scan".In the dialog box place a tick mark next to all your local drives (Earlier you scanned only C drive.Malware can reside in other drives as well.) * Now click "Start Scan". * The scan may take some time to finish,so please be patient. * When the scan is complete, click OK, then Show Results to view the results. * Make sure that everything is checked, and click Remove Selected. * When disinfection is completed, a log will open in NOTEPAD and you may be prompted to Restart.(See Extra Note) * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. * Copy&Paste the entire report in your next reply. PLEASE NOTE: If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. 3) Next download RootRepeal.rar and unzip it to your Desktop. You'll need WinRAR to extract it * Double click RootRepeal.exe to start the program * Click on the Report tab at the bottom of the program window * Click the Scan button * In the Select Scan dialog, check: o Drivers o Files o Processes o SSDT o Stealth Objects o Hidden SERVICES * Click the OK button * In the next dialog, select all drives showing * Click OK to start the scan The scan can take some time. DO NOT run any other programs while the scan is RUNNING * When the scan is complete, the Save Report button will become available * Click this and save the report to your Desktop as RootRepeal.txt * Go to File, then Exit to close the program *Attach this log in your next post. 4) Download[ DDS by sUBs to your desktop. Your antivirus software might question the file. If it does, allow it. * Double click DDS.scr to run it and wait for the scan to finish * When finished DDS.txt will open * A small while later, a prompt will open. Answer Yes * DDS will continue scanning * When done, Attach.txt will open Copy and paste the DDS.txt and attach Attach.txt |
|
| 3632. |
Solve : spyware and whatnot problems? |
| Answer» IM GOING through the steps on the malware help forum and in running ccleaner it says to keep any cookies that I want... are there any that I should definitely keep?If you delete all the cookies, you will have to sign in to any forum (such as this one) that are currently signed into. Keep the cookies for those forum/sites where you have to log in. Cookies just let you CONNECT to sites more QUICKLY. | |
| 3633. |
Solve : where can i get good firewall?? |
|
Answer» i m using win xp 2,i need GOOD firewall can someone tell me where can i get firewall from any sharing site,i m using nod32 V4 it doesn't has firewall thanks.I assume you are not using a router?A good software firewall is Online Armor. There are free version and paid versions. |
|
| 3634. |
Solve : Help much appreciated - virus/malware issues? |
|
Answer» Hi anyone willing to help, |
|
| 3635. |
Solve : INTERNET EXPLORER AND APPS HANG, RUNNING SUPER SLOW, TRIED EVERYTHING? |
|
Answer» I’ve spent hours and hours trying everything I can think of from defragging to deleting temp Internet files to deleting browser add-ons, uninstalling unneeded programs, running anti-virus, anti-spy, anti-mal countless times, and on and on but my pc is STILL running SUPER SLOW- applications hang constantly, especially Internet Explorer 8 – I get "Not RESPONDING" dozens of times per session – many times I can’t close web sites that are "Not Responding", not even with Task Manager – When I’m online, Task Manager always shows there are TWO Internet Explorer processes running, one using around 70, - 95, kb and the other using around 10, - 14, kb. Symptoms seem to get worse at night after being on the Internet for a while. |
|
| 3637. |
Solve : Advice for viruses (logs attached)? |
|
Answer» Hi, |
|
| 3638. |
Solve : Advice for viruses (logs attached) part 2? |
|
Answer» MBAM LOG: |
|
| 3639. |
Solve : ThreatFire causes Skype to close on its own? |
|
Answer» HI ! Starting yesterday, the Skype on my PC will close automatically after running for a few minutes. I've TRIED to reinstall it and run a virus SCAN but it didn't HELP. Finally, I found a post on the Skype forum which SUGGESTS that ThreatFire is the culprit for the issue. And it is true. Problem solved after uninstalling ThreatFire. Is this a known issue between the two programs?Seems to be confirmed by multiple users at the ThreatFire forum. http://www.pctools.com/forum/showthread.php?t=62659&highlight=skype |
|
| 3640. |
Solve : Trojan problems? |
|
Answer» Hello SD, |
|
| 3641. |
Solve : Cannot install windows security updates.? |
|
Answer» Try this. How to reset Internet Explorer settings http://support.microsoft.com/kb/923737Hi. reset internet explorer as Microsoft bulletin, twice and rebooted between each one, tried to install SP3 and still getting the same installation failed message.
Is the problem fixed?Hi Results from MGA scan attached, no threats / faults found on dial a fix, still getting SP3 installation cancelled after rebooting PC, Thanks for your help so far Gary [Saving space, attachment deleted by admin]Hi just doing a bit of web surfing and came across this site with a repair for windows update do you think it is WORTH trying? link attached, http://windowssecrets.com/2007/09/27/03-Stealth-Windows-update-prevents-XP-repair thanks GaryYes that link is worth a try. If that doesn't work try starting a new topic in the Computer Help forum so others will reply with some new ideas. I'm SORT of out of suggestions.OK that link makes no difference , thanks for your help so far, i will raise a new topic and see what can be done. Thanks Gary |
|
| 3642. |
Solve : F8 doesn't work? |
|
Answer» OK then, but how do you start the recovery console on XP? |
|
| 3643. |
Solve : MSE Antivirus question? |
|
Answer» Hai I would suggest that you buy for a license one like Malwarebytes' Anti-Malware full version or SUPERAntiSpyware Professional. Great recommendations but these are antimalware, not antivirus, so do not OFFER as much protection. I'm running MSE on my main COMPUTER and have not had any issues with it. Also, it's not open source. Quote Where another party says it does not work as good as other paid softwares ... like kaspersky or mcafee. There is a long standing debate over this. In the end you go with what works best for you. I can however personally say that I have never seen a paid antivirus out perform a free one. |
|
| 3644. |
Solve : adware/trojan help? |
|
Answer» This is what I found |
|
| 3645. |
Solve : six point star plz help? |
|
Answer» Ok, so I logged onto my computer today, and was working like normally other than it TOOK a minute to load up. Then about 30 seconds later once everything in the taskbar loaded (including a white six point star) the COMP froze. Nothing is accessible unless it is ALREADY opened before the OS finished loading. Any help would be amazing. .... ok so I figured it out!!!! It is aparently a program that is downloaded from a survey company called Premier Opinion. I dont know why it locked up my computer, but here is what I did. I opened the comp in safe mode. Went to my taskbar manager to see what it might have been. Well it is there and it is labeled Premier Opinion, and it sure enough has that little white star. Either way, while in safe mode, I opened up the control panel, then opened the Programs and Features tab.... Then FOUND it in that, uninstalled it, and restarted the computer.... Amazingly it worked!!! So if you have a Six Point White Star in your Taskbar, this is how you need to fix it..... Thanks for anyone who tried to help!!Thanks so much http://www.mywot.com/en/scorecard/premieropinion.com - Malicious content, viruses |
|
| 3646. |
Solve : computer screen keeps flashing whilst on net? |
|
Answer» Hi totally new to computers so its all confusing, when i started my LAPTOP it came up on the screen, Arcade deluxe agent .exe not working, and DDRAW.D11 cannot be found, sais to uninstall may help have found how to do this but have not tried it yet, screen only flashing whilst on NET ie yahoo home page or ebay, is this a virus, have the NORTON 360 and sais all ok? if i uninstall how do i reinstall if this will fix it? its an acer laptop |
|
| 3647. |
Solve : Search Engine Redirection? |
|
Answer» Hi, I am having a PROBLEM with my search engine results being redirected. Sometimes the link will take me to an alternate site; sometimes IE just crashes. My log files are attached. Any help would be much appreciated. |
|
| 3648. |
Solve : Trojan.Vundo? Please Help!? |
|
Answer» Here are the logs. By the way, did ComboFix take away 0.2 GB off my hard drive? look at the bottom of the log it says the bytes free it changed :O? By the way, did ComboFix take away 0.2 GB off my hard drive? look at the bottom of the log it says the bytes free it changed :O?robles56, not to worry. We're going to remove it later. Let's run this scan FIRST: ESET Online Scan Scan your computer with the ESET FREE Online Virus Scan * CLICK the ESET Online Scanner button. * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop * Double click on the esetsmartinstaller_enu.exe icon on your desktop. * Place a check mark next to YES, I accept the Terms of Use. * Click the Start button. * Accept any security warnings from your browser. * Leave the check mark next to Remove found threats and place a check next to Scan archives. * Click the Start button. * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time. * When the scan completes, click List of found threats. * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply. * Click the <<Back button then click Finish. In your next reply please include the ESET Online Scan Log I tried what you said but produced no log. It said I had no infections at all. I just left the window minimized and did my homework. When I came back, I saw that the scan was finished. The screen shot of the finished scan is attached. Sorry but no log came out. [Saving space, attachment deleted by admin]Looks good. How's your computer running now?Normal like usual, except that I'm worried about my free space. Sometimes there is 28 GB free and sometimes 32 and I think one time 40 GB free on my C: drive. I never installed anything EVER since September but my space still changes. Now i have 31.8 GB of space free. It's creepy. By the way, how do i remove ComboFix?Quote Normal like usual, except that I'm worried about my free space. Sometimes there is 28 GB free and sometimes 32 and I think one time 40 GB free on my C: drive. I never installed anything ever since September but my space still changes. Now i have 31.8 GB of space free. It's creepy. By the way, how do i remove ComboFix?Every time you go on the internet, files get loaded on your computer. Do you do a regular cleanup? * Click START then RUN - Vista users press the Windows Key and the R keys for the Run box. * Now type Combofix /uninstall in the runbox * Make sure there's a space between Combofix and /Uninstall * Then hit Enter * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. Note: The above may not work at the moment because ComboFix has been taken off-line for Maintenance. I'll let you know when it's up and running. Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to PREVENT spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smooth.thanks for the help thank you superdave so much! You just saved my computer! |
|
| 3649. |
Solve : Malware badness? |
|
Answer» My computer has been hit by some malware. I have gone through the steps in your recommendation, except for the MalwareBytes thing. When I install that, it tries to find mbam.exe to start, but there is no such animal. There's an mbamgui.exe, but double-clicking that does nothing, nor does renaming it to mbam.exe or mbam.*. The other THINGS have installed and run, but I can't get a log file out of SAS because the log file won't open. I did get a log file out of HJT, which is attached. |
|
| 3650. |
Solve : Windows Firewall???? |
|
Answer» Everytime I turn on my computer Windows Firewall says it is turned off. I have TRIED to reset the settings to what windows has it on and it still won't stay on. What is the solution to this? Thanks. Malware has the nasty habit of turning off the firewall and protective programs. Won't don't you go to this link and follow the directions and post the necessary logs. We will analyze them and tell you if your computer is clean or not. That is a good suggestion and thank you for it. Are there any other options for a solution?The FIRST thing we need to determine whether or not the problem is causes by an infection. If it is not, then we can look for other solutions. |
|