InterviewSolution
This section includes InterviewSolutions, each offering curated multiple-choice questions to sharpen your knowledge and support exam preparation. Choose a topic below to get started.
| 101. |
Solve : West Yorkshire Police Virus? |
|
Answer» Hi!
System Restore Windows Complete PC Restore Windows Memory Diagnostic Tool Command Prompt [/list]
Logs on my flash drive are as follows; Scan result of Farbar Recovery Scan Tool (FRST written by Farbar) Version: 29-08-2012 03 Ran by SYSTEM at 29-08-2012 20:27:12 Running from E:\ Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: English(US) The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [ISTray] "C:\Program FILES\Spyware Doctor\pctsTray.exe" [1243088 2009-11-18] (PC Tools) HKLM\...\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter HKLM\...\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [30040 2009-02-26] (Microsoft Corporation) HKLM\...\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe [2339168 2012-01-17] (AVG Technologies CZ, s.r.o.) HKLM\...\Run: [DivXUpdate] "C:\Program Files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW [1259376 2011-07-28] () HKLM\...\Run: [Anvi Smart Defender] C:\Program Files\Anvisoft\Anvi Smart Defender\ASDTray.exe [1229104 2012-08-23] (Anvisoft) HKLM\...\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray [462920 2012-07-03] (Malwarebytes Corporation) HKU\Default\...\RunOnce: [BurnImage] regsvr32 /s c:\windows\IMAPIShellExt.dll [720896 2008-08-28] (Dell Inc) HKU\Default User\...\RunOnce: [BurnImage] regsvr32 /s c:\windows\IMAPIShellExt.dll [720896 2008-08-28] (Dell Inc) HKU\Gemma\...\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background [4280184 2012-03-08] (Microsoft Corporation) HKU\Gemma\...\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe [125952 2008-01-20] (Microsoft Corporation) HKU\Gemma\...\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe [8704 2006-11-02] (Microsoft Corporation) HKU\Gemma\...\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /minimized /regrun [17418928 2012-07-13] (Skype Technologies S.A.) HKU\Gemma\...\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-20] (Microsoft Corporation) HKU\Gemma\...\Run: [WindowsCodecsExt] C:\Users\Gemma\AppData\Local\Microsoft\Windows\228\WindowsCodecsExt.exe [75264 2012-08-27] () Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\570\G2AWinLogon.dll [X] Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Startup: C:\Users\Default\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) ========================== Services (Whitelisted) ======================== 2 asdsrv; C:\Program Files\Anvisoft\Anvi Smart Defender\ASDSrv.exe [686896 2012-08-23] (Anvisoft) 2 AVGIDSAgent; "C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe" [7391072 2012-01-31] (AVG Technologies CZ, s.r.o.) 2 avgwd; "C:\Program Files\AVG\AVG10\avgwdsvc.exe" [269520 2011-02-07] (AVG Technologies CZ, s.r.o.) 2 Browser Defender Update Service; "C:\Program Files\Spyware Doctor\BDT\BDTUpdateService.exe" [112592 2010-01-21] (Threat Expert Ltd.) 2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [161048 2008-04-28] (Stardock Corporation) 2 MBAMService; "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe" [655944 2012-07-03] (Malwarebytes Corporation) 3 McComponentHostService; "C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe" [227232 2010-01-15] (McAfee, Inc.) 2 sdAuxService; C:\Program Files\Spyware Doctor\pctsAuxs.exe [359624 2009-10-30] (PC Tools) 2 sdCoreService; C:\Program Files\Spyware Doctor\pctsSvc.exe [1141712 2009-11-06] (PC Tools) 2 sprtsvc_dellsupportcenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service /p dellsupportcenter ==================== Drivers (Whitelisted) =================== 3 alcan5wn; C:\Windows\System32\DRIVERS\alcan5wn.sys [53600 2003-12-08] (THOMSON) 3 alcaudsl; C:\Windows\System32\DRIVERS\alcaudsl.sys [70688 2003-12-08] (THOMSON) 1 asdrm; C:\Windows\System32\DRIVERS\asdrm.sys [16208 2012-08-20] (Anvisoft) 2 asdrs; \??\C:\Windows\system32\DRIVERS\asdrs.sys [22864 2012-08-20] (Anvisoft) 2 asdws; \??\C:\Windows\system32\DRIVERS\asdws.sys [14160 2012-08-20] () 3 AVGIDSDriver; C:\Windows\System32\DRIVERS\AVGIDSDriver.Sys [134480 2011-05-27] (AVG Technologies CZ, s.r.o. ) 0 AVGIDSEH; C:\Windows\System32\DRIVERS\AVGIDSEH.Sys [22992 2011-02-21] (AVG Technologies CZ, s.r.o. ) 3 AVGIDSFilter; C:\Windows\System32\DRIVERS\AVGIDSFilter.Sys [24144 2011-02-09] (AVG Technologies CZ, s.r.o. ) 3 AVGIDSShim; C:\Windows\System32\DRIVERS\AVGIDSShim.Sys [28624 2011-02-09] (AVG Technologies CZ, s.r.o. ) 1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [248656 2011-01-06] (AVG Technologies CZ, s.r.o.) 1 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [34896 2011-03-01] (AVG Technologies CZ, s.r.o.) 0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [32592 2011-03-16] (AVG Technologies CZ, s.r.o.) 1 Avgtdix; C:\Windows\System32\DRIVERS\avgtdix.sys [297168 2011-04-04] (AVG Technologies CZ, s.r.o.) 3 MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [22344 2012-07-03] (Malwarebytes Corporation) 0 PCTCore; C:\Windows\System32\drivers\PCTCore.sys [207792 2009-11-09] (PC Tools) 3 s1018bus; C:\Windows\System32\DRIVERS\s1018bus.sys [86824 2009-03-25] (MCCI Corporation) 3 s1018mdfl; C:\Windows\System32\DRIVERS\s1018mdfl.sys [15016 2009-03-25] (MCCI Corporation) 3 s1018mdm; C:\Windows\System32\DRIVERS\s1018mdm.sys [114728 2009-03-25] (MCCI Corporation) 3 s1018mgmt; C:\Windows\System32\DRIVERS\s1018mgmt.sys [106208 2009-03-25] (MCCI Corporation) 3 s1018nd5; C:\Windows\System32\DRIVERS\s1018nd5.sys [26024 2009-03-25] (MCCI Corporation) 3 s1018obex; C:\Windows\System32\DRIVERS\s1018obex.sys [104744 2009-03-25] (MCCI Corporation) 3 s1018unic; C:\Windows\System32\DRIVERS\s1018unic.sys [109864 2009-03-25] (MCCI Corporation) 3 BCM42RLY; C:\Windows\System32\drivers\BCM42RLY.sys 3 IpInIp; C:\Windows\System32\DRIVERS\ipinip.sys 3 MREMPR5; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS 3 MRENDIS5; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS 3 NwlnkFlt; C:\Windows\System32\DRIVERS\nwlnkflt.sys 3 NwlnkFwd; C:\Windows\System32\DRIVERS\nwlnkfwd.sys 3 PCDSRVC{E9D79540-57D5953E-06020101}_0; \??\c:\program files\dell support center\pcdsrvc.pkms 3 SymIMMP; C:\Windows\System32\DRIVERS\SymIM.sys ==================== NetSvcs (Whitelisted) ================= ============ One Month Created Files and Folders ============== 2012-08-29 20:26 - 2012-08-29 20:26 - 00000000 ____D C:\FRST 2012-08-28 15:09 - 2012-08-28 15:10 - 00000000 ____D C:\Users\Gemma\AppData\Roaming\hellomoto 2012-08-28 11:42 - 2012-08-28 11:42 - 06954184 ____A C:\Users\Gemma\Downloads\spybotsd_includes.exe 2012-08-28 11:17 - 2012-08-28 11:17 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-08-28 11:15 - 2012-08-28 11:15 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Gemma\Downloads\mbam-setup-1.62.0.1300.exe 2012-08-28 09:56 - 2012-08-28 10:25 - 00001458 ____A C:\Windows\System32\avgrep.txt 2012-08-28 07:11 - 2012-08-28 07:11 - 00000979 ____A C:\Users\Public\Desktop\Anvi Smart Defender.lnk 2012-08-28 07:11 - 2012-08-28 07:11 - 00000000 ____D C:\Users\Gemma\AppData\Roaming\Anvisoft 2012-08-28 07:11 - 2012-08-28 07:11 - 00000000 ____D C:\Users\All Users\Anvisoft 2012-08-28 07:11 - 2012-08-28 07:11 - 00000000 ____D C:\Program Files\Anvisoft 2012-08-28 07:11 - 2012-08-20 01:23 - 00022864 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrs.sys 2012-08-28 07:11 - 2012-08-20 01:23 - 00016208 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrm.sys 2012-08-28 07:11 - 2012-08-20 01:23 - 00014160 ____A C:\Windows\System32\Drivers\asdws.sys 2012-08-28 07:08 - 2012-08-28 07:08 - 16680192 ____A C:\Users\Gemma\Downloads\asdsetup_16.exe 2012-08-28 07:01 - 2012-08-28 07:01 - 02002944 ____A (Trend Micro Inc.) C:\Users\Gemma\Downloads\HousecallLauncher(9).exe 2012-08-28 01:18 - 2012-08-28 01:19 - 00000000 ____D C:\Users\Gemma\AppData\Local\{94447B95-2C31-450D-9891-0A31668D3720} 2012-08-18 13:55 - 2012-08-18 13:56 - 00000000 ____D C:\Users\Gemma\AppData\Local\{D06149FA-5C31-4A05-99A9-E589DEF82FF1} 2012-08-18 13:55 - 2012-08-18 13:55 - 00000000 ____D C:\Users\Gemma\AppData\Local\{A6A552F1-E76C-45AB-858C-F45E67BE5CC3} 2012-08-17 14:20 - 2012-08-17 14:20 - 00000000 ____D C:\Users\Gemma\AppData\Local\{91E5961A-2EC3-4DD7-99C6-0481718275CC} 2012-08-17 14:03 - 2012-06-28 16:04 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-08-17 14:03 - 2012-06-28 16:01 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-08-17 14:03 - 2012-06-28 16:01 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-08-17 14:03 - 2012-06-28 16:00 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-08-17 14:03 - 2012-06-28 15:57 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-08-17 14:02 - 2012-06-28 16:52 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-08-17 14:02 - 2012-06-28 16:27 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-08-17 14:02 - 2012-06-28 16:16 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-08-17 14:02 - 2012-06-28 16:09 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-08-17 14:02 - 2012-06-28 16:09 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-08-17 14:02 - 2012-06-28 16:08 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-08-17 14:02 - 2012-06-28 16:07 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-08-17 14:02 - 2012-06-28 16:06 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-08-17 14:02 - 2012-06-28 16:04 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-08-17 14:01 - 2012-07-04 06:02 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-08-15 11:49 - 2012-06-29 08:01 - 00467968 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll 2012-08-15 11:49 - 2012-05-11 07:57 - 00623616 ____A (Microsoft Corporation) C:\Windows\System32\localspl.dll ============ 3 Months Modified Files ======================== 2012-08-29 11:00 - 2006-11-02 02:33 - 00706628 ____A C:\Windows\System32\PerfStringBackup.INI 2012-08-29 10:59 - 2009-11-22 04:01 - 00001356 ____A C:\Users\Gemma\AppData\Local\d3d9caps.dat 2012-08-28 22:16 - 2012-06-22 13:02 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2012-08-28 22:16 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2012-08-28 22:16 - 2006-11-02 04:47 - 00003616 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2012-08-28 15:11 - 2008-08-26 11:04 - 01665058 ____A C:\Windows\WindowsUpdate.log 2012-08-28 15:06 - 2006-11-02 05:01 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2012-08-28 14:58 - 2006-11-02 05:01 - 00032536 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2012-08-28 11:42 - 2012-08-28 11:42 - 06954184 ____A C:\Users\Gemma\Downloads\spybotsd_includes.exe 2012-08-28 11:17 - 2012-08-28 11:17 - 00000908 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk 2012-08-28 11:15 - 2012-08-28 11:15 - 10652120 ____A (Malwarebytes Corporation ) C:\Users\Gemma\Downloads\mbam-setup-1.62.0.1300.exe 2012-08-28 10:25 - 2012-08-28 09:56 - 00001458 ____A C:\Windows\System32\avgrep.txt 2012-08-28 07:11 - 2012-08-28 07:11 - 00000979 ____A C:\Users\Public\Desktop\Anvi Smart Defender.lnk 2012-08-28 07:10 - 2012-02-17 12:27 - 00326277 ____A C:\Users\Gemma\AppData\Local\census.cache 2012-08-28 07:10 - 2012-02-17 11:37 - 00185002 ____A C:\Users\Gemma\AppData\Local\ars.cache 2012-08-28 07:08 - 2012-08-28 07:08 - 16680192 ____A C:\Users\Gemma\Downloads\asdsetup_16.exe 2012-08-28 07:01 - 2012-08-28 07:01 - 02002944 ____A (Trend Micro Inc.) C:\Users\Gemma\Downloads\HousecallLauncher(9).exe 2012-08-28 01:13 - 2008-01-20 18:47 - 00144932 ____A C:\Windows\PFRO.log 2012-08-27 16:02 - 2010-06-14 13:12 - 00000402 ___AH C:\Windows\Tasks\Norton Security Scan for Gemma.job 2012-08-24 15:34 - 2008-09-15 11:47 - 00091648 ____A C:\Users\Gemma\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2012-08-20 01:23 - 2012-08-28 07:11 - 00022864 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrs.sys 2012-08-20 01:23 - 2012-08-28 07:11 - 00016208 ____A (Anvisoft) C:\Windows\System32\Drivers\asdrm.sys 2012-08-20 01:23 - 2012-08-28 07:11 - 00014160 ____A C:\Windows\System32\Drivers\asdws.sys 2012-08-17 14:15 - 2006-11-02 04:47 - 00381896 ____A C:\Windows\System32\FNTCACHE.DAT 2012-08-17 14:04 - 2006-11-02 02:24 - 59884088 ____A (Microsoft Corporation) C:\Windows\System32\mrt.exe 2012-08-14 10:52 - 2012-06-22 13:02 - 00426184 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2012-08-14 10:52 - 2011-05-15 08:32 - 00070344 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2012-07-12 12:26 - 2006-11-02 02:23 - 00000219 ____A C:\Windows\win.ini 2012-07-07 09:48 - 2011-12-18 04:07 - 00013404 ____A C:\Users\Gemma\Desktop\Ebay.xlsx 2012-07-07 09:32 - 2012-07-07 09:32 - 00812368 ____A (PortableApps.com) C:\Users\Gemma\Downloads\SkypePortable_5.10.0.115_online.paf.exe 2012-07-07 09:22 - 2012-07-07 09:22 - 00946352 ____A (Skype Technologies S.A.) C:\Users\Gemma\Downloads\SkypeSetup(1).exe 2012-07-04 06:02 - 2012-08-17 14:01 - 02047488 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys 2012-07-03 04:46 - 2011-05-14 10:41 - 00022344 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2012-06-29 08:01 - 2012-08-15 11:49 - 00467968 ____A (Microsoft Corporation) C:\Windows\System32\netapi32.dll 2012-06-28 16:52 - 2012-08-17 14:02 - 12317184 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2012-06-28 16:27 - 2012-08-17 14:02 - 09737728 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2012-06-28 16:16 - 2012-08-17 14:02 - 01800704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2012-06-28 16:09 - 2012-08-17 14:02 - 01129472 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2012-06-28 16:09 - 2012-08-17 14:02 - 01103872 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2012-06-28 16:08 - 2012-08-17 14:02 - 01427968 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2012-06-28 16:07 - 2012-08-17 14:02 - 00231936 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2012-06-28 16:06 - 2012-08-17 14:02 - 00065024 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2012-06-28 16:04 - 2012-08-17 14:03 - 00142848 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2012-06-28 16:04 - 2012-08-17 14:02 - 00717824 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2012-06-28 16:01 - 2012-08-17 14:03 - 01793024 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2012-06-28 16:01 - 2012-08-17 14:03 - 00073216 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2012-06-28 16:00 - 2012-08-17 14:03 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2012-06-28 15:57 - 2012-08-17 14:03 - 00176640 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2012-06-15 10:09 - 2012-06-15 10:09 - 02002320 ____A (Trend Micro Inc.) C:\Users\Gemma\Downloads\HousecallLauncher(.exe 2012-06-08 09:47 - 2012-07-10 16:06 - 11586048 ____A (Microsoft Corporation) C:\Windows\System32\shell32.dll 2012-06-06 11:59 - 2012-06-06 11:59 - 01070152 ____A (Microsoft Corporation) C:\Windows\System32\MSCOMCTL.OCX 2012-06-05 08:47 - 2012-07-10 16:06 - 01401856 ____A (Microsoft Corporation) C:\Windows\System32\msxml6.dll 2012-06-05 08:47 - 2012-07-10 16:06 - 01248768 ____A (Microsoft Corporation) C:\Windows\System32\msxml3.dll 2012-06-04 07:26 - 2012-07-10 16:06 - 00440704 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys 2012-06-02 14:19 - 2012-06-21 11:34 - 01933848 ____A (Microsoft Corporation) C:\Windows\System32\wuaueng.dll 2012-06-02 14:19 - 2012-06-21 11:34 - 00577048 ____A (Microsoft Corporation) C:\Windows\System32\wuapi.dll 2012-06-02 14:19 - 2012-06-21 11:34 - 00053784 ____A (Microsoft Corporation) C:\Windows\System32\wuauclt.exe 2012-06-02 14:19 - 2012-06-21 11:34 - 00045080 ____A (Microsoft Corporation) C:\Windows\System32\wups2.dll 2012-06-02 14:19 - 2012-06-21 11:34 - 00035864 ____A (Microsoft Corporation) C:\Windows\System32\wups.dll 2012-06-02 14:12 - 2012-06-21 11:34 - 02422272 ____A (Microsoft Corporation) C:\Windows\System32\wucltux.dll 2012-06-02 14:12 - 2012-06-21 11:34 - 00088576 ____A (Microsoft Corporation) C:\Windows\System32\wudriver.dll 2012-06-02 06:19 - 2012-06-21 11:33 - 00171904 ____A (Microsoft Corporation) C:\Windows\System32\wuwebv.dll 2012-06-02 06:12 - 2012-06-21 11:33 - 00033792 ____A (Microsoft Corporation) C:\Windows\System32\wuapp.exe 2012-06-01 16:04 - 2012-07-10 16:06 - 00278528 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll 2012-06-01 16:03 - 2012-07-10 16:06 - 00204288 ____A (Microsoft Corporation) C:\Windows\System32\ncrypt.dll 2012-06-01 01:53 - 2006-11-02 04:52 - 00104975 ____A C:\Windows\setupact.log ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is LEGIT C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 2037.31 MB Available physical RAM: 1683.78 MB Total Pagefile: 1970.94 MB Available Pagefile: 1846.59 MB Total Virtual: 2047.88 MB Available Virtual: 1975.56 MB ==================== Partitions ============================ 1 Drive c: (OS) (Fixed) (Total:99.19 GB) (Free:59.52 GB) NTFS ==>[Drive with boot components (obtained from BCD)] 3 Drive e: () (Removable) (Total:0.94 GB) (Free:0.94 GB) FAT32 4 Drive x: (RECOVERY) (Fixed) (Total:10 GB) (Free:5.15 GB) NTFS Disk ### Status Size Free Dyn Gpt -------- ---------- ------- ------- --- --- Disk 0 Online 112 GB 0 B Disk 1 Online 965 MB 0 B Partitions of Disk 0: =============== Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 OEM 102 MB 32 KB Partition 2 Primary 10 GB 102 MB Partition 3 Primary 99 GB 10 GB Partition 0 Extended 2560 MB 109 GB Partition 4 Logical 2559 MB 109 GB ================================================================================== Disk: 0 Partition 1 Type : DE Hidden: Yes Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 FAT Partition 102 MB Healthy Hidden ================================================================================== Disk: 0 Partition 2 Type : 07 Hidden: No Active: No Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 1 X RECOVERY NTFS Partition 10 GB Healthy Boot ================================================================================== Disk: 0 Partition 3 Type : 07 Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 C OS NTFS Partition 99 GB Healthy ================================================================================== Disk: 0 Partition 4 Type : DD Hidden: Yes Active: No There is no volume associated with this partition. ================================================================================== Partitions of Disk 1: =============== Partition ### Type Size Offset ------------- ---------------- ------- ------- Partition 1 Primary 965 MB 16 KB ================================================================================== Disk: 1 Partition 1 Type : 0B Hidden: No Active: Yes Volume ### Ltr Label Fs Type Size Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 E FAT32 Removable 965 MB Healthy ================================================================================== Last Boot: 2012-08-28 15:13 ==================== End Of Log ============================= Where would I find the other data log? I've SEARCHED on the laptop and can't find it?That's okay. Let's go to Safe Mode with Networking... ComboFix Please download ComboFix by sUBs From BleepingComputer.com Please save the file to your Desktop, but rename it first to svchost.exe [SIZE=14]Important information about ComboFix[/SIZE] Before the download:
Safe Mode: If you still cannot get ComboFix to run, try booting into Safe Mode, and run it there. (To boot into Safe Mode, tap F8 after BIOS, and just before the Windows logo appears. A list of options will appear, select "Safe Mode.") Re-downloading: If this doesn't work either, try the same method (above method), but try to download it again, except name ComboFix.exe to iexplore.exe, explorer.exe, or winlogon.exe. Malware is known for blocking all "user" processes, except for its whitelist of system important processes such as iexplore.exe, explorer.exe, winlogon.exe. NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error. Hi and thanks again, I have the following ComboFix 12-08-30.05 - Gemma 31/08/2012 10:22:06.1.1 - x86 NETWORK Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2037.1433 [GMT 1:00] Running from: c:\users\Gemma\Desktop\svchost.exe.exe SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Created a new restore point . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64} c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\chrome.manifest c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\chrome\content\_cfg.js c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\chrome\content\overlay.xul c:\users\Gemma\AppData\Local\{42545D07-923E-4CDB-922B-2BB467D52D64}\install.rdf c:\users\Gemma\AppData\Local\qrly c:\users\Gemma\AppData\Roaming\6E3C.CA9 c:\users\Gemma\AppData\Roaming\Adobe\plugs c:\users\Gemma\AppData\Roaming\Adobe\shed . . ((((((((((((((((((((((((( Files Created from 2012-07-28 to 2012-08-31 ))))))))))))))))))))))))))))))) . . 2012-08-31 09:28 . 2012-08-31 09:28--------d-----w-c:\users\Default\AppData\Local\temp 2012-08-31 09:28 . 2012-08-31 09:28--------d-----w-c:\users\Gemma\AppData\Local\temp 2012-08-30 04:26 . 2012-08-30 04:26--------d-----w-C:\FRST 2012-08-28 23:09 . 2012-08-28 23:10--------d-----w-c:\users\Gemma\AppData\Roaming\hellomoto 2012-08-28 16:41 . 2012-08-28 16:41--------d-----w-C:\Temp 2012-08-28 15:11 . 2012-08-31 08:36--------d-----w-c:\users\Gemma\AppData\Roaming\Anvisoft 2012-08-28 15:11 . 2012-08-28 15:11--------d-----w-c:\programdata\Anvisoft 2012-08-28 15:11 . 2012-08-28 15:11--------d-----w-c:\program files\Anvisoft 2012-08-17 22:03 . 2012-06-29 01:00140920----a-w-c:\program files\Internet Explorer\sqmapi.dll 2012-08-17 22:03 . 2012-06-29 00:002382848----a-w-c:\windows\system32\mshtml.tlb 2012-08-17 22:03 . 2012-06-29 00:06194560----a-w-c:\program files\Internet Explorer\ieproxy.dll 2012-08-17 22:03 . 2012-06-29 00:06194048----a-w-c:\program files\Internet Explorer\IEShims.dll 2012-08-17 22:03 . 2012-06-29 00:04142848----a-w-c:\windows\system32\ieUnatt.exe 2012-08-17 22:02 . 2012-06-29 00:161800704----a-w-c:\windows\system32\jscript9.dll 2012-08-17 22:02 . 2012-06-29 00:091129472----a-w-c:\windows\system32\wininet.dll 2012-08-17 22:02 . 2012-06-29 01:00748664----a-w-c:\program files\Internet Explorer\iexplore.exe 2012-08-17 22:02 . 2012-06-29 00:10678912----a-w-c:\program files\Internet Explorer\iedvtool.dll 2012-08-17 22:02 . 2012-06-29 00:10387584----a-w-c:\program files\Internet Explorer\jsdbgui.dll 2012-08-17 22:02 . 2012-06-29 00:081427968----a-w-c:\windows\system32\inetcpl.cpl 2012-08-17 22:01 . 2012-07-04 14:022047488----a-w-c:\windows\system32\win32k.sys 2012-08-15 19:49 . 2012-05-11 15:57623616----a-w-c:\windows\system32\localspl.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-08-14 18:52 . 2012-06-22 21:02426184----a-w-c:\windows\system32\FlashPlayerApp.exe 2012-08-14 18:52 . 2011-05-15 16:3270344----a-w-c:\windows\system32\FlashPlayerCPLApp.cpl 2012-07-03 12:46 . 2011-05-14 18:4122344----a-w-c:\windows\system32\drivers\mbam.sys 2012-06-06 19:59 . 2012-06-06 19:591070152----a-w-c:\windows\system32\MSCOMCTL.OCX 2012-06-05 16:47 . 2012-07-11 00:061401856----a-w-c:\windows\system32\msxml6.dll 2012-06-05 16:47 . 2012-07-11 00:061248768----a-w-c:\windows\system32\msxml3.dll 2012-06-04 15:26 . 2012-07-11 00:06440704----a-w-c:\windows\system32\drivers\ksecdd.sys 2012-06-02 22:19 . 2012-06-21 19:3453784----a-w-c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-21 19:3445080----a-w-c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-21 19:3435864----a-w-c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-21 19:34577048----a-w-c:\windows\system32\wuapi.dll 2012-06-02 22:19 . 2012-06-21 19:341933848----a-w-c:\windows\system32\wuaueng.dll 2012-06-02 22:12 . 2012-06-21 19:342422272----a-w-c:\windows\system32\wucltux.dll 2012-06-02 22:12 . 2012-06-21 19:3488576----a-w-c:\windows\system32\wudriver.dll 2012-06-02 14:19 . 2012-06-21 19:33171904----a-w-c:\windows\system32\wuwebv.dll 2012-06-02 14:12 . 2012-06-21 19:3333792----a-w-c:\windows\system32\wuapp.exe 2012-07-18 20:15 . 2011-05-28 22:48136672----a-w-c:\program files\mozilla firefox\components\browsercomps.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952] "Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240] "WindowsCodecsExt"="c:\users\Gemma\AppData\Local\Microsoft\Windows\228\WindowsCodecsExt.exe" [2012-08-28 75264] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040] "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-07-28 1259376] "Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce] "AvgUninstallURL"="start http://www.avg.com/ww.special-uninstallation-feedback-appf?lic=NFVZOVgtTlNWVkwtTzRCWlEtUUlNQ0wtU VREQ0gtNElKTUg&inst=NzctNjI0MDU1MjQ0LVRUKzEtVDUtVUNBTEwrMS1TVDErMi1 GUDkyKzYtQkFSOU8rMS1GTCs5LVhPMzYrMS1GOU 0xMEErMi1GOU0yKzEtRkwxMCsxLVhPMTArMTEtT ElDKzItRERUKzU4ODg5LUREMTBGKzEtU1 QxMEZBUFArMS1GMTBNMTJUQSsxLVUxMCsxLVZJU DEyKzEtRjEwTTEyUisxLUYxME0xMlIyKzEtQ0lE MTArMS1DSUQrMTA∏=90&ver=10.0.1424" [?] . c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-5-13 1058088] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2010-10-13 18:0916680----a-w-c:\program files\Citrix\GoToAssist\570\g2awinlogon.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] @="Driver" . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Digital Line Detect.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Digital Line Detect.lnk backup=c:\windows\pss\Digital Line Detect.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk backup=c:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup backupExtension=.CommonStartup . [HKLM\~\startupfolder\C:^Users^Gemma^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dell Dock.lnk] path=c:\users\Gemma\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk backup=c:\windows\pss\Dell Dock.lnk.Startup backupExtension=.Startup . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2008-10-15 01:0439792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint] 2008-05-04 09:25167936----a-w-c:\program files\DellTPad\Apoint.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI] 2008-05-16 12:173444736----a-w-c:\windows\System32\WLTRAY.EXE . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\btbb_McciTrayApp] 2009-12-07 11:501584640----a-w-c:\program files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DACSMiniApp] 2007-07-24 11:20197888----a-w-c:\program files\Fisher-Price\DACS\MiniApp\DACSMiniApp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate] 2011-07-28 23:081259376----a-w-c:\program files\DivX\DivX Update\DivXUpdate.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ECenter] 2008-02-29 04:1817920----a-w-c:\dell\E-Center\EULALauncher.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe] 2008-01-21 02:25125952----a-w-c:\windows\ehome\ehtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2009-02-26 18:3630040----a-w-c:\program files\Microsoft Office\Office12\GrooveMonitor.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2008-03-06 07:58166424----a-w-c:\windows\System32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif] 2007-03-21 12:00174872----a-w-c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2008-03-06 07:58141848----a-w-c:\windows\System32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)] 2012-07-03 12:46973488----a-w-c:\program files\Malwarebytes' Anti-Malware\mbam.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr] 2012-03-08 17:504280184----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMService] 2007-12-21 09:58184320----a-w-c:\program files\Dell\MediaDirect\PCMService.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2008-03-06 07:58133656----a-w-c:\windows\System32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp] 2007-11-12 11:07405504----a-w-c:\program files\Sigmatel\C-Major Audio\WDM\sttray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] 2012-07-13 12:3317418928----a-r-c:\program files\Skype\Phone\Skype.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Companion] 2009-06-18 09:04772096----a-w-c:\program files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpeedTouch USB Diagnostics] 2004-01-26 10:38866816----a-w-c:\program files\Thomson\SpeedTouch USB\dragdiag.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] 2009-03-05 15:072260480--sha-r-c:\program files\Spybot - Search & Destroy\TeaTimer.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2010-05-14 10:44248552----a-w-c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe] 2010-05-20 22:40202256----a-w-c:\program files\Common Files\Real\Update_OB\realsched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomTomHOME.exe] 2009-11-13 11:31247144----a-w-c:\program files\TomTom HOME 2\TomTomHOMERunner.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender] 2008-01-21 02:231008184----a-w-c:\program files\Windows Defender\MSASCui.exe . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 . R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\aestsrv.exe R3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe . . --- Other Services/Drivers In Memory --- . *NewlyCreated* - ECACHE . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonationREG_MULTI_SZ FontCache . Contents of the 'Scheduled Tasks' folder . 2012-08-29 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-06-22 18:52] . 2012-08-28 c:\windows\Tasks\Norton Security Scan for Gemma.job - c:\progra~1\NORTON~2\Engine\301~1.8\Nss.exe [2011-01-26 01:45] . . ------- Supplementary Scan ------- . uStart Page = about:blank uSearchMigratedDefaultURL = hxxp://search.orange.co.uk/all?brand=ouk&tab=web&p=_adr&q={searchTerms} mWindow Title = Microsoft Internet Explorer Provided by Wanadoo uInternet Settings,ProxyOverride = uInternet Settings,ProxyServer = http=127.0.0.1:58343 IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.1.254 FF - ProfilePath - c:\users\Gemma\AppData\Roaming\Mozilla\Firefox\Profiles\75cd0c58.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxps://www.google.com/accounts/ServiceLogin?service=mail&passive=true&rm=false&continue=http%3A%2F%2Fmail.google.com%2Fmail%2F%3Fui%3Dhtml%26zy%3Dl&bsv=1eic6yu9oa4y3&scc=1<mpl=default<mplcache=2 FF - prefs.js: keyword.URL - hxxp://flvtubesearch.co/?prt=02ff&clid=&subid=&Keywords= FF - prefs.js: network.proxy.http - 127.0.0.1 FF - prefs.js: network.proxy.http_port - 58343 FF - prefs.js: network.proxy.type - 4 FF - user.js: network.cookie.cookieBehavior - 0 FF - user.js: privacy.clearOnShutdown.cookies - false FF - user.js: security.warn_viewing_mixed - false FF - user.js: security.warn_viewing_mixed.show_once - false FF - user.js: security.warn_submit_insecure - false FF - user.js: security.warn_submit_insecure.show_once - false . - - - - ORPHANS REMOVED - - - - . Toolbar-BigBitmap - (no file) Toolbar-SmallBitmap - (no file) HKLM-Run-dellsupportcenter - c:\program files\Dell Support Center\bin\sprtcmd.exe MSConfigStartUp-AVG9_TRAY - c:\progra~1\AVG\AVG9\avgtray.exe MSConfigStartUp-DellSupportCenter - c:\program files\Dell Support Center\bin\sprtcmd.exe MSConfigStartUp-dscactivate - c:\program files\Dell Support Center\gs_agent\custom\dsca.exe MSConfigStartUp-ISTray - c:\program files\Spyware Doctor\pctsTray.exe . . . ************************************************************************** . catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2012-08-31 10:28 Windows 6.0.6002 Service Pack 2 NTFS . scanning hidden processes ... . scanning hidden autostart entries ... . scanning hidden files ... . scan completed successfully hidden files: 0 . ************************************************************************** . [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\PCDSRVC{E9D79540-57D5953E-06020101}_0] "ImagePath"="\??\c:\program files\dell support center\pcdsrvc.pkms" . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2012-08-31 10:32:28 ComboFix-quarantined-files.txt 2012-08-31 09:32 . Pre-Run: 65,570,836,480 bytes free Post-Run: 66,023,469,056 bytes free . - - End Of File - - 3B5C74C0FDE1CAB09C16CC280DEE2D21 Please download aswMBR from here
Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives
aswMBR version 0.9.9.1665 COPYRIGHT(c) 2011 AVAST Software Run date: 2012-08-31 13:17:32 ----------------------------- 13:17:32.961 OS Version: Windows 6.0.6002 Service Pack 2 13:17:32.961 Number of processors: 1 586 0x1601 13:17:32.961 ComputerName: GEMMA-PC UserName: Gemma 13:17:50.433 Initialize success 13:18:08.717 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 13:18:08.717 Disk 0 Vendor: ST912081 3.AD Size: 114473MB BusType: 3 13:18:08.748 Disk 0 MBR read successfully 13:18:08.748 Disk 0 MBR scan 13:18:08.763 Disk 0 Windows VISTA default MBR code 13:18:08.779 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 101 MB offset 63 13:18:08.795 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 208896 13:18:08.810 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 101569 MB offset 21180416 13:18:08.810 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 229195776 13:18:08.888 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 229197824 13:18:08.919 Disk 0 scanning sectors +234438656 13:18:09.044 Disk 0 scanning C:\Windows\system32\drivers 13:18:16.220 Service scanning 13:18:38.591 Modules scanning 13:18:44.300 Disk 0 trace - called modules: 13:18:44.347 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 13:18:44.347 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8b02f878] 13:18:44.363 3 CLASSPNP.SYS[8d9a78b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x8a5c0030] 13:18:44.363 Scan finished successfully 13:41:27.849 Disk 0 MBR has been saved successfully to "C:\Users\Gemma\Desktop\MBR.dat" 13:41:27.865 The log file has been saved successfully to "C:\Users\Gemma\Desktop\aswMBR.txt" Thanks again, I appreciate your help!Excellent work! ESET Online Scan Please run a free online scan with the ESET Online Scanner
C:\Users\Gemma\AppData\Local\Microsoft\Windows\228\WindowsCodecsExt.exea variant of Win32/Kryptik.ALBD trojancleaned by deleting - quarantined C:\Users\Gemma\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\120217225646367.rsc_tmpmultiple threatsdeleted - quarantined C:\Users\Gemma\AppData\Roaming\AVG\Rescue\PC Tuneup 2011\120217231620925.rscmultiple threatsdeleted - quarantined C:\Users\Gemma\AppData\Roaming\B4414EE8A7520B62EDE608ED711EDA7A\enemies-names.txtWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined C:\Users\Gemma\AppData\Roaming\B4414EE8A7520B62EDE608ED711EDA7A\local.iniWin32/Adware.AntimalwareDoctor.AE.Gen applicationcleaned by deleting - quarantined C:\Users\Gemma\Downloads\BitZipper50TrialSetupEn.exea variant of Win32/InstallIQ applicationcleaned by deleting - quarantined C:\Users\Gemma\Downloads\BitZipperH2010.v8326484.TrialSetupEn.exea variant of Win32/InstallIQ applicationcleaned by deleting - quarantined ThanksAny more issues? We need to know any other issues that are plaguing your computer. Kindly give a summary so we know how to continue from here. Many of the things to note for us would be:
Is there a good free anti virus you can recommend? Thanks again!Let's clean up, then you will be able to see them. This is preventative measures to make sure you don't get infected again... Clean up System Restore Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back." To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
Purge old temporary files Download CCleaner Slim and save it to your Desktop - Alternate download link When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe Follow the prompts to install the program. * Double-click the CCleaner shortcut on the desktop to start the program. * Click on the Options block on the left, then choose Cookies. * Under Cookies to Delete, highlight any cookies you would like to retain permanently * Click the right arrow > to move them to the Cookies to Keep window. * Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours * Click Cleaner on the left then Run Cleaner on the right to run the program. * Important: Make sure that ALL browser windows are closed before selecting Run Cleaner Caution: Only use the Registry feature if you are very familiar with the registry. Always back up your registry before making any changes. Exit CCleaner after it has completed it's process. Security Check Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
|
|
| 102. |
Solve : FireFox hanging +? |
|
Answer» Firefox 15 is hanging and unresponsive. Tried re-installing etc. MB says it is clean and dds and adwcleaner say ok. IExplorer seems to be ok. Below is combo fix. R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-28 135664] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl64.sys [2010-04-19 22528] R3 netr28ux;Belkin N+ Wireless USB Adapter Driver;c:\windows\system32\DRIVERS\netr28ux.sys [2011-06-14 1061888] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688] R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696] R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4925184] R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe R3 sbhips;sbhips;c:\windows\system32\drivers\sbhips.sys [2011-12-19 60536] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-20 59392] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-04-25 52736] R3 VF0350Afx;VF0350 Audio FX;c:\windows\system32\Drivers\V0350Afx.sys [2007-06-11 214240] R3 VF0350Vfx;VF0350 Video FX;c:\windows\system32\DRIVERS\V0350VFx.sys [2007-03-05 12288] R3 VF0350Vid;Live! Cam Video IM (VF0350);c:\windows\system32\DRIVERS\V0350Vid.sys [2007-08-29 214976] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2011-06-14 1255736] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184] S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2008-06-16 55024] S1 SBRE;SBRE;c:\windows\system32\drivers\SBREdrv.sys [2011-10-26 57976] S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904] S2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-08 169312] S2 DragonSvc;Dragon Service;c:\program files (x86)\Common Files\Nuance\dgnsvc.exe [2012-07-18 310232] S2 EasyRedirect;EasyRedirect;c:\program files\Easy-Hide-IP\rdr\EasyRedirect.exe [2012-07-13 3542856] S2 OberonGameConsoleService;Oberon Media Game Console service;c:\program files (x86)\Packard Bell GameZone\GameConsole\OberonGameConsoleService.exe [2009-08-29 44312] S2 PDFProFiltSrvPP;PDFProFiltSrvPP;c:\program files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [2010-02-10 144672] S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys [2011-11-29 74872] S2 Updater Service;Updater Service;c:\program files\Packard Bell\Packard Bell Updater\UpdaterService.exe [2009-07-04 240160] S3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\DRIVERS\athrxusb.sys [2008-07-28 1075712] S3 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\7.1.361.0\SeaPort.exe [2012-02-10 240408] S3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda64v.sys [2009-08-21 84512] . . Contents of the 'Scheduled Tasks' folder . 2012-08-31 c:\windows\Tasks\0.job - c:\program files (x86)\internet explorer\iexplore.exe [2012-08-28 01:00] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1] @="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2] @="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3] @="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4] @="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}" [HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}] 2010-10-06 23:3697792----a-w-c:\users\Cesare\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "LoadAppInit_DLLs"=0x0 . ------- Supplementary Scan ------- . uStart Page = hxxp://www.bbc.co.uk/ uLocal Page = c:\windows\system32\blank.htm mStart Page = hxxp://homepage.packardbell.com/rdr.aspx?b=ACPW&l=0809&m=imedia_s3720&r=173606119306p03f5v1k5y4721031q mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: Free YouTube Download - c:\users\Cesare\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubedownload.htm IE: Free YouTube to MP3 Converter - c:\users\Cesare\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: OPEN with PDF Viewer Plus - c:\program files (x86)\Nuance\PDFViewerPlus\Bin\PlusIEContextMenu.dll/PlusIEContextMenu.htm IE: Se&nd to OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105 LSP: c:\windows\system32\EasyRedirect.dll TCP: DhcpNameServer = 192.168.1.1 FF - ProfilePath - c:\users\Cesare\AppData\Roaming\Mozilla\Firefox\Profiles\sdbtzu4f.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.bbc.co.uk/ FF - prefs.js: network.proxy.type - 0 . . ------- File Associations ------- . JSEFile=NOTEPAD.EXE %1 . - - - - ORPHANS REMOVED - - - - . Toolbar-Locked - (no file) Toolbar-Locked - (no file) . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}] @Denied: (A) (Everyone) "Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3] @Denied: (A) (Everyone) . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0] "Key"="ActionsPane3" "Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2012-09-01 13:20:52 ComboFix-quarantined-files.txt 2012-09-01 12:20 . Pre-Run: 36,748,992,512 bytes free Post-Run: 36,613,259,264 bytes free . - - End Of File - - 5FBC790BC3BB303F89368B4FD269C0CB [year+ old attachment deleted by admin]Hi there. Please download aswMBR from here
Note: Do not take action against any **Rootkit** entries until I have reviewed the log. Often there are false positives
aswMBR version 0.9.9.1665 Copyright(c) 2011 AVAST Software Run date: 2012-09-01 19:46:42 ----------------------------- 19:46:42.604 OS Version: Windows x64 6.1.7601 Service Pack 1 19:46:42.604 Number of processors: 4 586 0x170A 19:46:42.605 ComputerName: CESARE-PC UserName: Cesare 19:46:43.393 Initialize success 19:48:40.504 AVAST engine defs: 12090100 19:48:54.964 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005c 19:48:54.968 Disk 0 Vendor: Hitachi_ ST2O Size: 305245MB BusType: 3 19:48:55.021 Disk 0 MBR read successfully 19:48:55.027 Disk 0 MBR scan 19:48:55.037 Disk 0 Windows 7 default MBR code 19:48:55.045 Disk 0 Partition 1 00 42 SFS 0 MB offset 63 19:48:55.072 Disk 0 Partition 2 00 27 Hidden NTFS WinRE NTFS 15360 MB offset 2048 19:48:55.087 Disk 0 Partition 3 80 (A) 42 SFS NTFS 100 MB offset 31459328 19:48:55.103 Disk 0 Partition 4 00 42 SFS NTFS 144846 MB offset 31664128 19:48:55.111 Disk 0 scanning C:\Windows\system32\drivers 19:48:55.119 Service scanning 19:49:23.738 Modules scanning 19:49:23.750 Disk 0 trace - called modules: 19:49:23.770 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys storport.sys hal.dll nvstor64.sys 19:49:24.011 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa800334b060] 19:49:24.019 3 CLASSPNP.SYS[fffff88001bbd43f] -> nt!IofCallDriver -> [0xfffffa8002fc2e40] 19:49:24.031 5 ACPI.sys[fffff88000f877a1] -> nt!IofCallDriver -> \Device\0000005c[0xfffffa8002fb66f0] 19:49:25.130 AVAST engine scan C:\Windows 19:49:25.139 AVAST engine scan C:\Windows\system32 19:49:25.152 AVAST engine scan C:\Windows\system32\drivers 19:49:25.162 AVAST engine scan C:\Users\Cesare 19:49:25.173 AVAST engine scan C:\ProgramData 19:49:25.183 Scan finished successfully 19:49:58.375 Disk 0 MBR has been saved successfully to "C:\Users\Cesare\Desktop\MBR.dat" 19:49:58.389 The log file has been saved successfully to "C:\Users\Cesare\Desktop\aswMBR001.txt" Please download AdwCleaner by Xplode onto your Desktop.
# Updated 30/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : Cesare - CESARE-PC # Boot Mode : Normal # Running from : C:\Users\Cesare\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v15.0 (en-US) Profile name : default File : C:\Users\Cesare\AppData\Roaming\Mozilla\Firefox\Profiles\sdbtzu4f.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Users\Cesare\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. -\\ Opera v11.11.2109.0 File : C:\Users\Cesare\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] File is clean. ************************* AdwCleaner[S1].txt - [5842 octets] - [01/09/2012 09:01:21] AdwCleaner[R1].txt - [1179 octets] - [02/09/2012 12:22:01] AdwCleaner[S2].txt - [1390 octets] - [02/09/2012 12:22:21] AdwCleaner[R2].txt - [1151 octets] - [02/09/2012 23:16:08] ########## EOF - C:\AdwCleaner[R2].txt - [1211 octets] ########## Cheers altvicRogueKiller log: RogueKiller V8.0.2 [08/31/2012] by Tigzy mail: tigzyRKgmailcom Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/ Blog: http://tigzyrk.blogspot.com Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : Cesare [Admin rights] Mode : Scan -- Date : 09/02/2012 23:20:52 ¤¤¤ Bad processes : 3 ¤¤¤ [RESIDUE] iexplore.exe -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -> KILLED [TermProc] [RESIDUE] iexplore.exe -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -> KILLED [TermProc] [RESIDUE] iexplore.exe -- C:\Program Files (x86)\Internet Explorer\iexplore.exe -> KILLED [TermThr] ¤¤¤ Registry Entries : 11 ¤¤¤ [TASK][ROGUE ST] 0.job : c:\program files (x86)\internet explorer\iexplore.exe -> FOUND [HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND [HJ] HKLM\[...]\System : ConsentPromptBehaviorAdmin (0) -> FOUND [HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND [HJ] HKLM\[...]\Wow6432Node\System : ConsentPromptBehaviorAdmin (0) -> FOUND [HJ] HKLM\[...]\System : EnableLUA (0) -> FOUND [HJ] HKLM\[...]\Wow6432Node\System : EnableLUA (0) -> FOUND [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND [FILEASSO] HKLM\[...]\command : ("C:\Program Files (x86)\Internet Explorer\iexplore.exe") -> FOUND ¤¤¤ Particular Files / Folders: ¤¤¤ ¤¤¤ Driver : [NOT LOADED] ¤¤¤ ¤¤¤ Infection : ¤¤¤ ¤¤¤ HOSTS File: ¤¤¤ --> C:\Windows\system32\drivers\etc\hosts 127.0.0.1 localhost ¤¤¤ MBR Check: ¤¤¤ +++++ PhysicalDrive0: Hitachi HDT721032SLA SCSI Disk Device +++++ --- User --- [MBR] b6fca15b00ab5cfcd59958d591ebc78d [BSP] 018e58c0f60582cf2d35679dcc2f8b1b : Windows 7 MBR Code Partition table: 0 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 63 | Size: 0 Mo 1 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo 2 - [ACTIVE] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo 3 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 31664128 | Size: 144846 Mo User = LL1 ... OK! Error reading LL2 MBR! Finished : << RKreport[1].txt >> RKreport[1].txt Please download and run TDSSKiller to your desktop as outlined below: Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters. For Windows XP, double-click to start. For Vista or Windows 7, do a right-click on the program, select Run as ADMINISTRATOR to start, & when PROMPTED Allow to run. ------------------------- Check the boxes beside Verify Driver Digital Signature and Detect TDLFS file system, then click OK. ------------------------ Click the Start Scan button. ----------------------- If a suspicious object is detected, the default action will be Skip, click on Continue If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose Skip and click on Continue ---------------------- If malicious objects are found, they will show in the Scan results and offer three (3) options. Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process. Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed. -------------------- A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste its contents on your next reply. Sometimes these logs can be very large, in that case please attach it or zip it up and attach it. ------------------- Here's a summary of what to do if you would like to print it out: If a suspicious object is detected, the default action will be Skip, click on Continue If you get the warning about a file UnsignedFile.Multi.Generic or LockedFile.Multi.Generic please choose Skip and click on Continue If malicious objects are found, they will show in the Scan results and offer three (3) options. Ensure Cure is selected, then click Continue => Reboot now to finish the cleaning process. Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed. |
|
| 103. |
Solve : Logs from malware removal guide? |
|
Answer» i reported a malware problem earlier, as a guest, but have since become a registered user. i'm being prompted to allow the installation of an ask toolbar. i removed everything "ask" related using revo uninstaller, but continued to RECEIVE the prompt. i followed the steps in the "malware removal guide" and am submitting the requested logs for review. also, i'm confused regarding step 6. i ran HJT, but took no action when i received the results of the scan. how do i proceed in regards to the scan results? thanks for all your help, you guys are doing a great job!
---------- Disable Winpatrol so it does not block any fixes. You can re-enable it after we're done. Right-click the running icon of Winpatrol in the sytem tray and choose exit. ---------- Malwarebytes is a version behind so you need to update and run it again. Open Malwarebytes' Anti-Malware. * Click the Update tab. * Click Check for Updates * If an update is found, it will download and install. * Click the Scanner tab. * Select Perform Quick Scan, then click Scan. * The scan may take some time to finish,so PLEASE be patient. * When the scan is complete, click OK, then Show Results to view the results. * Make sure that everything is checked, and click Remove Selected. * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note) * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. * Copy & Paste the entire report in your next reply. Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. ---------- Right click HijackThis and choose Run as Administrator Next select Do a system scan only Place a check mark next to the following entries: (if there) - O2 - BHO: (no NAME) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) Important: Close all open windows except for HijackThis and then click Fix checked. Once completed, exit HijackThis. ---------- I am not seeing where the Ask installer is running from so we need to go in and find it. The 64 bit OS also limits us as to the tools we can use. But we will get it. First let's try the easy way and hope it finds and removes the leftovers. Ask Toolbar Remover 1.3: A program that is able to remove the Ask toolbar (plus all the debris) and set the homepage back to the one the user wants to. More info here. http://fred-de-vries.blogspot.com/2009/12/autoclean-ask-toolbar-remover.html Download here. http://autoclean.computersitter.com/downloads/ASKRemover.zip?attredirects=0&d=1 Just download and open the zip file then run the tool. A window swill open with more information and that is normal. The tool runs/completes very fast. Restart the computer and let me know if it worked. |
|
| 104. |
Solve : My computer won't even come on now? |
|
Answer» My friend gave me a lap top computer. It is an HP PAVILION dv6000. I can't tell you much else about it because it doesn't even TURN on. He said that it was locking up on him, and he gave it to someone that supposedly makes a living fixing computers, but after 6 weeks he gave it back and now it doesn't do anything. Is there something that I can do to try and get it working again. |
|
| 105. |
Solve : Getting my A** kicked by nodqq.exe virus on 3 machines....wow? |
|
Answer» Took most of last night and today to sift through posts, google searches and to get my THOUGHTS together...so here goes. |
|
| 106. |
Solve : Hijacked by "File Recovery" malware sales program? |
|
Answer» Update Your Java (JRE)
It appears that the trash-999 folder was genuinely connected to the trash, because the files in it were empty folders that I recently deleted on purpose. Here's what ComboFix spit out this time: ComboFix 12-07-21.01 - Franis 07/22/2012 15:35:39.2.1 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2812.1809 [GMT -10:00] Running from: c:\users\Franis\Desktop\ComboFixAlso.exe Command switches used :: c:\users\Franis\Desktop\CFScript.txt AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((( Files Created from 2012-06-23 to 2012-07-23 ))))))))))))))))))))))))))))))) . . 2012-07-23 01:45 . 2012-07-23 01:45--------d-----w-c:\users\Guest\AppData\Local\temp 2012-07-23 01:45 . 2012-07-23 01:45--------d-----w-c:\users\Default\AppData\Local\temp 2012-07-23 01:45 . 2012-07-23 01:45--------d-----w-c:\users\Certainly\AppData\Local\temp 2012-07-23 00:25 . 2012-07-23 00:25476976----a-w-c:\windows\SysWow64\npdeployJava1.dll 2012-07-18 09:57 . 2012-07-18 09:57--------d-----w-c:\users\Franis\AppData\Roaming\SUPERAntiSpyware.com 2012-07-18 09:57 . 2012-07-18 09:57--------d-----w-c:\program files\SUPERAntiSpyware 2012-07-18 09:57 . 2012-07-18 09:57--------d-----w-c:\programdata\SUPERAntiSpyware.com 2012-07-15 20:29 . 2012-07-15 20:29--------d---a-w-C:\.Trash-999 2012-07-11 22:32 . 2012-07-11 22:32--------d-----w-c:\program files (x86)\Malwarebitey 2012-07-11 22:32 . 2012-04-05 01:5624904----a-w-c:\windows\system32\drivers\mbam.sys 2012-07-11 16:38 . 2012-07-11 16:38--------d-----w-c:\program files (x86)\Mozilla Maintenance Service 2012-07-11 16:38 . 2012-07-11 16:38421200----a-w-c:\program files (x86)\Mozilla Firefox\msvcp100.dll 2012-07-11 16:38 . 2012-07-11 16:38770384----a-w-c:\program files (x86)\Mozilla Firefox\msvcr100.dll 2012-07-11 16:04 . 2012-06-12 03:083148800----a-w-c:\windows\system32\win32k.sys 2012-07-11 15:48 . 2012-06-02 12:01173056----a-w-c:\windows\system32\ieUnatt.exe 2012-07-11 14:50 . 2012-06-06 06:062004480----a-w-c:\windows\system32\msxml6.dll 2012-07-11 14:50 . 2012-06-06 06:061881600----a-w-c:\windows\system32\msxml3.dll 2012-07-11 14:50 . 2012-06-06 05:051390080----a-w-c:\windows\SysWow64\msxml6.dll 2012-07-11 14:50 . 2012-06-06 05:051236992----a-w-c:\windows\SysWow64\msxml3.dll 2012-07-11 14:50 . 2010-06-26 03:552048----a-w-c:\windows\system32\msxml3r.dll 2012-07-11 14:50 . 2010-06-26 03:242048----a-w-c:\windows\SysWow64\msxml3r.dll . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2012-07-23 00:25 . 2010-06-07 12:18472880----a-w-c:\windows\SysWow64\deployJava1.dll 2012-07-13 10:14 . 2012-04-04 20:32426184----a-w-c:\windows\SysWow64\FlashPlayerApp.exe 2012-07-13 10:14 . 2011-05-31 10:1270344----a-w-c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2012-07-11 15:52 . 2009-11-21 06:4359701280----a-w-c:\windows\system32\MRT.exe 2012-06-03 01:19 . 2012-06-22 06:48186752----a-w-c:\windows\system32\wuwebv.dll 2012-06-03 01:15 . 2012-06-22 06:4836864----a-w-c:\windows\system32\wuapp.exe 2012-06-02 22:19 . 2012-06-22 06:4938424----a-w-c:\windows\system32\wups.dll 2012-06-02 22:19 . 2012-06-22 06:502428952----a-w-c:\windows\system32\wuaueng.dll 2012-06-02 22:19 . 2012-06-22 06:5057880----a-w-c:\windows\system32\wuauclt.exe 2012-06-02 22:19 . 2012-06-22 06:5044056----a-w-c:\windows\system32\wups2.dll 2012-06-02 22:19 . 2012-06-22 06:49701976----a-w-c:\windows\system32\wuapi.dll 2012-06-02 22:15 . 2012-06-22 06:502622464----a-w-c:\windows\system32\wucltux.dll 2012-06-02 22:15 . 2012-06-22 06:4999840----a-w-c:\windows\system32\wudriver.dll 2012-05-20 06:36 . 2012-05-16 21:1498848----a-w-c:\windows\system32\drivers\avgntflt.sys 2012-05-20 06:36 . 2012-05-16 21:14132832----a-w-c:\windows\system32\drivers\avipbb.sys 2012-05-04 11:06 . 2012-06-14 09:505559664----a-w-c:\windows\system32\ntoskrnl.exe 2012-05-04 10:03 . 2012-06-14 09:503968368----a-w-c:\windows\SysWow64\ntkrnlpa.exe 2012-05-04 10:03 . 2012-06-14 09:503913072----a-w-c:\windows\SysWow64\ntoskrnl.exe 2012-05-01 05:40 . 2012-06-14 09:50209920----a-w-c:\windows\system32\profsvc.dll 2012-04-28 03:55 . 2012-06-14 09:50210944----a-w-c:\windows\system32\drivers\rdpwd.sys 2012-04-26 05:41 . 2012-06-14 09:5077312----a-w-c:\windows\system32\rdpwsx.dll 2012-04-26 05:41 . 2012-06-14 09:50149504----a-w-c:\windows\system32\rdpcorekmts.dll 2012-04-26 05:34 . 2012-06-14 09:509216----a-w-c:\windows\system32\rdrmemptylst.exe 2012-04-24 05:37 . 2012-06-14 09:49184320----a-w-c:\windows\system32\cryptsvc.dll 2012-04-24 05:37 . 2012-06-14 09:49140288----a-w-c:\windows\system32\cryptnet.dll 2012-04-24 05:37 . 2012-06-14 09:491462272----a-w-c:\windows\system32\crypt32.dll 2012-04-24 04:36 . 2012-06-14 09:491158656----a-w-c:\windows\SysWow64\crypt32.dll 2012-04-24 04:36 . 2012-06-14 09:49140288----a-w-c:\windows\SysWow64\cryptsvc.dll 2012-04-24 04:36 . 2012-06-14 09:49103936----a-w-c:\windows\SysWow64\cryptnet.dll . . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of C:\.Trash-999 ---- . 2012-07-15 22:14 . 2012-07-15 22:14111----a-w-c:\.trash-999\info\Out4improv.trashinfo 2012-07-15 22:13 . 2012-07-15 22:13105----a-w-c:\.trash-999\info\Text.trashinfo 2012-07-15 20:52 . 2012-07-15 20:52102----a-w-c:\.trash-999\info\video clips.trashinfo 2012-07-15 20:34 . 2012-07-15 20:34108----a-w-c:\.trash-999\info\Hula-at-Volcano on SAT-July14th.txt.trashinfo 2012-07-15 20:29 . 2012-07-15 20:2998----a-w-c:\.trash-999\info\malware_File_Recovery.lnk.trashinfo 2012-07-14 08:10 . 2012-07-14 08:10659----a-w-c:\.trash-999\files\malware_File_Recovery.lnk 2012-07-08 17:04 . 2012-07-08 17:041494----a-w-c:\.trash-999\files\Hula-at-Volcano on SAT-July14th.txt . .Please download Rooter and Save it to your desktop.
Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (2924) - Deluxe\PlayMovie\PMVService.exe (3216) C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (3216) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (1612) (these may have been part of the bloatware that came originally with the computer, even though I don't use them) Programs that I do use and recognize are: C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (1584) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1440) C:\Users\Franis\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (2388) C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (2260) C:\Windows\Tasks\GlaryInitialize.job I'm curious about what the rest of this scan means, if you care to educate me a bit. Here is the Rooter scan results: Rooter.exe (v1.0.2) by Eric_71 . SeDebugPrivilege granted successfully ... . Windows 7 Home Edition (6.1.7601) Service Pack 1 [32_bits] - AMD64 Family 15 Model 124 Stepping 2, AuthenticAMD . [wscsvc] (Security Center) RUNNING (state:4) [MpsSvc] RUNNING (state:4) Windows Firewall -> Enabled Windows Defender -> Enabled . Internet Explorer 9.0.8112.16421 Mozilla Firefox 13.0.1 (en-US) . C:\ [Fixed-NTFS] .. ( Total:136 Go - Free:76 Go ) D:\ [CD_Rom] . Scan : 02:39.14 Path : C:\Users\Franis\Desktop\Rooter.exe User : Franis ( Administrator -> YES ) . ----------------------\\ Processes . Locked [System Process] (0) Locked System (4) ______ ? (260) ______ ? (400) ______ ? (472) ______ ? (484) ______ ? (532) ______ ? (540) ______ ? (548) ______ ? (604) ______ ? (700) ______ ? (772) ______ ? (820) ______ ? (940) ______ ? (984) ______ ? (100) ______ C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe (308) ______ ? (716) ______ ? (1080) ______ ? (1108) ______ ? (1252) ______ C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (1292) ______ ? (1312) ______ ? (1420) ______ C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (1440) ______ ? (1492) ______ C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (1536) ______ C:\Program Files (x86)\Yuna Software\Messenger Plus! for Skype\MsgPlusForSkypeService.exe (1584) ______ C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (1612) ______ C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (1660) ______ ? (1760) ______ C:\Program Files\Acer\Acer Updater\UpdaterService.exe (1824) ______ ? (1864) ______ ? (1988) ______ ? (2144) ______ ? (2152) ______ ? (2516) ______ ? (2608) ______ ? (2648) ______ ? (2856) ______ ? (2868) ______ ? (2896) ______ C:\Users\Franis\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (2388) ______ ? (140) ______ C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe (960) ______ ? (1324) ______ ? (1956) ______ C:\Program Files (x86)\Launch Manager\LManager.exe (2940) ______ C:\Program Files (x86)\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe (2924) ______ C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (2260) ______ ? (904) ______ C:\Program Files (x86)\Brother\Brmfcmon\BrMfcWnd.exe (2384) ______ C:\Program Files (x86)\Acer Arcade Deluxe\PlayMovie\PMVService.exe (3216) ______ ? (3232) ______ C:\Program Files (x86)\Brother\Brmfcmon\BrMfcmon.exe (3268) ______ C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (3308) ______ C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (3444) ______ ? (3484) ______ ? (2404) ______ ? (2364) ______ ? (3968) ______ ? (4104) ______ ? (4992) Locked audiodg.exe (4524) ______ C:\Users\Franis\Desktop\Rooter.exe (4600) . ----------------------\\ Device\Harddisk0\ . \Device\Harddisk0 [Sectors : 63 x 512 Bytes] . \Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:12888981504) \Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:12889013760 | Length:106928640) \Device\Harddisk0\Partition3 (Start_Offset:12995942400 | Length:147044894720) . ----------------------\\ Scheduled Tasks . C:\Windows\Tasks\Adobe Flash Player Updater.job C:\Windows\Tasks\GlaryInitialize.job C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1109757479-377625319-1456128612-1000Core.job C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1109757479-377625319-1456128612-1000UA.job C:\Windows\Tasks\SA.DAT C:\Windows\Tasks\SCHEDLGU.TXT . ----------------------\\ Registry . . ----------------------\\ Files & Folders . ----------------------\\ Scan completed at 02:39.26 . C:\Rooter$\Rooter_3.txt - (24/07/2012 | 02:39.26) Quote The ones I don't recognize as programs I use are:They probably were install when your computer was loaded or by another program. If you don't use them, uninstall them. Quote I'm curious about what the rest of this scan means, if you care to educate me a bit.I don't wish to go into too much detail in an open forum but it is a scanner looking for Rootkits. How is your computer working now? I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt OK, that scan (which took twelve hours!) found a couple of objections... The computer seems to be running normally, even before these two little problems were found. Is there any cleanup that I should do to uninstall some of these programs we've used to scour these bugs away? These programs you recommended to use in this process seem pretty tiny - is there any danger of leaving them installed? Here's the log file from the online scan: C:\Users\Franis\Documents\THINKGS\src\browsers\newerChrome\chromupdater_exe.exea variant of Win32/InstallCore.D applicationcleaned by deleting - quarantined C:\Users\Franis\Documents\THINKGS\src\skype\recording messenger svs\Setup-SkypePlus-1.2.exea variant of Win32/MessengerPlus.A applicationdeleted - quarantined Quote Is there any cleanup that I should do to uninstall some of these programs we've used to scour these bugs away? These programs you recommended to use in this process seem pretty tiny - is there any danger of leaving them installed? Yes, we can do some cleanup. You can keep SAS and MBAM on your computer, if you wish. Update them and run them on a regular basis as they are not full-time scanners. Download this program and run it Uninstall ComboFix .It will remove ComboFix for you. *************************************************** To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. This will give you a new, clean Restore Point. *************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, VIRUSES and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! Yes, I appreciate the reminder to do a new restore point again and the other things to do you suggested to beef up my protection levels. I'm considering also using Comodor for my firewall too, because I heard that the default one I have been using wasn't really adequate. I have a few more clueless questions. When I ran the uninstall to Combofix, it didn't disappear the .exe file that was on my desktop where I'd downloaded it. So does that mean the uninstall program uninstalled ComboFix, but left the original file that installed ComboFix alone... and if I clicked on the .exe file of ComboFix I would reinstall it again? Another one of the things that changed because of the attack was how the list of currently running programs is displayed on my task bar. These currently running programs used to be in a MENU that took up a half an inch of space on my lower right corner. Since the attack, these programs are in a line, taking up three inches instead of a half inch. Also, I imagine I can replace the icons that used to be next to my "start" button by dragging them onto the task bar on the other side, but there used to be an icon there signifying "show desktop" that I'd like to have back too. I think that I'm remembering this change happened when I ran the "unhide" program. Quote When I ran the uninstall to Combofix, it didn't disappear the .exe file that was on my desktop where I'd downloaded it. So does that mean the uninstall program uninstalled ComboFix, but left the original file that installed ComboFix alone... and if I clicked on the .exe file of ComboFix I would reinstall it again?It's probably just something left over. You can check for ComboFix on C: Combofix. If it's still there please run the uninstall program. I've never tried that uninstall program so I'm unsure how it works. Quote Another one of the things that changed because of the attack was how the list of currently running programs is displayed on my task bar. These currently running programs used to be in a menu that took up a half an inch of space on my lower right corner. Since the attack, these programs are in a line, taking up three inches instead of a half inch. Also, I imagine I can replace the icons that used to be next to my "start" button by dragging them onto the task bar on the other side, but there used to be an icon there signifying "show desktop" that I'd like to have back too. I think that I'm remembering this change happened when I ran the "unhide" program.I'm not sure what you mean. Could you provide a screenprint? How to post screenshots or images OK, here's a screen shot of what I mean... I was about wrote a little note on the picture itself. (Hope the typeface isn't too small to see... but if it is, it says: Here's a screenprint. these icons you see below used to not be located in a line as they are now. They used to be in a menu, (which did not take up more than an EIGHTH of the space here) After clicking on the menu, each icon was displayed and could be interacted with in the same way, but they were displayed in a menu box rather than in a line as they appear here. ) That looks normal but here's more information about the icons. |
|
| 107. |
Solve : Some advice?? |
|
Answer» I have some pretty strong suspicions of others messing around with my machine. Im not going to get into detail of who is doing it or for whatever reasons because in truth I dont know and because it will take a long long time. Whenever I format the drive it tells me that it has space used as you can see. The amount of space varies by filesystem it is the same drive under different filesystems. This does not only happen with this hard drive but with all of the drives I own.Data used and reserved for file structures with various File Systems use disk space. Quote So what I did today was to install windows XP and look for rootkits via a utility called TDSSKiller. To my surprise It found over 174 rootkits but I knew something was up from the start..Only way I can see that happening is with a pirated install of XP. (Or, if the install was actually a repair install or upgrade install of an existing infected XP installation) Quote The hole gets deeper tough when I attempt to run the program DBAN I cant use it. It tells me that the Hard disks might contain bad sectors yet in on other computer I can use the software. One possibility that I am getting that error might be hardware related issues but by any chance can a motherboard become infected?bad sectors can be responsible for false flaggings of rootkits, based on how a lot of them work (which is typically to inspect the disk at a lower level than the API functions that a rootkit would circumvent). Errors are sometimes flagged as rootkits. This is a sensible approach because the assumption on the software side is that hardware is working properly, so if something goes wrong, it assumes there is some other piece of software getting in the way. DBAN isn't designed to wipe disks with bad sectors. You could try an alternative tool like MHDD or HDDErase. Another common tool is [emailprotected] disk, which comes in a free VERSION that can be used. Quote What I will attempt is to run DBAN once again but am expecting the same result since Ive done it before I installed windows XP and found the rootkits.Rootkits are low level drivers installed into the operating System, usually used to facilitate the infection of the machine by hiding those new files from your standard OS tools. It quite literally cannot exist separate from the OS. A fresh install of Windows- or any OS, for that matter, quite literally cannot be infected in this way- UNLESS the install is done using a pirated Disc, which can often come with loads of "goodies" in the form of malware and rootkits. Some could argue that as part of a MBR or other low level code it could, but the XP install rewrites the MBR (as does GRUB install, to my recollection) so that isn't a place it would survive. Theoretically it is POSSIBLE for a virus to infect a BIOS, however, the problem here is that a Jumper would almost always have to be moved on the motherboard, and it would have to be BUILT to specifically target that exact Motherboard model. Since malware authors aim to infect as many machines as possible, this simply isn't economical from that perspective. Tried anything I can think of including deleting the master boot records and activekilldisk. Some pretty sticky malware i now dont think this drive is of any use to me now. Thank you.Please excuse the double post but I really need some guidance. I was able to run Dariks boot and nuke (switched AHCI to IDE) but now have a bigger issue. The issue now is the read/write rate. I suspect that the hard drives are somehow "frozen" the reasons for this are that as soon as I run the program the read/write rates are pretty fast (in KB/s) Expecting a successful wipe in about 8-10 hours after 20 minutes or so the read/write rates drop to bytes per second and the expected wipe should complete in 350+ hours.. Will try to use parted magic as my next resort.Are you needing malware removal or hard drive assistance?I apologize for not posting earlier. The reason is that I have been using other operating systems. I dont even know what is happening to my machine. I think I found some rootkits Im not sure though. Ran a scan with Kapersky TDSSKiller and found a lot of nasty stuff I would post logs but I didnt save them. The system would act up like nothing that Ive seen before. For example when I would try to install a piece of software like an antivirus the installer would hang unless I went to the task manager and ended a process called svchost that would take up %25 cpu usage the installer would then continue. Many things that are unexplained have caused me to believe that there is someone messing with my computer I dont want to get into detail since there is always that possibility that I am wrong. |
|
| 108. |
Solve : Application cannot be executed. The file **** is infected - Please help? |
|
Answer» I was stupidly downloading music and I must have come to some site that GAVE me a virus. I'm not TOO familiar with computers REALLY. Any help would be very APPRECIATED. This (possible) virus is really making me angry. |
|
| 109. |
Solve : Searchfilterhost.exe is infected -- My world has turned on me......? |
|
Answer» Hello:
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 4029 Windows 6.1.7600 (Safe Mode) Internet Explorer 8.0.7600.16385 4/24/2010 7:56:09 AM - Ardy mbam-log-2010-04-24 (07-56-09).txt Scan type: Full scan (C:\|D:\|) Objects scanned: 380728 Time elapsed: 1 hour(s), 0 minute(s), 28 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 2 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qrwaffgj (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ygwsslvv (Trojan.FakeAlert) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Users\Ardy\AppData\Local\inngnjoss\vfuxnrxtssd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Users\Ardy\AppData\Local\ktrfptpku\dcowjmatssd.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Users\Ardy\AppData\Local\syssvc.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. Please run a free online scan with the ESET Online Scanner
[emailprotected] as CAB hook log: OnlineScanner.ocx - registred OKIs any of this working? I've got the same thing.Please re-open Malwarebytes, click the Update tab, and click Check for Updates. Then, click the Scanner tab, select Perform Quick Scan, and press Scan. Remove selected, and post the log in your next reply.Scan report for Malwarebytes: Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 4036 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/25/2010 7:47:26 PM - Ardy mbam-log-2010-04-25 (19-47-26).txt Scan type: Quick scan Objects scanned: 110793 Time elapsed: 9 minute(s), 5 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) To manually create a new Restore Point
To remove all of the tools we used and the files and folders they created, please do the following: Please download OTC.exe by OldTimer:
== Please download TFC by OldTimer to your desktop
Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
Results of screen317's Security Check version 0.99.3 Windows 7 (UAC is enabled) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Antivirus up to date! (On Access scanning disabled!) ``````````````````````````````` Anti-malware/Other Utilities Check: Ad-Aware Free Registry Cleaner For Vista 2.0 Java(TM) SE Runtime Environment 6 Adobe Flash Player 10 ```````````````````````````````` Process Check: objlist.exe by Laurent Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
Once again I really appriciate your help. Is ther any way I would be able to donate and or give to this cause......... ArdyYou can keep Ad-Aware. It is good. There is no way to donate on this site unfortunately. We help for free, so you don't have to pay. |
|
| 110. |
Solve : Help with Windows Security Alert virus? |
|
Answer» I am having trouble opening any files, especially .exe files or update my virus protection, etc. Please help!
============== Please visit this webpage for a tutorial on downloading and running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix See the area: Using ComboFix, and when done, post the log back here.DragonMaster Jay, Link#1 is no longer a valid page. Therefore, I downloaded Link 2 but it would not run, same for Link 3. I have them saved on my desktop but when I dbl click the icon a black window opens for one second then closes, after which I get a Security Warning window that reads: Application cannot be executed. the file rkill(2).com is infected. Do you want to activate your antivirus software now? I figured that I should shut down my virus protection so I can download and run the links but everytime I try to access the add or remove programs it is shut down automatically. Hope you can help, thanks.Please try this:
ave.exe
Please reboot to Safe Mode with Networking (tap the F8 key just before Windows starts to load and select the Safe Mode with Networking option from the menu). Please visit this webpage for a tutorial on downloading and running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix See the area: Using ComboFix, and when done, post the log back here.DragonMaster Jay, here is the post. I started the system in safe mode and first ran the rkill program, which seemed to work. After that I ran the ComboFix and here is the log: ComboFix 10-04-21.01 - ppratt 04/24/2010 17:00:00.1.2 - x86 NETWORK Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.677 [GMT -4:00] Running from: c:\documents and settings\Cressida Silvers\Desktop\ComboFix.exe AV: Symantec AntiVirus Corporate Edition *On-access scanning enabled* (Outdated) {FB06448E-52B8-493A-90F3-E43226D3305C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe c:\windows\asam.exe c:\windows\eSellerateEngine.dll c:\windows\herjek.config . ((((((((((((((((((((((((( Files Created from 2010-03-24 to 2010-04-24 ))))))))))))))))))))))))))))))) . 2010-04-23 17:43 . 2010-04-23 17:4361184----a-w-c:\documents and settings\Cressida Silvers\Local Settings\Application Data\syssvc.exe 2010-04-23 17:41 . 2010-04-24 21:04--------d-----w-c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf 2010-04-10 23:51 . 2010-04-10 23:51--------d-----w-c:\program files\WindSolutions 2010-04-10 23:51 . 2010-04-10 23:54--------d-----w-c:\documents and settings\Cressida Silvers\Application Data\WindSolutions 2010-04-10 23:51 . 2010-04-10 23:51--------d-----w-c:\documents and settings\All Users\Application Data\WindSolutions . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-24 20:33 . 2008-07-18 16:05--------d-----w-c:\program files\Symantec AntiVirus 2010-04-22 16:39 . 2010-01-05 21:1040252---ha-w-c:\windows\system32\mlfcache.dat 2010-04-16 00:19 . 2005-10-20 14:25--------d-----w-c:\program files\Mozilla Thunderbird 2010-03-25 18:14 . 2005-04-22 19:0846800----a-w-c:\documents and settings\Cressida Silvers\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2010-03-10 06:15 . 2005-06-22 17:52420352----a-w-c:\windows\system32\vbscript.dll 2010-02-25 06:24 . 2005-06-22 17:52916480----a-w-c:\windows\system32\wininet.dll 2010-02-24 13:11 . 2005-06-22 17:49455680------w-c:\windows\system32\drivers\mrxsmb.sys 2010-02-19 23:47 . 2010-02-19 23:473604480----a-w-c:\windows\system32\GPhotos.scr 2010-02-16 14:08 . 2004-08-03 23:182146304------w-c:\windows\system32\ntoskrnl.exe 2010-02-16 13:25 . 2004-08-03 22:592024448------w-c:\windows\system32\ntkrnlpa.exe 2010-02-12 04:33 . 2005-06-22 17:46100864------w-c:\windows\system32\6to4svc.dll 2010-02-11 12:02 . 2005-06-22 17:51226880------w-c:\windows\system32\drivers\tcpip6.sys 2010-02-09 19:57 . 2010-02-09 19:5745056----a-w-c:\documents and settings\Cressida Silvers\Application Data\Sun\Java\Deployment\cache\javaws\http\Dqedoc.net\P80\DMqqp\RNlibraries.jar\jniwrap.dll 2005-07-01 15:55 . 2005-07-01 15:552649----a-w-c:\program files\Psyllids at Andytown update.eml 2004-05-19 13:51 . 2006-08-31 17:4110339----a-w-c:\program files\sas91_859417.txt . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-11-19 135664] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648] "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2003-12-17 1241138] "SoundMan"="SOUNDMAN.EXE" [2004-08-30 69632] "HP SchedIndexer"="c:\program files\Hewlett-Packard\LaserJet 33xx\hppschedindexer.exe" [2002-01-03 94208] "HP AutoIndexer"="c:\program files\Hewlett-Packard\LaserJet 33xx\hppautoindexer.exe" [2002-01-03 90112] "Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328] "RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2003-11-01 32768] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-05-29 52840] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2007-10-08 125368] "RoxWatchTray"="c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatchTray10.exe" [2008-05-20 244208] "DMXLauncher"="c:\program files\Roxio\CinePlayer\DMXLauncher.exe" [2008-04-07 113136] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "RunNarrator"="Narrator.exe" [2008-04-14 53760] "MPlayer2_FixUp"="c:\windows\inf\unregmp2.exe" [2008-04-14 208896] c:\documents and settings\ppratt\Start Menu\Programs\Startup\ HotSync Manager.LNK - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008] c:\documents and settings\Cressida Silvers\Start Menu\Programs\Startup\ HotSync Manager.LNK - c:\program files\palmOne\HOTSYNC.EXE [2004-4-13 299008] c:\documents and settings\All Users\Start Menu\Programs\Startup\ Adobe Acrobat SPEED Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-100000000002}\SC_Acrobat.exe [2005-7-7 25214] Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-6-30 113664] HP LaserJet Director.lnk - c:\program files\Hewlett-Packard\LaserJet 33xx\hppdirector.exe [2005-6-28 204800] hpoddt01.exe.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe [2003-4-9 28672] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "filteradministratortoken"= 1 (0x1) "ReportControllerMissing"= 1 (0x1) "LogonType"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "PreXPSP2ShellProtocolBehavior"= 0 (0x0) "NoMSAppLogo5ChannelNotify"= 1 (0x1) "NoWebServices"= 1 (0x1) "NoOnlinePrintsWizard"= 1 (0x1) "NoPublishingWizard"= 1 (0x1) "NoWelcomeScreen"= 1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Gateway\\HPA\\GWMenu.exe"= "c:\\Program Files\\SAS\\SAS 9.1\\sas.exe"= "c:\\Program Files\\Retrospect\\Retrospect Client\\retroclient.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009 S2 Retrospect Client;Retrospect Client;c:\program files\Retrospect\Retrospect Client\RemotSvc.exe [3/20/2006 10:39 AM 61440] S2 Roxio Upnp Server 10;Roxio Upnp Server 10;c:\program files\Roxio\Digital Home 10\RoxioUpnpService10.exe [5/20/2008 9:15 AM 362992] S2 RoxLiveShare10;LiveShare P2P Server 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxLiveShare10.exe [5/20/2008 9:13 AM 309744] S2 RoxWatch10;Roxio Hard Drive Watcher 10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxWatch10.exe [5/20/2008 9:13 AM 166384] S2 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [10/7/2007 8:48 PM 116664] S3 DNINDIS5;DNINDIS5 NDIS Protocol Driver;c:\windows\system32\DNINDIS5.sys [8/15/2009 1:31 PM 17149] S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [8/13/2009 11:54 AM 101936] S3 Roxio UPnP Renderer 10;Roxio UPnP Renderer 10;c:\program files\Roxio\Digital Home 10\RoxioUPnPRenderer10.exe [5/20/2008 9:15 AM 313840] S3 RoxMediaDB10;RoxMediaDB10;c:\program files\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [5/20/2008 9:12 AM 1120752] S3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service;c:\windows\system32\drivers\WPN111.sys [8/15/2009 1:31 PM 384608] . Contents of the 'Scheduled Tasks' folder 2010-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34] 2010-04-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-861567501-682003330-1003Core.job - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-19 22:41] 2010-04-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-861567501-682003330-1003UA.job - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-11-19 22:41] . . ------- Supplementary Scan ------- . uDefault_Search_URL = hxxp://www.google.com/ie uInternet Settings,ProxyOverride = uInternet Settings,ProxyServer = http=127.0.0.1:5555 uSearchAssistant = hxxp://www.google.com/ie uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200 IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 DPF: {CAFECAFE-0013-0001-0017-ABCDEFABCDEF} FF - ProfilePath - c:\documents and settings\Cressida Silvers\Application Data\Mozilla\Firefox\Profiles\w1zfhx73.Default User 2\ FF - prefs.js: browser.startup.homepage - hxxp://cnn.com FF - plugin: c:\documents and settings\Cressida Silvers\Application Data\Move Networks\plugins\npqmp071505000011.dll FF - plugin: c:\documents and settings\Cressida Silvers\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava11.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava12.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava13.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava14.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJava32.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPJPI150_10.dll FF - plugin: c:\program files\Java\jre1.5.0_10\bin\NPOJI610.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npCouponPrinter.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\NPJinit13117.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false); c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); . - - - - ORPHANS REMOVED - - - - HKCU-Run-chwgonkc - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe HKCU-Run-asam - c:\windows\asam.exe HKLM-Run-chwgonkc - c:\documents and settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe HKLM-Run-asam - c:\windows\asam.exe AddRemove-McAfee Security Scan - c:\program files\McAfee Security Scan\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-04-24 17:07 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(772) c:\windows\system32\Ati2evxx.dll . Completion time: 2010-04-24 17:10:19 ComboFix-quarantined-files.txt 2010-04-24 21:10 Pre-Run: 8,021,364,736 bytes free Post-Run: 12,825,636,864 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect - - End Of File - - EB5129E6AA2056EE64DF83BE96E018F7 Please download Malwarebytes Anti-Malware from Malwarebytes.org. Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 4036 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 4/26/2010 6:42:51 AM mbam-log-2010-04-26 (06-42-51).txt Scan type: Full scan (C:\|) Objects scanned: 323637 Time elapsed: 1 hour(s), 59 minute(s), 21 second(s) MEMORY Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 3 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\Documents and Settings\Cressida Silvers\Local Settings\Application Data\syssvc.exe (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\Documents and Settings\Cressida Silvers\Local Settings\Application Data\hmsnddgyf\vixqnsftssd.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\Qoobox\Quarantine\C\WINDOWS\asam.exe.vir (Trojan.FakeAlert.Gen) -> Quarantined and deleted successfully. Please run a free online scan with the ESET Online Scanner
|
|
| 111. |
Solve : Re Direct? |
|
Answer» If I enetr a search topic and then click on a link it takes me to E bay or some other site not connected to where I want to go, how do I prevent this? it started about 5 days ago thanks in advanceHello and welcome to COMPUTER Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately. ************************************************* Download DDS from HERE or HERE and save it to your desktop. Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it) * XP users Double click on dds to run it. * If your antivirus or firewall try to block DDS then please allow it to run. * When finished DDS will open two (2) logs. * Save both reports to your desktop. * The instructions here ask you to attach the Attach.txt. 1) DDS.txt 2) Attach.txt Instead of attaching, please copy/past both logs into your Thread Note: DDS will instruct you to post the Attach.txt log as an attachment. Please just post it as you would any other log by copying and pasting it into the reply. •Close the program window, and delete the program from your desktop. Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt ) |
|
| 112. |
Solve : Metropolitan Police malware has infected my system? |
|
Answer» Here is the ESET Log I got Metropolitan Police malware on my laptop. I followed the "read this before requesting malware removal help" post which seems to have stopped it, Now I just need to get rid of the damage? I think there are still some files left on my laptop from the malware and I am missing a RUNDLL file from the windows directory. I have attache a jpg of the ERROR window as I couldn't seem to get it into the post. I believe the RUNDLL file was the source of my malware issue. I will explain my reasoning though I could be wrong. When I got the malware it locked up the laptop. It didn't however start until the internet connection was live. So with the internet disconnected I looked in my startup folder by going right mouse button on Start and browsing all USERS. I found a short cut called cpfmon. I deleted cos I didn't know what it was. Came straight back. So I searched C drive for cpfmon and found a few other files withe the same name. I deleted them and then connected to the internet. No malware issue. When I restarted and connected I got the malware back. So I looked at the properties of the cpfmon shortcut and found where it was linked to, it was a RUNDLL file in the windows directory. Hence why I think the RUNDLL file was the source of the malware or at least what it had infected. Apart from this missing file everything is ok that I can see. I appreciate all the help you have given. Thank you [year+ old attachment deleted by admin]I'm happy that everything is working well but I want to check further on that alert and then we'll so some cleanup.Please download SystemLook from one of the links below and save it to your desktop. Link # 1 Link # 2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double-click SystemLook.exe to run it. Copy the contents of the following codebox into the main textfield. Code: [Select]:filefind jork_0_typ_col.exe Click the Look button to start the scan. Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt SystemLook 30.07.11 by jpshortstuff Log created at 18:17 on 05/07/2012 by Benni Administrator - Elevation successful ========== filefind ========== Searching for "jork_0_typ_col.exe" No files found. -= EOF =- Double-click SystemLook.exe to run it. Copy the contents of the following codebox into the main textfield. Code: [Select]:regfind jork_0_typ_col.exe Click the Look button to start the scan. Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt Nothing exciting I'm afraid SystemLook 30.07.11 by jpshortstuff Log created at 19:39 on 06/07/2012 by Benni Administrator - Elevation successful ========== regfind ========== Searching for "jork_0_typ_col.exe" No data found. -= EOF =-Please download SystemLook from one of the links below and save it to your desktop. Link # 1 Link # 2 Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double-click SystemLook.exe to run it. Copy the contents of the following codebox into the main textfield. Code: [Select]:regfind "error loading" Click the Look button to start the scan. Note: The scan may take some time so please just let it do its work and be patient (or do something else unrelated to the computer). When finished, a notepad window will open with the results of the scan. Please post the log. The log can also be found on your desktop entitled SystemLook.txt I'm afraid there is still no joy SystemLook 30.07.11 by jpshortstuff Log created at 18:08 on 08/07/2012 by Benni Administrator - Elevation successful ========== regfind ========== Searching for ""error loading"" No data found. -= EOF =-Please do this even if you don't have your OS disk.Please let me know what happens. Do you have an XP CD? If so, place it in your CD ROM drive and follow the instructions below: •Click on Start > Run and type sfc /scannow then press Enter (note the space between scf and /scannow) *Let this run undisturbed until the window with the blue progress bar goes away SFC - Which stands for System File Checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.Unfortunatly I don't have the XP CD. I got the lap top with an XP downgrade as I didn't want Windows Vista. I have the Vista CD though. I followed the FSC /Scannow instructions. It went through it all. There was no message after it finished so I assume everything was ok.Quote from: benni9000 on July 11, 2012, 10:36:10 AM Unfortunatly I don't have the XP CD. I got the lap top with an XP downgrade as I didn't want Windows Vista. I have the Vista CD though.If it didn't ask for the XP disk that means all the OS files are ok. I'm at a loss as to what's causing this error.Ok. No worries. Other than that message on startup everything seems to be working ok. I really appreciate the time and effort you've spent helping me sort my laptop out. Thank youWe should do some cleanup before you go. Download this program and run it Uninstall ComboFix .It will remove ComboFix for you ******************************************* To turn off Windows XP System Restore: NOTE: These instructions assume that you are using the default Windows XP Start Menu and have not changed to the Classic Start menu. To re-enable the default menu, right-click Start, click Properties, click Start menu (not Classic) and then click OK. 1. Click Start. 2. Right-click the My Computer icon, and then click Properties. 3. Click the System Restore tab. 4. Check "Turn off System Restore" or "Turn off System Restore on all drives" 5. Click Apply. 6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this. 7. Click OK. 8. Restart the computer and follow the instructions in the next section to turn on System Restore. To turn on Windows XP System Restore: 1. Click Start. 2. Right-click My Computer, and then click Properties. 3. Click the System Restore tab. 4. Uncheck "Turn off System Restore" or "Turn off System Restore on all drives." 5. Click Apply, and then click OK. ************************************************ Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ************************************************ Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all CRITICAL updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - SEARCH & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 113. |
Solve : How do i get rid of a trojan virus on my computer?? |
|
Answer» My computer has a trojan virus. There are so many pop-ups..and it randomly shuts down every half hour. how do i REMOVE this virus?Please visit this webpage for a tutorial on downloading and running ComboFix: |
|
| 114. |
Solve : Wireless Router Virus?? |
|
Answer» Ok, so I am very paranoid about viruses...but only because I am starting a photography blog/website and I am concerned about spreading a virus to others. I have a laptop that is wiped clean. I am using a brand new memory card in my digital camera and only using it with this computer (to prevent viruses) to take photographs for the website. My main concern now is that of our home wireless network...the router is hooked up to our main desktop computer...and one other laptop connects to and uses the wireless network (family member). My question is...when I connect my clean laptop to the internet via wireless, can I get a virus from one of the other computers in my household because of sites that they have visited? I have heard that this is possible, and am interested in finding out how to ensure that this does not happen (as I do not want my files/photos that I intend to share on the website to infect others). I have not connected to the internet on the laptop since I have restored the computer to original factory state...I intend to immediately install MICROSOFT Security Essentials...but I must connect wirelessly to do so...Will this also put me at risk? I know that this is kind of a complicated hypothetical thing, but I was interested in a little help/input if at all possible. Also, Is there a way to scan the router for infections? Thanks :-)Yes. It can. And you can fix it Using the reset feature, you can stick a toothpick into the HOLE and force the router back to factory settings. But you have to go through the setup again to get the right settings for your local network and internet service. So do this only if you have reason the think the router has been infected. If you Google Router Virus Removal You can find many recent posts and articles. Here is just one: http://forums.majorgeeks.com/showthread.php?t=213939 Here is another: http://forums.cnet.com/7723-7589_102-145685/virus-inside-router/ Does this help any? The router is hooked up to my desktop computer...Instead of using wireless, what if I used a Cat 5 cable and plugged my laptop directly into the router? Would a virus still be a risk?Yes, a virus of some type for form could enter either via cable or wireless. The greater danger is the PC itself. There are dozens of places a virus could hide in a PC. In the router, there is less space available for a virus to reside. Some say the more common problem is router 'poison' RATHER that a virus. A kind of MALWARE inside the PC alters the settings of the router without actually change the router program code. Here is a discussion about the most common router infection, Quote APR (ARP Poison Routing) is a main feature of the program. It enables sniffing on switched networks and the hijacking of IP traffic between hosts. The name "ARP Poison Routing" derives from the two steps needed to PERFORM such unusual network sniffing: an ARP Poison Attack and routing packets to the correct destination. ... This is of concern in complex networks.This is not a Virus and spyware removal topic. If it is, then please start a new topic, and you will receive help from a Malware Removal Specialist. The advice given in this thread is compromised, and should not be followed. For those untrained in malware removal and security basics should not be trusted with any advice. Topic closed! |
|
| 115. |
Solve : Computer Hijack Help? |
|
Answer» Looking for some help on getting CONTROL of my computer back!! I am currently getting fake security warnings and am unable to run ANY program with the message "application cannot be executed". I was trying to install some removal tools but safe mode will not let me, and I can do nothing after a normal boot. Any help/knowledge is greatly appreciated! |
|
| 116. |
Solve : Help removing infections? |
|
Answer» Hi everyone |
|
| 118. |
Solve : Run-time error '372'?? |
|
Answer» I believe this is a virus but it may be something wrong with the files on the computer. It may be tl;dr but I need to list all the details. |
|
| 119. |
Solve : Virus Keep Opening Websites...? |
|
Answer» Hey fellas,
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
============================== Please download Malwarebytes Anti-Malware from Malwarebytes.org. Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
There's some malwares detected but the problem still persist... I'll TRY the other one soon...Ok. Post the GMER log when you can.I have just restarted my computer and I'm not really sure why but the problem has been fixed My guess would be from the ComboFix... Thanks a lot fellas If the problem come up again in the future, I'll be sure to let you guys know...Umm...ok Please uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
|
|
| 120. |
Solve : ''File cannot be executed. The file ______ is infected.'' Problem? |
|
Answer» Hello,
Link #1 Link #2 Link #3
Then, please try to run the tools again.Log 1 HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-18 ProfileImagePath REG_EXPAND_SZ %systemroot%\system32\config\systemprofile HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-19 ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-20 ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3988202556-4294345629-2372359041-1003 ProfileImagePath REG_EXPAND_SZ C:\Users\Sean HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3988202556-4294345629-2372359041-1004 ProfileImagePath REG_EXPAND_SZ C:\Users\Kimmy HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-3988202556-4294345629-2372359041-1005 ProfileImagePath REG_EXPAND_SZ C:\Users\Mommy and Daddy ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\LocalService ProfileImagePath REG_EXPAND_SZ %SystemRoot%\ServiceProfiles\NetworkService SystemRoot REG_SZ C:\Windows Log 3 Cheetah-Anti-Rogue v1.4.1 by DragonMaster Jay Microsoft Windows [Version 6.0.6000] Date: 21/04/2010 - Time: 18:05:18 - Arch.: x86 -- Malware removal tools check -- User has Sandboxie installed! Sandboxie Malwarebytes' Anti-Malware SUPERAntiSpyware -- Known infection -- C:\Program Files\FunWebProducts (Adw.MyWebSearch) C:\Program Files\MyWebSearch (Adw.MyWebSearch) C:\Windows\system32\f3PSSavr.scr (Adw.MyWebSearch!3M) C:\Program Files\Windows Live\Messenger\riched20.dll (Adw.MyWebSearch) Extra message: Detection only. EOF The 2nd program STOPPED because it said that it cannot access C:\Windows\Syetem32\LogFiles\WMI\RtBackup\EtwRTDiaLog.et1 I am very thankful for your help, please advise me on what to do next. Please visit this webpage for a tutorial on downloading and running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix See the area: Using ComboFix, and when done, post the log back here.Here is the log ComboFix 10-04-21.01 - Sean 22/04/2010 1:41.1.2 - x86 Microsoft® Windows Vista™ Home PREMIUM 6.0.6000.0.1252.2.1033.18.1917.1152 [GMT -4:00] Running from: c:\users\Sean\Desktop\ComboFix.exe AV: avast! antivirus 4.8.1368 [VPS 100421-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: avast! antivirus 4.8.1368 [VPS 100421-1] *disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle.bin\S-1-5-21-1731352543-3892579127-1766459742-500 c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500 c:\program files\Cheat Engine\dbk32.sys c:\program files\mjc c:\program files\racle~1 c:\program files\Sakora c:\users\Kimmy\AppData\Local\Microsoft\Windows\Temporary Internet Files\CPV.stt c:\users\Mommy and Daddy\AppData\Local\Microsoft\Windows\Temporary Internet Files\CPV.stt c:\windows\curity~1 c:\windows\UA000106.DLL . ((((((((((((((((((((((((( Files Created from 2010-03-22 to 2010-04-22 ))))))))))))))))))))))))))))))) . 2010-04-22 05:55 . 2010-04-22 05:57--------d-----w-c:\users\Sean\AppData\Local\temp 2010-04-22 05:55 . 2010-04-22 05:55--------d-----w-c:\users\Default\AppData\Local\temp 2010-04-22 05:55 . 2010-04-22 05:55--------d-----w-c:\users\Mommy and Daddy\AppData\Local\temp 2010-04-22 05:55 . 2010-04-22 05:55--------d-----w-c:\users\Kimmy\AppData\Local\temp 2010-04-21 23:06 . 2010-04-21 23:06--------d-----w-c:\program files\Microsoft ATS 2010-04-21 12:13 . 2010-02-20 23:5424064----a-w-c:\windows\system32\nshhttp.dll 2010-04-21 12:13 . 2010-02-20 23:5131232----a-w-c:\windows\system32\httpapi.dll 2010-04-21 12:13 . 2010-02-20 21:30396800----a-w-c:\windows\system32\drivers\http.sys 2010-04-21 04:00 . 2009-10-19 14:42156672----a-w-c:\windows\system32\t2embed.dll 2010-04-21 04:00 . 2009-10-19 14:3924064----a-w-c:\windows\system32\lpk.dll 2010-04-21 04:00 . 2009-10-19 14:3772704----a-w-c:\windows\system32\fontsub.dll 2010-04-21 04:00 . 2009-10-19 14:3710240----a-w-c:\windows\system32\dciman32.dll 2010-04-21 04:00 . 2009-10-19 14:3634304----a-w-c:\windows\system32\atmlib.dll 2010-04-21 04:00 . 2009-10-19 11:45289792----a-w-c:\windows\system32\atmfd.dll 2010-04-21 04:00 . 2009-12-11 12:15306688----a-w-c:\windows\system32\drivers\srv.sys 2010-04-21 04:00 . 2009-12-11 12:1584992----a-w-c:\windows\system32\drivers\srvnet.sys 2010-04-21 03:58 . 2009-08-10 13:052048----a-w-c:\windows\system32\msxml6r.dll 2010-04-21 03:57 . 2009-08-31 15:16428032----a-w-c:\windows\system32\EncDec.dll 2010-04-21 03:57 . 2009-08-31 15:21292352----a-w-c:\windows\system32\psisdecd.dll 2010-04-21 03:57 . 2009-08-31 15:171244672----a-w-c:\windows\system32\mcmde.dll 2010-04-21 03:57 . 2010-01-23 08:052048----a-w-c:\windows\system32\tzres.dll 2010-04-21 03:55 . 2010-02-18 14:22167424----a-w-c:\windows\system32\tcpipcfg.dll 2010-04-21 03:55 . 2010-02-18 14:19179712----a-w-c:\windows\system32\iphlpsvc.dll 2010-04-21 03:55 . 2010-02-18 12:05815104----a-w-c:\windows\system32\drivers\tcpip.sys 2010-04-21 03:55 . 2010-02-18 12:0425088----a-w-c:\windows\system32\drivers\tunnel.sys 2010-04-21 03:55 . 2009-08-14 17:16213592----a-w-c:\windows\system32\drivers\netio.sys 2010-04-21 03:55 . 2010-02-18 12:0422016----a-w-c:\windows\system32\netiougc.exe 2010-04-21 03:55 . 2010-02-18 12:0415360----a-w-c:\windows\system32\drivers\TUNMP.SYS 2010-04-21 03:55 . 2009-08-14 14:012031104----a-w-c:\windows\system32\win32k.sys 2010-04-21 03:53 . 2009-12-28 12:3611776----a-w-c:\windows\system32\tsbyuv.dll 2010-04-21 03:53 . 2009-12-28 12:3422528----a-w-c:\windows\system32\msyuv.dll 2010-04-21 03:53 . 2009-12-28 12:3413312----a-w-c:\windows\system32\msrle32.dll 2010-04-21 03:53 . 2009-12-28 12:3250176----a-w-c:\windows\system32\iyuv_32.dll 2010-04-21 03:53 . 2009-12-28 12:34123904----a-w-c:\windows\system32\msvfw32.dll 2010-04-21 03:53 . 2009-12-28 12:3382944----a-w-c:\windows\system32\mciavi32.dll 2010-04-21 03:53 . 2009-12-28 12:3088576----a-w-c:\windows\system32\avifil32.dll 2010-04-21 03:53 . 2009-12-28 12:3065024----a-w-c:\windows\system32\avicap32.dll 2010-04-21 03:53 . 2009-04-02 11:50604672----a-w-c:\windows\system32\WMSPDMOD.DLL 2010-04-21 03:43 . 2009-09-10 15:29311296----a-w-c:\windows\system32\unregmp2.exe 2010-04-21 03:43 . 2009-09-10 17:404096----a-w-c:\windows\system32\dxmasf.dll 2010-04-21 03:43 . 2009-09-10 17:397680----a-w-c:\windows\system32\spwmp.dll 2010-04-21 03:43 . 2009-09-10 15:298147968----a-w-c:\windows\system32\wmploc.DLL 2010-04-21 03:41 . 2009-12-23 12:45171520----a-w-c:\windows\system32\wintrust.dll 2010-04-21 03:41 . 2010-01-13 18:2397792----a-w-c:\windows\system32\cabview.dll 2010-04-20 05:10 . 2010-04-20 05:1052224----a-w-c:\users\Sean\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll 2010-04-20 05:10 . 2010-04-20 05:10117760----a-w-c:\users\Sean\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL 2010-04-20 05:09 . 2010-04-20 05:09--------d-----w-c:\programdata\SUPERAntiSpyware.com 2010-04-20 05:08 . 2010-04-20 05:085120----a-r-c:\users\Sean\AppData\Roaming\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF16.exe 2010-04-20 05:08 . 2010-04-20 05:0865024----a-r-c:\users\Sean\AppData\Roaming\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe 2010-04-20 05:08 . 2010-04-20 05:0818944----a-r-c:\users\Sean\AppData\Roaming\Microsoft\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe 2010-04-20 05:07 . 2010-04-20 05:07--------d-----w-c:\program files\SUPERAntiSpyware 2010-04-20 05:07 . 2010-04-20 05:07--------d-----w-c:\users\Sean\AppData\Roaming\SUPERAntiSpyware.com 2010-04-20 04:55 . 2010-03-29 19:2438224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys 2010-04-20 04:55 . 2010-04-20 04:55--------d-----w-c:\programdata\Malwarebytes 2010-04-20 04:55 . 2010-04-20 04:55--------d-----w-c:\program files\Malwarebytes' Anti-Malware 2010-04-20 04:55 . 2010-03-29 19:2420824----a-w-c:\windows\system32\drivers\mbam.sys 2010-04-20 04:24 . 2010-04-20 04:2460672----a-w-c:\users\Sean\AppData\Local\syssvc.exe 2010-04-20 04:22 . 2010-04-20 22:35--------d-----w-c:\users\Sean\AppData\Local\wxkagtccy 2010-04-18 22:57 . 2010-04-18 22:57--------d-----w-c:\program files\FreeMind 2010-04-17 15:11 . 2010-04-17 15:11--------d-----w-c:\users\Sean\AppData\Roaming\XemiComputers 2010-04-17 15:11 . 2010-04-17 15:11--------d-----w-c:\program files\XemiComputers 2010-04-04 21:34 . 2010-04-04 21:3436400----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\ALWIL.dll 2010-04-04 21:34 . 2010-04-04 21:3433328----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\Microsoft Corporation.dll 2010-04-04 21:34 . 2010-04-04 21:3432304----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\MicrosoftAV.dll 2010-04-04 21:34 . 2010-04-04 21:34174592----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\64bitProxy.exe 2010-04-04 21:34 . 2010-04-04 21:34150064----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\FWManager.dll 2010-04-04 21:34 . 2010-04-04 21:3424112----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\AVManager.dll 2010-04-04 21:34 . 2010-04-04 21:34151088----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\OPSWATAVCommon.dll 2010-04-04 21:34 . 2010-04-04 21:3419120----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\libinspector.dll 2010-04-04 21:33 . 2010-04-04 21:3314512----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\libdesktop.dll 2010-04-04 21:33 . 2010-04-04 21:3347280----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco HostScan\bin\hostscan.exe 2010-04-04 21:33 . 2010-04-04 21:3329872----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco\Cisco Secure Desktop\Cache\Temp8-P00h\CSDWebLaunch.exe 2010-04-04 21:33 . 2010-04-04 21:33--------d-----w-c:\users\Mommy and Daddy\AppData\Roaming\Cisco 2010-04-04 03:10 . 2010-04-04 03:10509552----a-w-c:\programdata\Google\Google Toolbar\Update\gtb563C.tmp.exe 2010-04-02 05:28 . 2010-04-02 05:28--------d-----w-c:\users\Sean\AppData\Roaming\MPEG Streamclip 2010-03-31 06:00 . 2010-03-31 06:0086016----a-w-c:\windows\system32\frapsvid.dll 2010-03-25 03:16 . 2010-03-25 03:1648788----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\uninstallOctazen.exe 2010-03-25 02:34 . 2010-03-25 02:34--------d-----w-c:\users\Mommy and Daddy\AppData\Local\Smilebox 2010-03-25 02:34 . 2010-03-25 03:16--------d-----w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox 2010-03-25 02:34 . 2010-03-25 02:3459313----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\uninstall.exe . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-22 05:58 . 2009-11-16 03:55--------d-----w-c:\program files\Common Files\Akamai 2010-04-22 05:54 . 2009-12-17 22:04--------d-----w-c:\program files\Cheat Engine 2010-04-22 04:55 . 2009-04-29 02:29--------d-----w-c:\programdata\Google Updater 2010-04-22 03:48 . 2008-12-06 22:13--------d-----w-c:\users\Sean\AppData\Roaming\gtk-2.0 2010-04-21 22:58 . 2008-03-21 21:56--------d-----w-c:\program files\OGPlanet 2010-04-21 21:50 . 2008-03-22 09:21114936----a-w-c:\users\Sean\AppData\Local\GDIPFONTCACHEV1.DAT 2010-04-21 21:44 . 2009-11-15 22:43--------d-----w-c:\program files\Microsoft Silverlight 2010-04-21 13:00 . 2006-11-02 11:18--------d-----w-c:\program files\Windows Mail 2010-04-21 12:58 . 2007-09-02 11:39--------d-----w-c:\programdata\Microsoft Help 2010-04-21 12:29 . 2007-09-02 11:41--------d-----w-c:\program files\Microsoft Works 2010-04-21 12:18 . 2007-09-02 11:46--------d-----w-c:\program files\Microsoft SQL Server 2010-04-20 05:06 . 2008-11-28 02:17--------d-----w-c:\program files\Common Files\Wise Installation Wizard 2010-04-18 21:28 . 2008-04-12 21:33--------d-----w-c:\users\Sean\AppData\Roaming\LimeWire 2010-04-17 15:07 . 2008-04-28 00:13--------d-----w-c:\program files\Google 2010-04-16 21:54 . 2009-09-20 23:51--------d-----w-c:\users\Sean\AppData\Roaming\IObit 2010-04-09 22:57 . 2008-10-04 15:51--------d-----w-c:\users\Kimmy\AppData\Roaming\LimeWire 2010-04-05 18:10 . 2009-08-22 23:43--------d-----w-c:\program files\Counter-Strike Source 2010-04-05 15:14 . 2009-09-06 20:29--------d-----w-c:\program files\IObit 2010-04-02 18:35 . 2008-10-01 01:53--------d-----w-c:\users\Sean\AppData\Roaming\Publish Providers 2010-03-09 19:15 . 2010-02-17 21:05287368----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxTray.exe 2010-03-09 16:50 . 2010-04-21 03:5552736----a-w-c:\windows\AppPatch\iebrshim.dll 2010-02-24 14:16 . 2009-10-03 06:29181632------w-c:\windows\system32\MpSigStub.exe 2010-02-24 06:48 . 2008-06-13 01:10--------d-----w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire 2010-02-24 03:00 . 2010-02-24 03:0020480----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll 2010-02-24 03:00 . 2010-02-24 03:0018944----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll 2010-02-24 03:00 . 2010-02-24 03:0017408----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll 2010-02-24 03:00 . 2010-02-24 03:008192----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll 2010-02-24 03:00 . 2010-02-24 03:0020480----a-w-c:\users\Mommy and Daddy\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll 2010-02-23 20:46 . 2010-03-11 14:37419040----a-w-c:\windows\system32\WMInstallMgrUninst.exe 2010-02-23 20:46 . 2010-03-11 14:3762688----a-w-c:\windows\system32\WMWebLauncherUninst.exe 2010-02-23 20:46 . 2010-03-11 14:37255200----a-w-c:\windows\system32\SystemObserver.dll 2010-02-23 20:46 . 2010-03-11 14:3754496----a-w-c:\windows\system32\GetInfoLauncher.exe 2010-02-23 13:14 . 2010-04-21 03:58211968----a-w-c:\windows\system32\drivers\mrxsmb10.sys 2010-02-23 13:14 . 2010-04-21 03:5858368----a-w-c:\windows\system32\drivers\mrxsmb20.sys 2010-02-23 13:14 . 2010-04-21 03:58102400----a-w-c:\windows\system32\drivers\mrxsmb.sys 2010-02-19 23:47 . 2010-02-19 23:473604480----a-w-c:\windows\system32\GPhotos.scr 2010-02-18 14:54 . 2010-04-21 03:583502480----a-w-c:\windows\system32\ntkrnlpa.exe 2010-02-18 14:54 . 2010-04-21 03:583468168----a-w-c:\windows\system32\ntoskrnl.exe 2010-02-17 21:05 . 2010-02-18 00:50397960----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxStarter.exe 2010-02-17 21:05 . 2010-02-18 00:10168584----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxBrowserEngine.dll 2010-02-17 21:05 . 2010-02-17 21:05217736----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxDvd.exe 2010-02-17 20:50 . 2010-02-17 20:501602184----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxClient.exe 2010-02-17 20:10 . 2010-02-17 20:10344712----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxDvdEngine.dll 2010-02-17 20:10 . 2010-02-17 20:10135816----a-w-c:\users\Mommy and Daddy\AppData\Roaming\Smilebox\SmileboxUpdater.exe 2010-02-11 03:16 . 2010-02-11 03:1641872----a-w-c:\windows\system32\xfcodec.dll 2010-01-30 17:41 . 2010-01-30 17:41282624----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\websrvcs.dll 2010-01-30 17:41 . 2010-01-30 17:41200704----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\transformiix.dll 2010-01-30 17:41 . 2010-01-30 17:4115872----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\xmlextras.dll 2010-01-30 17:41 . 2010-01-30 17:41110592----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\universalchardet.dll 2010-01-30 17:41 . 2010-01-30 17:4119968----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\pippki.dll 2010-01-30 17:41 . 2010-01-30 17:41225280----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\pipnss.dll 2010-01-30 17:41 . 2010-01-30 17:4120992----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\pipboot.dll 2010-01-30 17:41 . 2010-01-30 17:4120480----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\autoconfig.dll 2010-01-30 17:41 . 2010-01-30 17:4118944----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\appshell_modal.dll 2010-01-30 17:41 . 2010-01-30 17:4117408----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\components\auth.dll 2010-01-30 17:41 . 2010-01-30 17:418192----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\AccessibleMarshal.dll 2010-01-30 17:41 . 2010-01-30 17:4120480----a-w-c:\users\Sean\AppData\Roaming\LimeWire\browser\xulrunner\IA2Marshal.dll 2010-01-25 12:58 . 2010-04-21 03:54473088----a-w-c:\windows\system32\secproc_isv.dll 2010-01-25 12:58 . 2010-04-21 03:54154624----a-w-c:\windows\system32\secproc_ssp_isv.dll 2010-01-25 12:58 . 2010-04-21 03:54154112----a-w-c:\windows\system32\secproc_ssp.dll 2010-01-25 12:58 . 2010-04-21 03:54472576----a-w-c:\windows\system32\secproc.dll 2010-01-25 12:56 . 2010-04-21 03:54312320----a-w-c:\windows\system32\msdrm.dll 2010-01-25 08:36 . 2010-04-21 03:54435712----a-w-c:\windows\system32\RMActivate_ssp.exe 2010-01-25 08:36 . 2010-04-21 03:54515584----a-w-c:\windows\system32\RMActivate.exe 2010-01-25 08:36 . 2010-04-21 03:54431104----a-w-c:\windows\system32\RMActivate_ssp_isv.exe 2010-01-25 08:35 . 2010-04-21 03:54523776----a-w-c:\windows\system32\RMActivate_isv.exe . ------- Sigcheck ------- [-] 2009-03-30 . 74B6336C7ACC815483C2399BDD53EFCC . 245248 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll [7] 2008-01-19 . 27F10F348E508243F6254846F8370D0D . 247296 . . [6.0.6001.18000] . . c:\windows\SoftwareDistribution\Download\b2ee164db645e6bc8d77bb51f082e3b3\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6001.18000_none_cd305d2a1ced96e2\shsvcs.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}] 2008-09-29 21:24325000----a-w-c:\program files\AskBarDis\bar\bin\askBar.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-09-29 325000] [HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}] [HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Google Update"="c:\users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe" [2008-08-29 133104] "Pando Media Booster"="c:\program files\Pando Networks\Media Booster\PMB.exe" [2009-10-17 2920632] "cdloader"="c:\users\Sean\AppData\Roaming\mjusbsp\cdloader2.exe" [2009-08-01 50520] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-10 39408] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2007-08-23 1006264] "TPwrMain"="c:\program files\TOSHIBA\Power Saver\TPwrMain.EXE" [2007-03-29 411192] "HSON"="c:\program files\TOSHIBA\TBS\HSON.exe" [2006-12-07 55416] "SmoothView"="c:\program files\Toshiba\SmoothView\SmoothView.exe" [2007-06-16 448080] "00TCrdMain"="c:\program files\TOSHIBA\FlashCards\TCrdMain.exe" [2007-05-22 538744] "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-12-17 149280] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-11-12 141600] "GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072] c:\users\Kimmy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-12-16 503808] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Mises … jour planifi‚es.lnk - c:\program files\Quicken\bagent.exe [2003-4-18 53248] M‚mento Quicken.lnk - c:\program files\Quicken\billmind.exe [2003-4-18 36864] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 19:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" R2 gupdate1c9c8726becfc2b;Google Update Service (gupdate1c9c8726becfc2b);c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 133104] R2 mrtRate;mrtRate; R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-03-15 2804788] R3 XDva189;XDva189;c:\windows\system32\XDva189.sys R3 XDva193;XDva193;c:\windows\system32\XDva193.sys R3 XDva202;XDva202;c:\windows\system32\XDva202.sys R3 XDva309;XDva309;c:\windows\system32\XDva309.sys S1 aswSP;avast! Self Protection; S1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2010-02-17 12872] S1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2010-02-17 66632] S2 Akamai;Akamai NetSession Interface;c:\windows\System32\svchost.exe [2006-11-02 22016] S2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2009-11-24 20560] S2 aswMonFlt;aswMonFlt;c:\windows\system32\DRIVERS\aswMonFlt.sys [2009-11-24 53328] S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [2006-11-20 7168] S3 RTL8187B;Realtek RTL8187B Wireless 802.11g 54Mbps USB 2.0 Network Adapter;c:\windows\system32\DRIVERS\RTL8187B.sys [2007-06-01 252416] S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2010-02-17 12872] S3 SCREAMINGBDRIVER;Screaming Bee Audio;c:\windows\system32\drivers\ScreamingBAudio.sys [2009-04-06 23064] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] AkamaiREG_MULTI_SZ Akamai . Contents of the 'Scheduled Tasks' folder 2010-04-22 c:\windows\Tasks\Google Software Updater.job - c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-10 02:29] 2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 02:30] 2010-04-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-29 02:30] 2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3988202556-4294345629-2372359041-1003Core.job - c:\users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe [2008-07-11 23:46] 2010-04-22 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3988202556-4294345629-2372359041-1003UA.job - c:\users\Sean\AppData\Local\Google\Update\GoogleUpdate.exe [2008-07-11 23:46] 2010-04-22 c:\windows\Tasks\User_Feed_Synchronization-{D3E6FF0B-1889-4DA0-85D0-4DB5C614576B}.job - c:\windows\system32\msfeedssync.exe [2010-04-21 11:31] . . ------- Supplementary Scan ------- . mStart PAGE = hxxp://www.shoptoshiba.ca/welcome uInternet Settings,ProxyOverride = uInternet Settings,PROXYSERVER = http=127.0.0.1:5555 DPF: {87A638DE-396F-40FD-A2F8-01B56072F553} - hxxp://download.gemfighter.com/launcher/gemx2.cab DPF: {BD68328E-1222-4A62-BA16-E6F42CA49A64} - hxxp://gf.wemade.com/comsso/active/WMInstallMgr.cab FF - ProfilePath - c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\yq7b81t9.default\ FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2260173&SearchSource=3&q={searchTerms} FF - prefs.js: browser.search.selectedEngine - MyWebSearch FF - prefs.js: browser.startup.homepage - hxxp://login.live.com/login.srf?wa=wsignin1.0&rpsnv=11&ct=1265259818&rver=6.0.5285.0℘=MBI&wreply=http:%2F%2Fmail.live.com%2Fdefault.aspx&lc=1033&id=64855&mkt=en-us FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101757&gct=&gc=1&q= FF - component: c:\users\Sean\AppData\Roaming\Mozilla\Firefox\Profiles\yq7b81t9.default\extensions\{8bdea9d6-6f62-45eb-8ee9-8a81af0d2f94}\components\FFExternalAlert.dll FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll FF - plugin: c:\program files\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll FF - plugin: c:\users\Sean\AppData\Local\Google\Update\1.2.183.23\npGoogleOneClick8.dll FF - plugin: c:\users\Sean\Program Files\DNA\plugins\npbtdna.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ ---- FIREFOX POLICIES ---- FF - user.js: browser.cache.memory.capacity - 65536 FF - user.js: browser.chrome.favicons - fales FF - user.js: browser.display.show_image_placeholders - true FF - user.js: browser.turbo.enabled - true FF - user.js: browser.urlbar.autocomplete.enabled - true FF - user.js: browser.urlbar.autofill - true FF - user.js: browser.xul.error_pages.enabled - true FF - user.js: content.interrupt.parsing - true FF - user.js: content.max.tokenizing.time - 3000000 FF - user.js: content.maxtextrun - 8191 FF - user.js: content.notify.backoffcount - 5 FF - user.js: content.notify.interval - 750000 FF - user.js: content.notify.ontimer - true FF - user.js: content.switch.threshold - 750000 FF - user.js: network.http.max-connections - 32 FF - user.js: network.http.max-connections-per-server - 8 FF - user.js: network.http.max-persistent-connections-per-proxy - 8 FF - user.js: network.http.max-persistent-connections-per-server - 4 FF - user.js: network.http.pipelining - true FF - user.js: network.http.pipelining.firstrequest - true FF - user.js: network.http.pipelining.maxrequests - 8 FF - user.js: network.http.proxy.pipelining - true FF - user.js: network.http.request.max-start-delay - 0 FF - user.js: nglayout.initialpaint.delay - 0 FF - user.js: plugin.expose_full_path - true FF - user.js: ui.submenuDelay - 0 . - - - - ORPHANS REMOVED - - - - AddRemove-Fraps - c:\users\Sean\Desktop\Fraps\uninstall.exe ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-04-22 01:57 Windows 6.0.6000 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... c:\windows\TEMP\TMP0000006CE42FA671EAFB0412 524288 bytes executable scan completed successfully hidden files: 1 ************************************************************************** [HKEY_LOCAL_MACHINE\system\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- LOCKED REGISTRY KEYS --------------------- [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . Completion time: 2010-04-22 02:02:22 ComboFix-quarantined-files.txt 2010-04-22 06:02 Pre-Run: 45,322,604,544 bytes free Post-Run: 47,394,820,096 bytes free - - End Of File - - 73F15F2102F69EBC06AE56A8CCC8FBE8 Please download Malwarebytes Anti-Malware from Malwarebytes.org. Alternate link: BleepingComputer.com. (Note: if you already have the program installed, just follow the directions. No need to re-download or re-install!) Double Click mbam-setup.exe to install the application. (Note: if you already have the program installed, open Malwarebytes from the Start Menu or Desktop shortcut, click the Update tab, and click Check for Updates, before doing the scan as instructed below!)
GMER Note about this tool:
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan. Double-click gmer.exe. The program will begin to run. **Caution** These types of scans can produce false positives. Do NOT take any action on any "<--- ROOKIT" entries unless advised! If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
|
|
| 121. |
Solve : vista blue screen, crashes? |
|
Answer» I ran the sfc scan and it read there were corrup files and was unable to fix some of them. Computer didn't come with any disks, but I DOWNLOADED 2 recovery factory default disc and 1 DRIVER and APPLICATION backup disc from the computer. Do I need to use these on the computer? Also will I lose everthing on the computer? Again I appreciate all your help. Quote Computer didn't come with any disks, but I downloaded 2 recovery factory default disc and 1 driver and application backup disc from the computer. Do I need to use these on the computer? Also will I lose everthing on the computer?You should be able to use the Recovery Disks to repair the corrupted files and it will not harm the other data on your computer if you just do a Repair. If you do a full Recovery it will take your computer back to the day it was purchased.How do I do just repair. When I loaded first recovery disk it read full recovery or EXIT, there wasn't an option for repair. Also do I use the application disk? ThanksQuote How do I do just repair. When I loaded first recovery disk it read full recovery or exit, there wasn't an option for repair. Also do I use the application disk? ThanksAlmost every recovery disk is made differently so I'm not sure without looking at the disk. You may have do save your important data and do a complete recovery.Thank you for all of your help, I greatly appreciate it. I ended up restoring the whole computer, at least it runs a lot better. Again I want to thank you (learned a lot)You're welcome. I will lock this thread. If you need it re-opened, please send me a PM. |
|
| 122. |
Solve : File cannot be executed. The file ______ is infected.? |
|
Answer» I figured since I was having the same problem I would just post here instead of cluttering up the boards with the same problem. I hope you can help DragonMaster Jay. |
|
| 123. |
Solve : hijackthislog? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.3 (BETA) |
|
| 124. |
Solve : Valdr's problem.? |
|
Answer» windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1263093828140O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1265594445281... I know you guys don't like this but... bump. any IDEA whats going on? I still can't post that from my hjt in ONE post. i'm still getting a random NEW tab popup in firefox. |
|
| 125. |
Solve : Virus infection- Please help.? |
|
Answer» Well, after your last message I went into normal mode, and its fine. Was even able to get ONLINE. |
|
| 126. |
Solve : (F-secure) Sirefef.HC, Sirefef.HD? |
|
Answer» Shall we look for Sirefef or end topic?It's been exactly a week since I removed Sirefef.HC, and it hasn't returned yet, so I'd SAY it's highly UNLIKELY it'll come back. |
|
| 127. |
Solve : Don't know what's wrong..? |
|
Answer» Somehow it says i have a virus but it's from those pop ups that aren't from the anti-virus programs that i have installed and they want me to pay for their services so i think they are shady. |
|
| 128. |
Solve : Rogue Security Software? |
|
Answer» Hello: |
|
| 129. |
Solve : Dell Vostro with Sirefef.ah rebooting within 90 seconds of boot.? |
|
Answer» Spybot found and fixed 2 things Casale-media & DoubleClick. Spybot found and fixed 2 things Casale-media & DoubleClick.Yes, unless SOMETHING else comes up. You might also KEEP SAS and MBAM, if you wish. Update them and run them on a regular basis.Thank you so much. Will do on the suggestions. Quote from: dschoellkopf on June 28, 2012, 09:02:49 PM Thank you so much. Will do on the suggestions.You're WELCOME. I will lock this THREAD. If you need it re-opened, please send me a pm. |
|
| 130. |
Solve : Need help with an unknown infection.? |
|
Answer» Re-run MBAM:
by swatkat ****************************************************************************************** ****************************************************************************************** No Hidden Processes found ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys Service Name: --- Module Base: F563D000 Module End: F5655000 Hidden: Yes Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS Service Name: --- Module Base: F7C5D000 Module End: F7C5F000 Hidden: Yes ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ****************************************************************************************** Hidden files/folders: Object: C:\Documents and Settings\All Users\Application Data\Google\Google Toolbar\Update\ Status: Hidden Object: C:\Program Files\AVG\AVG2012\ Status: Hidden Object: C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\8.0.1\ Status: Hidden Object: C:\Program Files\Google\Common\Google Updater\ Status: Hidden Object: C:\Program Files\Google\Update\ Status: Hidden Object: C:\Program Files\Java\jre6\bin\ Status: Hidden Object: C:\Qoobox\BackEnv\AppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cache.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Cookies.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Desktop.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Favorites.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\History.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Music.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\NetHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Personal.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Pictures.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\PrintHood.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Programs.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\Recent.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SendTo.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SetPath.bat Status: Access denied Object: C:\Qoobox\BackEnv\StartMenu.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\StartUp.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\SysPath.dat Status: Access denied Object: C:\Qoobox\BackEnv\Templates.folder.dat Status: Access denied Object: C:\Qoobox\BackEnv\VikPev00 Status: Access denied How's your computer running now? I'd like to scan your machine with ESET OnlineScan •Hold down Control and click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan •Click the button. •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
•Click the button. •Accept any security warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Super Dave, After the online scan, it gave me 2 options (optional) if i desired before clicking finished. 1st was delete eset from your computer. The 2nd was delete threat files. Based on the log, it appears they were deleted, I didnt choose either of them options as your instructions didnt mention to. As ar as the computers performance goes, its defitnely running a bit better. Last night the start menu>accessories reappeared. Previsouly it was mia ubder the start menu. Before getting assistance with you on this site, I was informed to run msinfo32. At that time nothing happened when i typed it in run. So that led me to services > help and support. I tried to manually start the service and got an error. Ive just tried both of those options again with the exact same result. Nothing comes up when i type in run>msinfo32 and i get an error when trying to start help and support in services. Im not sure if the help and support was damaged by the infection, but thought this info might help. Also I have pending windows updates Ive yet to install because I didnt want to change anything while weve been working at this. Is it safe to do so now? A pop up to upgrade to internet explorer 8 keeps coming up, but according to i.e, im already running i.e 8? The contexual toolbar which was in add/remove programs previously alerted me with threat detections (from avg) everytime i attempted to uninstall it from there. That tool bar is now gone from the add/remove programs which according to a google search, it was not a good file for my computer! Other than that, anything else I can take a look at to see if computer is indeed running better? Thanks A MILLION! C:\Documents and Settings\donnakeller\Desktop\music\boom boom boom (rare track).snda variant of WMA/TrojanDownloader.GetCodec.gen trojancleaned - quarantined C:\Documents and Settings\donnakeller\Desktop\music\boom boom came out in 2009 greatest hit 2009.wmaprobably a variant of Win32/Agent.CFDFCZI trojancleaned by deleting - quarantined C:\Documents and Settings\donnakeller\Desktop\music\prom queen lil wanye 2009.mp3a variant of WMA/TrojanDownloader.GetCodec.gen trojancleaned - quarantined C:\Program Files\vShare\imedix-silent.exeWin32/Toolbar.Zugo applicationdeleted - quarantined C:\System Volume Information\_restore{B5B2433D-7C5E-4FF8-8417-FE18E7328867}\RP1\A0000006.exeWin32/InstallBrain applicationcleaned by deleting - quarantined C:\System Volume Information\_restore{B5B2433D-7C5E-4FF8-8417-FE18E7328867}\RP19\A0006180.exeWin32/Toolbar.Zugo applicationdeleted - quarantined C:\TDSSKiller_Quarantine\02.04.2012_20.31.37\mbr0000\tdlfs0000\tsk0007.dtaa variant of Win32/Olmasco.O trojancleaned by deleting - quarantined C:\TDSSKiller_Quarantine\02.04.2012_20.31.37\mbr0000\tdlfs0000\tsk0010.dtaWin64/Olmasco.R trojancleaned by deleting - quarantined C:\TDSSKiller_Quarantine\02.04.2012_20.31.37\mbr0000\tdlfs0000\tsk0011.dtaa variant of Win32/Olmasco.Q trojancleaned by deleting - quarantined Update: Shortly after posting my previous reply msinfo32 did come up, but it took some time to do so. Help and support also came up, but under services is still saying its stopped. When i try to start it, I still get error message. ThanksQuote Also I have pending windows updates Ive yet to install because I didnt want to change anything while weve been working at this. Is it safe to do so now? A pop up to upgrade to internet explorer 8 keeps coming up, but according to i.e, im already running i.e 8? The contexual toolbar which was in add/remove programs previously alerted me with threat detections (from avg) everytime i attempted to uninstall it from there. That tool bar is now gone from the add/remove programs which according to a google search, it was not a good file for my computer! Other than that, anything else I can take a look at to see if computer is indeed running better?Yes, go ahead and get your updates. After that is done we can do some cleanup. As for msinfo32, it is just information about your computer. Not needed. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Update Your Java (JRE) Old versions of Java have vulnerabilities that malware can use to infect your system. First Verify your Java Version If there are any other version(s) installed then update now. Get the new version (if needed) If your version is out of date install the newest version of the Sun Java Runtime Environment. Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update. Be sure to close ALL open web browsers before starting the installation. Remove any old versions 1. Download JavaRa and unzip the file to your Desktop. 2. Open JavaRA.exe and choose Remove Older Versions 3. Once complete exit JavaRA. Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer. ******************************************************* Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. **************************************************** Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. ***************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online SCAMS, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you INTERACT with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing!Super Dave, I cant THANK you ENOUGH! Computer appears clean and is running like it should be!!!!!! I followed all steps My final question, and then you can lock this thread. Am I to delete the sysprot folder, TDSKILLER, ANTI-MALLWARE BYTES, SPYWARE SWEEPER along with all the setup files for the other programs that I wont be keeping? Are all the logs now safe to delete? Thanks!Quote Am I to delete theIf I were you the only two I would keep is SAS and MBAM. Update them and run them on a regular basis. Uninstall/delete all the rest. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. |
|
| 131. |
Solve : Security Essentials detected the Win32/sirefef.AC and .AH? |
|
Answer» Please run SysProt-AntiRootkit and post the log.
•Click the button. •Accept any SECURITY warnings from your browser. •Check •Push the Start button. •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. •When the scan completes, push •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. •Push the button. •Push A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt Sysrot crashed during the scan and threw up an error involving these files C:\Users\Bradley Adam\AppData\Local\Temp\WER7655.tmp.version.txt C:\Users\Bradley Adam\AppData\Local\Temp\WER8C84.tmp.appcompat.txt C:\Users\Bradley Adam\AppData\Local\Temp\WER8C85.tmp.mdmp It did produce a log file SysProt AntiRootkit v1.0.1.0 by swatkat ****************************************************************************************** ****************************************************************************************** Process: Name: C:\Windows\System32\PING.EXE PID: 5220 Hidden: Yes Window Visible: No Name: C:\Windows\System32\PING.EXE PID: 1692 Hidden: Yes Window Visible: No Name: C:\Windows\System32\PING.EXE PID: 708 Hidden: Yes Window Visible: No ****************************************************************************************** ****************************************************************************************** Kernel Modules: Module Name: \SystemRoot\System32\Drivers\dump_iaStor.sys Service Name: --- Module Base: 8F008000 Module End: 8F0D6000 Hidden: Yes ****************************************************************************************** ****************************************************************************************** No SSDT Hooks found ****************************************************************************************** ****************************************************************************************** No Kernel Hooks found ****************************************************************************************** ******************************************************************************************ok ran eset online and the log is below C:\Documents and Settings\Bradley Adam\Music\iTunes\iTunes Media\Mobile Applications\Fango 53.ipaJS/Exploit.CVE-2011-1250.A trojandeleted - quarantined C:\Windows\System32\drivers\cdrom.sysWin32/Sirefef.DA trojanunable to clean Operating memoryWin32/Sirefef.DN trojan Regards Brad * Go to Start > Run and type mrt.exe then press Enter on the keyboard). * (Vista and Windows 7 users go to Start and type mrt.exe in the search box then press Enter on the keyboard. * Click Next. * Choose Full Scan and click Next. * Once the scan is FINISHED click View detailed results of the scan. Look through the list and let me know if anything was found infected.ran mrt scan and it reported no malicous software detected. Google opens a new window now if I open one of my favourite SITES up Regards Brad Quote Google opens a new window now if I open one of my favourite sites up Does that mean the it's working properly now?Sorry, yes all is good, Thank you for your help. That's good news. Now we can do some cleanup. To set a new Restore Point. Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection. If you are prompted for an ADMINISTRATOR password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode. Click the Start button , click Control Panel, click System and Maintenance, and then click System. In the left pane, click System Protection. If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK. This will give you a new, clean Restore Point. ********************************************************** Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. ******************************************************** Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! |
|
| 132. |
Solve : Please help - www.searchnu.com/406 virus has infected my computer? |
| Answer» THANK you so very MUCH. You GUYS are TRULY AWESOME. | |
| 133. |
Solve : virus resource hog-Need help with removing it? |
|
Answer» Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive PROTECTORS such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
|
|
| 134. |
Solve : Windows explorer error on boot? |
|
Answer» Usually on the first boot of the day, I get the "Windows Explorer has encountered an error and needs to close" statement. I researched previous entries on the topic, and found an old one from 2008, which pointed to a malware problem.
(Note: Make sure there's a space between the WORD ComboFix and the forward-slash.)
This thread can be closed now. |
|
| 135. |
Solve : HJT Report? |
|
Answer» I've just run HJT. |
|
| 136. |
Solve : Is this a spyware/malware/virus problem? Problem shutting down? |
|
Answer» I'm not seeing anything to indicate a malware issue. |
|
| 137. |
Solve : Keyboard wont work after malware? |
|
Answer» I am running Win XP. I opened my computer this afternoon and the screen was full of malware saying my computer was INFECTED and buy thier removal tool. I could not open any programs or even use the keyboard. I restarted in safe mode and did a system restore for 2 days AGO and everything looks OK except the keyboard wont work. The lights come on but none of the keys will work. Some of the hot buttons work. The board will work in CMOS but not when windows loads. I have uninstalled through the device manager and keyboard in control panel and restarted. There is a screen that says that computer has detected new hardware and so I want to install, I click yes reboot and it is still x'ed out in device manager and won't work. I did troubleshoot and get this. |
|
| 138. |
Solve : Need help with possible malware infection? |
|
Answer» As of this morning, my computer has shown some odd symptoms while in normal mode:
Be sure to restart the computer after uninstalling everything. Can you update Malwarebytes now and run a new scan? I kept Avast and uninstalled everything except for Comodo, since that is the firewall that I use. After I restarted the computer nothing changed. I still can't update the definitions for MalwareBytes or SAS. If you already have ComboFix be sure to delete it and download a new copy. Download ComboFix© by sUBs from one of the below links. Be sure to save it to the Desktop. Link #1 Link #2 **Note: It is important that it is saved directly to your Desktop Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix. Temporarily disable your antivirus and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them. Double click combofix.exe & follow the prompts. When finished ComboFix will produce a log for you. Post the ComboFix log in your next reply. Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall. Remember to re-enable your antivirus and antispyware protection when ComboFix is complete. If you have problems with ComboFix usage, see How to use ComboFixOddly enough, it seems as if everything went back to normal on my computer last night. In normal mode, I am now able to connect to the internet, open programs and icons, update my Java, and update all my definitions for SAS, Malwarebytes, etc. It did this once I removed the other programs you suggested. I tried running ComboFix but it stalled toward the end. I guess I can try running it again. If you think I should do scans with SAS and Malwarebytes again since I updated the definitions I will do that. See if Combofix created a log. It will be located in C:\combofix.txt |
|
| 139. |
Solve : Open With Problem 2? |
|
Answer» Hi Dave, Did the ESET scan which returned no threats but it didn't give me the option to save a report it only gave the option to either uninstal it or close it. No threats is good news. When that happens, it doesn't produce a log. I never did find out what your original problem was with your computer. Is it working any better now?Hi Dave, The computer seems to be working perfectly and I think, better than ever so than you so much for your brilliant support, I really appreciate it. Obvioulsy I should be running anti viurs software (which I am) but what else would you recommend I install to keep the computer safe and running well. Cheers DavidQuote The computer seems to be working perfectly and I think, better than ever so than you so much for your brilliant support, I really appreciate it.Your Welcome. I'm glad I was able to help. Now it's time for some cleanup. You can uninstall HJT. You may keep SAS, MBAM and ESET if you wish. Update SAS and MBAM and run them on a regular basis. If you don't want to keep ESET, just delete it. To uninstall ComboFix
(Note: Make sure there's a space between the word ComboFix and the forward-slash.)
Clean out your temporary internet files and temp files. Download TFC by OldTimer to your desktop. Double-click TFC.exe to run it. Note: If you are running on Vista, right-click on the file and choose Run As Administrator TFC will close all programs when run, so make sure you have saved all your work before you begin. * Click the Start button to begin the cleaning process. * Depending on how often you clean temp files, execution time should be ANYWHERE from a few seconds to a minute or two. * Please let TFC run uninterrupted until it is finished. Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning. =============================== Looking over your log it seems you don't have any evidence of a third party firewall. Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors. Remember only install ONE firewall 1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one) 2) Online Armor 3) Agnitum Outpost 4) PC Tools Firewall Plus If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time. =============================== Use the Secunia Software Inspector to check for out of date software. •Click Start Now •Check the box next to Enable thorough system inspection. •Click Start •Allow the scan to finish and scroll down to see if any updates are needed. •Update anything listed. . ---------- Go to Microsoft Windows Update and get all critical updates. ---------- I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly. Safe Surfing! I also forgot to mention that you already have MicroSoft Malicious software removal Tool on your computer. Just go to run, and type in mrt.exe to run the scans. It doesn't produce a log so I never use to clean other computer but I use it on both my computers. If it's not there, you can download from the MS download site. |
|
| 140. |
Solve : Trojan problem? |
|
Answer» Hi, here the log, but I have a quetion: I must to create a clean restore point and then to get rid it? Or the second part is only an example? Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.You will not get rid of the new one you create. Whenever you get rid of the System Restore points, it always leaves one just in case. So, by creating a new one, then purging the old ones, you will be clean and have a fresh restore point. =============== Please download the newest version of Adobe Acrobat Reader from Adobe.com Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable. Go to the Control Panel and enter Add or Remove Programs (Programs and FEATURES in Vista/7). Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them. Once old versions are gone, please install the newest version. ================ Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection. Software recommendations Firewall
Resident Protection help A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them. Rogue programs help There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here: http://www.spywarewarrior.com/rogue_anti-spyware.htm Securing your computer
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option. If you are interested:
HaolitYou're welcome. Since this appears to be resolved, this topic is now closed. Glad we could help! =>CLOSED |
|
| 141. |
Solve : multiple virus,? |
|
Answer» although I have norton 360/spybot/ccleaner/etc they still got in. have to many to list but will try and attached loLogfile of Trend Micro HijackThis v2.0.2
|
|
| 142. |
Solve : antivirus soft virus...? |
|
Answer» I have the ANTIVIRUS soft virus. where it prompts you to buy the software to get rid of various viruses that it says it found on my laptop. i was unable to do anything with my laptop (because it kept saying that everything i tried to run was infected) until i changed my startup programs. then i was able to follow the directions in "Read this before requesting malware removal help" post. now i am posting the logs.
[Saving space, attachment deleted by admin]Please download Profiles by noahdfear.
=>CLOSED |
|
| 143. |
Solve : Not sure if i have a virus or something? |
|
Answer» Ok. First, we'll work on the internet connection problem which will probably solve the other problem.
************************************************************* Please download Farbar Service Scanner and run it on the computer with the issue.
Ran by Michal (administrator) on 19-04-2012 at 19:38:49 Windows 7 Ultimate (X64) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset set global popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : Michal-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Local Area Connection: Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller Physical Address. . . . . . . . . : 1C-6F-65-44-BD-7C DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::49dc:6bd9:c334:af66%13(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.0.14(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : Thursday, April 19, 2012 11:53:21 AM Lease Expires . . . . . . . . . . : Friday, April 20, 2012 2:22:41 PM Default Gateway . . . . . . . . . : 192.168.0.1 DHCP Server . . . . . . . . . . . : 192.168.0.1 DHCPv6 IAID . . . . . . . . . . . : 320630629 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-28-B3-BF-1C-6F-65-44-BD-7C DNS Servers . . . . . . . . . . . : 209.18.47.61 209.18.47.62 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.{AB9A3967-9594-4881-8F89-5FD219C10889}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: dns-cac-lb-01.rr.com Address: 209.18.47.61 Name: google.com Addresses: 74.125.228.64 74.125.228.65 74.125.228.66 74.125.228.67 74.125.228.68 74.125.228.69 74.125.228.70 74.125.228.71 74.125.228.72 74.125.228.73 74.125.228.78 Pinging google.com [72.14.204.138] with 32 bytes of data: Reply from 72.14.204.138: bytes=32 time=36ms TTL=54 Reply from 72.14.204.138: bytes=32 time=23ms TTL=54 Ping statistics for 72.14.204.138: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 23ms, Maximum = 36ms, Average = 29ms Server: dns-cac-lb-01.rr.com Address: 209.18.47.61 Name: yahoo.com Addresses: 98.139.183.24 209.191.122.70 72.30.38.140 Pinging yahoo.com [209.191.122.70] with 32 bytes of data: Reply from 209.191.122.70: bytes=32 time=76ms TTL=51 Reply from 209.191.122.70: bytes=32 time=59ms TTL=51 Ping statistics for 209.191.122.70: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 59ms, Maximum = 76ms, Average = 67ms Server: dns-cac-lb-01.rr.com Address: 209.18.47.61 Name: bleepingcomputer.com Address: 208.43.87.2 Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data: Reply from 208.43.87.2: Destination host unreachable. Reply from 208.43.87.2: Destination host unreachable. Ping statistics for 208.43.87.2: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 13...1c 6f 65 44 bd 7c ......Realtek PCIe GBE Family Controller 1...........................Software Loopback Interface 1 11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.14 20 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.0.0 255.255.255.0 On-link 192.168.0.14 276 192.168.0.14 255.255.255.255 On-link 192.168.0.14 276 192.168.0.255 255.255.255.255 On-link 192.168.0.14 276 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.0.14 276 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.0.14 276 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 13 276 fe80::/64 On-link 13 276 fe80::49dc:6bd9:c334:af66/128 On-link 1 306 ff00::/8 On-link 13 276 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Event log errors: =============================== Application errors: ================== Error: (04/19/2012 07:42:32 PM) (Source: Windows Search Service) (USER: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:38:31 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:34:29 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:30:27 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:26:26 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:22:25 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:18:23 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:14:21 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:10:19 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:06:17 PM) (Source: Windows Search Service) (User: ) Description: Unable to initialize the filter host process. Terminating. Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) System errors: ============= Error: (04/19/2012 11:56:55 AM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004002 Error: (04/19/2012 11:56:53 AM) (Source: Service Control Manager) (User: ) Description: The Background Intelligent Transfer Service service DEPENDS on the COM+ Event System service which failed to start because of the following error: %%0 Error: (04/19/2012 11:56:53 AM) (Source: DCOM) (User: ) Description: 1068BITS{4991D34B-80A1-4291-83B6-3328366B9097} Error: (04/19/2012 11:54:49 AM) (Source: Service Control Manager) (User: ) Description: The Internet Connection Sharing (ICS) service hung on starting. Error: (04/19/2012 11:53:20 AM) (Source: Service Control Manager) (User: ) Description: The System Event Notification Service service depends on the COM+ Event System service which failed to start because of the following error: %%0 Error: (04/19/2012 11:53:19 AM) (Source: EventLog) (User: ) Description: The previous system SHUTDOWN at 11:49:35 AM on ?4/?19/?2012 was unexpected. Error: (04/19/2012 11:51:01 AM) (Source: Service Control Manager) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service. Error: (04/19/2012 11:50:31 AM) (Source: Service Control Manager) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service. Error: (04/19/2012 11:50:01 AM) (Source: Service Control Manager) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service. Error: (04/19/2012 11:49:31 AM) (Source: Service Control Manager) (User: ) Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service. Microsoft Office Sessions: ========================= Error: (04/19/2012 07:42:32 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:38:31 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:34:29 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:30:27 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:26:26 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:22:25 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:18:23 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:14:21 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:10:19 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) Error: (04/19/2012 07:06:17 PM) (Source: Windows Search Service)(User: ) Description: Details: This operation returned because the timeout period expired. (HRESULT : 0x800705b4) (0x800705b4) ========================= Memory info: =================================== Percentage of memory in use: 26% Total physical RAM: 3959.49 MB Available physical RAM: 2905.25 MB Total Pagefile: 7917.13 MB Available Pagefile: 6296.39 MB Total Virtual: 4095.88 MB Available Virtual: 3970.79 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:97.56 GB) (Free:23.37 GB) NTFS 2 Drive d: () (Fixed) (Total:99.61 GB) (Free:99.39 GB) NTFS 3 Drive e: () (Fixed) (Total:734.25 GB) (Free:733.21 GB) NTFS ========================= Users: ======================================== User accounts for \\MICHAL-PC Administrator Guest Michal **** End of log **** Farbar Service Scanner Version: 16-04-2012 Ran by Michal (administrator) on 19-04-2012 at 20:40:24 Running from "C:\Users\Michal\Desktop" Windows 7 Ultimate (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Yahoo IP is accessible. File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys [2012-03-24 12:05] - [2011-12-27 23:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log ****Quote But I can still access the Internet, although any type of video from Youtube, Facebook etc. is extremely choppy, not even watchable.That would indicate a lack of enough memory. Please run the program below. It's supposed to fix a number of problems. Please download and run MS Fix-it from here. There is a program in Windows 7 that is specifically made to diagnose and repair problems with Windows updates. Could you please run it?I keep getting an error when trying to run Fix It There is a program in Windows 7 that is specifically made to diagnose and repair problems with Windows updates. Could you please run it? I'm no sure what this is either Yeah I'm clueless.Can you please try running Action Center? |
|
| 144. |
Solve : possible hacker in my pc? |
|
Answer» Logfile of Trend Micro HijackThis v2.0.2
=>CLOSED |
|
| 145. |
Solve : Google Redirect Virus? |
|
Answer» I'm stumped. I'm going to check with a colleague about this problem.Ok. Thank you.Please download MiniToolBox to Desktop and run it.
Ran by USER (administrator) on 07-04-2012 at 20:27:20 Microsoft Windows XP Professional Service Pack 3 (X86) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= Hosts content: ================================= 127.0.0.1 localhost ========================= IP Configuration: ================================ Intel(R) 82562V-2 10/100 Network Connection = Local Area Connection (Connected) # ---------------------------------- # Interface IP Configuration # ---------------------------------- pushd interface ip # Interface IP Configuration for "Local Area Connection" set address name="Local Area Connection" source=dhcp set dns name="Local Area Connection" source=dhcp register=PRIMARY set wins name="Local Area Connection" source=dhcp popd # End of interface IP configuration Windows IP Configuration Host Name . . . . . . . . . . . . : user-ffe079d9b5 Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Unknown IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Ethernet adapter Local Area Connection: Connection-specific DNS Suffix . : DESCRIPTION . . . . . . . . . . . : Intel(R) 82562V-2 10/100 Network Connection Physical Address. . . . . . . . . : 00-21-9B-0B-BC-88 Dhcp Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IP Address. . . . . . . . . . . . : 192.168.1.4 Subnet Mask . . . . . . . . . . . : 255.255.255.0 Default Gateway . . . . . . . . . : 192.168.1.1 DHCP Server . . . . . . . . . . . : 192.168.1.1 DNS Servers . . . . . . . . . . . : 192.168.1.1 Lease Obtained. . . . . . . . . . : Saturday, April 07, 2012 8:27:13 PM Lease Expires . . . . . . . . . . : SUNDAY, April 08, 2012 8:27:13 PM Server: UnKnown Address: 192.168.1.1 Name: google.com Addresses: 74.125.226.196, 74.125.226.197, 74.125.226.198, 74.125.226.199 74.125.226.200, 74.125.226.201, 74.125.226.206, 74.125.226.192, 74.125.226.193 74.125.226.194, 74.125.226.195 Pinging google.com [74.125.226.231] with 32 bytes of data: Reply from 74.125.226.231: bytes=32 time=34ms TTL=53 Reply from 74.125.226.231: bytes=32 time=33ms TTL=53 Ping statistics for 74.125.226.231: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: MINIMUM = 33ms, Maximum = 34ms, Average = 33ms Server: UnKnown Address: 192.168.1.1 Name: yahoo.com Addresses: 72.30.38.140, 98.139.183.24, 209.191.122.70 Pinging yahoo.com [209.191.122.70] with 32 bytes of data: Reply from 209.191.122.70: bytes=32 time=76ms TTL=50 Reply from 209.191.122.70: bytes=32 time=75ms TTL=50 Ping statistics for 209.191.122.70: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 75ms, Maximum = 76ms, Average = 75ms Server: UnKnown Address: 192.168.1.1 Name: bleepingcomputer.com Address: 208.43.87.2 Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data: Reply from 208.43.87.2: Destination host unreachable. Reply from 208.43.87.2: Destination host unreachable. Ping statistics for 208.43.87.2: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 0x1 ........................... MS TCP Loopback interface 0x2 ...00 21 9b 0b bc 88 ...... Intel(R) 82562V-2 10/100 Network Connection - Agnitum firewall miniport =========================================================================== =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.4 20 127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1 192.168.1.0 255.255.255.0 192.168.1.4 192.168.1.4 20 192.168.1.4 255.255.255.255 127.0.0.1 127.0.0.1 20 192.168.1.255 255.255.255.255 192.168.1.4 192.168.1.4 20 224.0.0.0 240.0.0.0 192.168.1.4 192.168.1.4 20 255.255.255.255 255.255.255.255 192.168.1.4 192.168.1.4 1 Default Gateway: 192.168.1.1 =========================================================================== Persistent Routes: None ========================= Event log errors: =============================== Application errors: ================== Error: (04/04/2012 04:28:33 PM) (Source: Application Hang) (User: ) Description: Fault bucket -1413921487. Error: (04/04/2012 04:28:31 PM) (Source: Application Hang) (User: ) Description: Hanging application firefox.exe, version 11.0.0.4454, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (04/03/2012 06:33:04 PM) (Source: Application Error) (User: ) Description: Fault bucket -1391902482. The Wep key exchange did not result in a secure connection setup after 802.1x authentication. The current setting has been marked as failed and the Wireless connection will be disconnected. Error: (04/03/2012 06:33:01 PM) (Source: Application Error) (User: ) Description: Faulting application FlashPlayerUpdateService.exe, version 11.2.202.228, faulting module FlashPlayerUpdateService.exe, version 11.2.202.228, fault address 0x0000abd8. Processing media-specific event for [FlashPlayerUpdateService.exe!ws!] Error: (04/01/2012 09:00:55 PM) (Source: Application Hang) (User: ) Description: Fault bucket 1217514343. Error: (04/01/2012 09:00:52 PM) (Source: Application Hang) (User: ) Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (04/01/2012 08:59:56 PM) (Source: Application Hang) (User: ) Description: Fault bucket 1217514343. Error: (04/01/2012 08:59:53 PM) (Source: Application Hang) (User: ) Description: Hanging application SysProt.exe, version 1.0.1.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Error: (03/31/2012 08:14:17 PM) (Source: Application Error) (User: ) Description: Faulting application oasrv.exe, version 5.5.0.1557, faulting module oasrv.exe, version 5.5.0.1557, fault address 0x00004a6f. Processing media-specific event for [oasrv.exe!ws!] Error: (03/21/2012 11:36:57 AM) (Source: Application Hang) (User: ) Description: Hanging application firefox.exe, version 11.0.0.4454, hang module hungapp, version 0.0.0.0, hang address 0x00000000. System errors: ============= Error: (04/07/2012 08:27:08 AM) (Source: Dhcp) (User: ) Description: The IP address lease 0.0.0.0 for the Network Card with network address 00219B0BBC88 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). Error: (04/07/2012 08:27:05 AM) (Source: Dhcp) (User: ) Description: The IP address lease 192.168.1.2 for the Network Card with network address 00219B0BBC88 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). Error: (04/01/2012 03:01:13 PM) (Source: Service Control Manager) (User: ) Description: The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service. Microsoft Office Sessions: ========================= Error: (04/04/2012 04:28:33 PM) (Source: Application Hang)(User: ) Description: -1413921487 Error: (04/04/2012 04:28:31 PM) (Source: Application Hang)(User: ) Description: firefox.exe11.0.0.4454hungapp0.0.0.0000 00000 Error: (04/03/2012 06:33:04 PM) (Source: Application Error)(User: ) Description: -1391902482 Error: (04/03/2012 06:33:01 PM) (Source: Application Error)(User: ) Description: FlashPlayerUpdateService.exe11.2.202.22 8FlashPlayerUpdateService.exe11.2.202.2 280000abd8 Error: (04/01/2012 09:00:55 PM) (Source: Application Hang)(User: ) Description: 1217514343 Error: (04/01/2012 09:00:52 PM) (Source: Application Hang)(User: ) Description: SysProt.exe1.0.1.0hungapp0.0.0.00000000 0 Error: (04/01/2012 08:59:56 PM) (Source: Application Hang)(User: ) Description: 1217514343 Error: (04/01/2012 08:59:53 PM) (Source: Application Hang)(User: ) Description: SysProt.exe1.0.1.0hungapp0.0.0.00000000 0 Error: (03/31/2012 08:14:17 PM) (Source: Application Error)(User: ) Description: oasrv.exe5.5.0.1557oasrv.exe5.5.0.15570 0004a6f Error: (03/21/2012 11:36:57 AM) (Source: Application Hang)(User: ) Description: firefox.exe11.0.0.4454hungapp0.0.0.0000 00000 ========================= Memory info: =================================== Percentage of memory in use: 24% Total physical RAM: 3326.1 MB Available physical RAM: 2521.16 MB Total Pagefile: 5210.32 MB Available Pagefile: 4515.76 MB Total Virtual: 2047.88 MB Available Virtual: 1974.96 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:298.08 GB) (Free:280.93 GB) NTFS ========================= Users: ======================================== User accounts for \\USER-FFE079D9B5 Administrator Guest HelpAssistant Sharon DePuy SUPPORT_388945a0 USER **** End of log **** Comments removed. |
|
| 146. |
Solve : Trouble downloading HijackThis to correct location? |
|
Answer» My comp is freezing, crashing and restarting. I'm WORKING through the pre-post "to-do" list. I've been unable to complete scans using SAS (comp restarts) and Malware Bytes (comp freezes). |
|
| 147. |
Solve : PLEASE HELP? |
|
Answer» i cant watch videos and everytime i try downloading flash player i have this message posted in wordpad on my desktop. What the *censored* isit and how can i get rid of it!! i want to cry haha # # A fatal error has been detected by the Java Runtime Environment: # # EXCEPTION_ACCESS_VIOLATION (0xc0000005) at pc=0x46bfe9ed, pid=512, tid=3696 # # JRE version: 6.0_17-b04 # Java VM: Java HotSpot(TM) Client VM (14.3-b01 mixed mode, sharing windows-x86 ) # Problematic frame: # C 0x46bfe9ed # # If you would like to submit a bug report, please visit: # http://java.sun.com/webapps/bugreport/crash.jsp # The crash happened outside the Java Virtual Machine in native code. # See problematic frame for where to report the bug. # --------------- T H R E A D --------------- Current thread (0x03122800): JavaThread "thread applet-com.diginet.digichat.client.DigiChatApplet-1" [_thread_in_native, id=3696, stack(0x03320000,0x03370000)] siginfo: ExceptionCode=0xc0000005, reading address 0x46bfe9ed Registers: EAX=0x0336d62c, EBX=0x00000188, ECX=0x03117618, EDX=0x00000004 ESP=0x0336d60c, EBP=0x0336de38, ESI=0x0336d62c, EDI=0x00000188 EIP=0x46bfe9ed, EFLAGS=0x00010202 Top of Stack: (sp=0x0336d60c) 0x0336d60c: 6d6171fe 00002360 0336d62c 00000188 0x0336d61c: 00000000 03122800 26df2bd8 26df2bd0 0x0336d62c: 20544547 6769442f 61684369 69442f74 0x0336d63c: 6c436967 65737361 6c432f73 746e6569 0x0336d64c: 315f355f 315f305f 616a2e39 54482072 0x0336d65c: 312f5054 0a0d312e 746e6f63 2d746e65 0x0336d66c: 65707974 7061203a 63696c70 6f697461 0x0336d67c: 2d782f6e 6176616a 6372612d 65766968 Instructions: (pc=0x46bfe9ed) 0x46bfe9dd: [error occurred during error reporting (printing registers, top of stack, instructions near pc), id 0xc0000005] Stack: [0x03320000,0x03370000], sp=0x0336d60c, free space=309k Native frames: (J=compiled Java code, j=interpreted, Vv=VM code, C=native code) C 0x46bfe9ed j java.net.SocketOutputStream.socketWrite 0(Ljava/io/FileDescriptor;[BII)V+0 j java.net.SocketOutputStream.socketWrite([BII)V+44 j java.net.SocketOutputStream.write([BII)V+4 j java.io.BufferedOutputStream.flushBuffe r()V+20 j java.io.BufferedOutputStream.flush()V+1 j java.io.PrintStream.flush()V+12 j sun.net.www.MessageHeader.print(Ljava/io/PrintStream;)V+101 j sun.net.www.http.HttpClient.writeReques ts(Lsun/net/www/MessageHeader;Lsun/net/www/http/PosterOutputStream;)V+13 j sun.net.www.protocol.http.HttpURLConnec tion.writeRequests()V+647 j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+278 j com.sun.deploy.net.HttpUtils.followRedi rects(Ljava/net/URLConnection;)Ljava/net/HttpURLConnection;+20 j com.sun.deploy.net.BasicHttpRequest.doR equest(Ljava/net/URL;Z[Ljava/lang/String;[Ljava/lang/String;ZJ)Lcom/sun/deploy/net/HttpResponse;+193 j com.sun.deploy.net.BasicHttpRequest.doG etRequestEX(Ljava/net/URL;[Ljava/lang/String;[Ljava/lang/String;J)Lcom/sun/deploy/net/HttpResponse;+8 j com.sun.deploy.net.DownloadEngine.isUpd ateAvailable(Ljava/net/URL;Ljava/lang/String;ZLjava/util/Map;)Z+329 j com.sun.deploy.cache.DeployCacheHandler .get(Ljava/net/URI;Ljava/lang/String;Ljava/util/Map;)Ljava/net/CacheResponse;+134 j sun.net.www.protocol.http.HttpURLConnec tion.plainConnect()V+54 j sun.net.www.protocol.http.HttpURLConnec tion.connect()V+1 j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+187 j sun.plugin.PluginURLJarFileCallBack.dow nloadJAR(Ljava/net/URLConnection;Z)V+34 j sun.plugin.PluginURLJarFileCallBack.acc ess$000(Lsun/plugin/PluginURLJarFileCallBack;Ljava/net/URLConnection;Z)V+3 j sun.plugin.PluginURLJarFileCallBack$2.run()Ljava/lang/Object;+103 v ~StubRoutines::call_stub V [jvm.dll+0xecf9c] V [jvm.dll+0x1741d1] V [jvm.dll+0xed01d] V [jvm.dll+0x11c2bf] C [java.dll+0x1047] j sun.plugin.PluginURLJarFileCallBack.ret rieve(Ljava/net/URL;)Ljava/util/jar/JarFile;+73 j sun.net.www.protocol.jar.URLJarFile.ret rieve(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+10 j sun.net.www.protocol.jar.URLJarFile.get JarFile(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+19 j sun.net.www.protocol.jar.JarFileFactory .get(Ljava/net/URL;Z)Ljava/util/jar/JarFile;+192 j sun.net.www.protocol.jar.JarURLConnecti on.connect()V+19 j sun.plugin.net.protocol.jar.CachedJarUR LConnection.connect()V+116 j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFileInternal()Ljava/util/jar/JarFile;+213 j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFile()Ljava/util/jar/JarFile;+2 j sun.misc.URLClassPath$JarLoader.getJarFile(Ljava/net/URL;)Ljava/util/jar/JarFile;+69 j sun.misc.URLClassPath$JarLoader.access$600(Lsun/misc/URLClassPath$JarLoader;Ljava/net/URL;)Ljava/util/jar/JarFile;+2 j sun.misc.URLClassPath$JarLoader$1.run()Ljava/lang/Object;+55 v ~StubRoutines::call_stub V [jvm.dll+0xecf9c] V [jvm.dll+0x1741d1] V [jvm.dll+0xed01d] V [jvm.dll+0x11c2bf] C [java.dll+0x1047] j sun.misc.URLClassPath$JarLoader.ensureOpen()V+15 j sun.misc.URLClassPath$JarLoader.(Ljava/net/URL;Ljava/net/URLStreamHandler;Ljava/util/HashMap;)V+60 j sun.misc.URLClassPath$3.run()Ljava/lang/Object;+82 v ~StubRoutines::call_stub V [jvm.dll+0xecf9c] V [jvm.dll+0x1741d1] V [jvm.dll+0xed01d] V [jvm.dll+0x11c2bf] C [java.dll+0x1047] j sun.misc.URLClassPath.getLoader(Ljava/net/URL;)Lsun/misc/URLClassPath$Loader;+9 j sun.misc.URLClassPath.getLoader(I)Lsun/misc/URLClassPath$Loader;+73 j sun.misc.URLClassPath.getResource(Ljava/lang/String;Z)Lsun/misc/Resource;+42 j sun.plugin2.applet.Plugin2ClassLoader$2.run()Ljava/lang/Object;+51 v ~StubRoutines::call_stub V [jvm.dll+0xecf9c] V [jvm.dll+0x1741d1] V [jvm.dll+0xed01d] V [jvm.dll+0x11c2bf] C [java.dll+0x1061] j sun.plugin2.applet.Plugin2ClassLoader.f indClassHelper(Ljava/lang/String;)Ljava/lang/Class;+33 j sun.plugin2.applet.Applet2ClassLoader.f indClass(Ljava/lang/String;)Ljava/lang/Class;+34 j java.lang.ClassLoader.loadClass(Ljava/lang/String;Z)Ljava/lang/Class;+43 j java.lang.ClassLoader.loadClass(Ljava/lang/String;)Ljava/lang/Class;+3 j sun.plugin2.applet.Plugin2ClassLoader.l oadCode(Ljava/lang/String;)Ljava/lang/Class;+123 j sun.plugin2.applet.Plugin2Manager.creat eApplet()Ljava/applet/Applet;+127 j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+183 j java.lang.Thread.run()V+11 v ~StubRoutines::call_stub V [jvm.dll+0xecf9c] V [jvm.dll+0x1741d1] V [jvm.dll+0xed167] V [jvm.dll+0xed1dd] V [jvm.dll+0x116290] V [jvm.dll+0x1d0414] V [jvm.dll+0x173e4c] C [msvcr71.dll+0x9565] C [kernel32.dll+0xb729] Java frames: (J=compiled Java code, j=interpreted, Vv=VM code) j java.net.SocketOutputStream.socketWrite 0(Ljava/io/FileDescriptor;[BII)V+0 j java.net.SocketOutputStream.socketWrite([BII)V+44 j java.net.SocketOutputStream.write([BII)V+4 j java.io.BufferedOutputStream.flushBuffe r()V+20 j java.io.BufferedOutputStream.flush()V+1 j java.io.PrintStream.flush()V+12 j sun.net.www.MessageHeader.print(Ljava/io/PrintStream;)V+101 j sun.net.www.http.HttpClient.writeReques ts(Lsun/net/www/MessageHeader;Lsun/net/www/http/PosterOutputStream;)V+13 j sun.net.www.protocol.http.HttpURLConnec tion.writeRequests()V+647 j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+278 j com.sun.deploy.net.HttpUtils.followRedi rects(Ljava/net/URLConnection;)Ljava/net/HttpURLConnection;+20 j com.sun.deploy.net.BasicHttpRequest.doR equest(Ljava/net/URL;Z[Ljava/lang/String;[Ljava/lang/String;ZJ)Lcom/sun/deploy/net/HttpResponse;+193 j com.sun.deploy.net.BasicHttpRequest.doG etRequestEX(Ljava/net/URL;[Ljava/lang/String;[Ljava/lang/String;J)Lcom/sun/deploy/net/HttpResponse;+8 j com.sun.deploy.net.DownloadEngine.isUpd ateAvailable(Ljava/net/URL;Ljava/lang/String;ZLjava/util/Map;)Z+329 j com.sun.deploy.cache.DeployCacheHandler .get(Ljava/net/URI;Ljava/lang/String;Ljava/util/Map;)Ljava/net/CacheResponse;+134 j sun.net.www.protocol.http.HttpURLConnec tion.plainConnect()V+54 j sun.net.www.protocol.http.HttpURLConnec tion.connect()V+1 j sun.net.www.protocol.http.HttpURLConnec tion.getInputStream()Ljava/io/InputStream;+187 j sun.plugin.PluginURLJarFileCallBack.dow nloadJAR(Ljava/net/URLConnection;Z)V+34 j sun.plugin.PluginURLJarFileCallBack.acc ess$000(Lsun/plugin/PluginURLJarFileCallBack;Ljava/net/URLConnection;Z)V+3 j sun.plugin.PluginURLJarFileCallBack$2.run()Ljava/lang/Object;+103 v ~StubRoutines::call_stub j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0 j sun.plugin.PluginURLJarFileCallBack.ret rieve(Ljava/net/URL;)Ljava/util/jar/JarFile;+73 j sun.net.www.protocol.jar.URLJarFile.ret rieve(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+10 j sun.net.www.protocol.jar.URLJarFile.get JarFile(Ljava/net/URL;Lsun/net/www/protocol/jar/URLJarFile$URLJarFileCloseController;)Ljava/util/jar/JarFile;+19 j sun.net.www.protocol.jar.JarFileFactory .get(Ljava/net/URL;Z)Ljava/util/jar/JarFile;+192 j sun.net.www.protocol.jar.JarURLConnecti on.connect()V+19 j sun.plugin.net.protocol.jar.CachedJarUR LConnection.connect()V+116 j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFileInternal()Ljava/util/jar/JarFile;+213 j sun.plugin.net.protocol.jar.CachedJarUR LConnection.getJarFile()Ljava/util/jar/JarFile;+2 j sun.misc.URLClassPath$JarLoader.getJarFile(Ljava/net/URL;)Ljava/util/jar/JarFile;+69 j sun.misc.URLClassPath$JarLoader.access$600(Lsun/misc/URLClassPath$JarLoader;Ljava/net/URL;)Ljava/util/jar/JarFile;+2 j sun.misc.URLClassPath$JarLoader$1.run()Ljava/lang/Object;+55 v ~StubRoutines::call_stub j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0 j sun.misc.URLClassPath$JarLoader.ensureOpen()V+15 j sun.misc.URLClassPath$JarLoader.(Ljava/net/URL;Ljava/net/URLStreamHandler;Ljava/util/HashMap;)V+60 j sun.misc.URLClassPath$3.run()Ljava/lang/Object;+82 v ~StubRoutines::call_stub j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;)Ljava/lang/Object;+0 j sun.misc.URLClassPath.getLoader(Ljava/net/URL;)Lsun/misc/URLClassPath$Loader;+9 j sun.misc.URLClassPath.getLoader(I)Lsun/misc/URLClassPath$Loader;+73 j sun.misc.URLClassPath.getResource(Ljava/lang/String;Z)Lsun/misc/Resource;+42 j sun.plugin2.applet.Plugin2ClassLoader$2.run()Ljava/lang/Object;+51 v ~StubRoutines::call_stub j java.security.AccessController.doPrivil eged(Ljava/security/PrivilegedExceptionAction;Ljava/security/AccessControlContext;)Ljava/lang/Object;+0 j sun.plugin2.applet.Plugin2ClassLoader.f indClassHelper(Ljava/lang/String;)Ljava/lang/Class;+33 j sun.plugin2.applet.Applet2ClassLoader.f indClass(Ljava/lang/String;)Ljava/lang/Class;+34 j java.lang.ClassLoader.loadClass(Ljava/lang/String;Z)Ljava/lang/Class;+43 j java.lang.ClassLoader.loadClass(Ljava/lang/String;)Ljava/lang/Class;+3 j sun.plugin2.applet.Plugin2ClassLoader.l oadCode(Ljava/lang/String;)Ljava/lang/Class;+123 j sun.plugin2.applet.Plugin2Manager.creat eApplet()Ljava/applet/Applet;+127 j sun.plugin2.applet.Plugin2Manager$AppletExecutionRunnable.run()V+183 j java.lang.Thread.run()V+11 v ~StubRoutines::call_stub --------------- P R O C E S S --------------- Java Threads: ( => current thread ) 0x03123000 JavaThread "Thread-10" [_thread_blocked, id=3216, stack(0x04080000,0x040d0000)] =>0x03122800 JavaThread "thread applet-com.diginet.digichat.client.DigiChatApplet-1" [_thread_in_native, id=3696, stack(0x03320000,0x03370000)] 0x03118400 JavaThread "AWT-EventQueue-2" [_thread_blocked, id=3648, stack(0x040d0000,0x04120000)] 0x03114400 JavaThread "Applet 2 LiveConnect Worker Thread" [_thread_blocked, id=3392, stack(0x04030000,0x04080000)] 0x030ec400 JavaThread "Browser Side Object Cleanup Thread" [_thread_blocked, id=3524, stack(0x03600000,0x03650000)] 0x03107000 JavaThread "Image FETCHER 3" daemon [_thread_blocked, id=3552, stack(0x03740000,0x03790000)] 0x03100c00 JavaThread "Windows Tray Icon Thread" [_thread_in_native, id=2996, stack(0x036f0000,0x03740000)] 0x03100800 JavaThread "CacheCleanUpThread" daemon [_thread_blocked, id=3088, stack(0x03650000,0x036a0000)] 0x030f5c00 JavaThread "CacheMemoryCleanUpThread" daemon [_thread_blocked, id=2976, stack(0x036a0000,0x036f0000)] 0x030e6000 JavaThread "Java Plug-In Heartbeat Thread" [_thread_blocked, id=1492, stack(0x035b0000,0x03600000)] 0x030e4c00 JavaThread "AWT-EventQueue-0" [_thread_blocked, id=4040, stack(0x03560000,0x035b0000)] 0x030e3000 JavaThread "AWT-Windows" daemon [_thread_in_native, id=1896, stack(0x034b0000,0x03500000)] 0x030e1c00 JavaThread "AWT-Shutdown" [_thread_blocked, id=3568, stack(0x03460000,0x034b0000)] 0x030dd800 JavaThread "Java2D Disposer" daemon [_thread_blocked, id=2544, stack(0x03410000,0x03460000)] 0x030dac00 JavaThread "Java Plug-In Pipe Worker Thread (Client-Side)" daemon [_thread_in_native, id=1600, stack(0x03370000,0x033c0000)] 0x030dc800 JavaThread "traceMsgQueueThread" daemon [_thread_blocked, id=3140, stack(0x032d0000,0x03320000)] 0x02d6bc00 JavaThread "Timer-0" [_thread_blocked, id=3836, stack(0x03080000,0x030d0000)] 0x02d49400 JavaThread "Low Memory Detector" daemon [_thread_blocked, id=3164, stack(0x02fc0000,0x03010000)] 0x02d42c00 JavaThread "CompilerThread0" daemon [_thread_blocked, id=2712, stack(0x02f70000,0x02fc0000)] 0x02d41400 JavaThread "Attach Listener" daemon [_thread_blocked, id=1176, stack(0x02f20000,0x02f70000)] 0x02d40000 JavaThread "Signal Dispatcher" daemon [_thread_blocked, id=3252, stack(0x02ed0000,0x02f20000)] 0x02d01800 JavaThread "Finalizer" daemon [_thread_blocked, id=2572, stack(0x02e80000,0x02ed0000)] 0x02cfcc00 JavaThread "Reference Handler" daemon [_thread_blocked, id=1368, stack(0x02e30000,0x02e80000)] 0x00a96800 JavaThread "main" [_thread_blocked, id=3132, stack(0x00b20000,0x00b70000)] Other Threads: 0x02cfb400 VMThread [stack: 0x02de0000,0x02e30000] [id=172] 0x02d5cc00 WatcherThread [stack: 0x03010000,0x03060000] [id=2732] VM state:not at safepoint (normal execution) VM Mutex/Monitor currently owned by a thread: None Heap def new generation total 960K, used 839K [0x22bc0000, 0x22cc0000, 0x230a0000) eden space 896K, 86% used [0x22bc0000, 0x22c81f00, 0x22ca0000) from space 64K, 100% used [0x22ca0000, 0x22cb0000, 0x22cb0000) to space 64K, 0% used [0x22cb0000, 0x22cb0000, 0x22cc0000) tenured generation total 4096K, used 491K [0x230a0000, 0x234a0000, 0x26bc0000) the space 4096K, 11% used [0x230a0000, 0x2311ac78, 0x2311ae00, 0x234a0000) compacting perm gen total 12288K, used 2276K [0x26bc0000, 0x277c0000, 0x2abc0000) the space 12288K, 18% used [0x26bc0000, 0x26df9250, 0x26df9400, 0x277c0000) ro space 8192K, 63% used [0x2abc0000, 0x2b0d8b20, 0x2b0d8c00, 0x2b3c0000) rw space 12288K, 53% used [0x2b3c0000, 0x2ba35138, 0x2ba35200, 0x2bfc0000) Dynamic libraries: 0x00400000 - 0x00424000 C:\Program Files\Java\jre6\bin\java.exe 0x7c900000 - 0x7c9b2000 C:\WINDOWS\system32\ntdll.dll 0x7c800000 - 0x7c8f6000 C:\WINDOWS\system32\kernel32.dll 0x77dd0000 - 0x77e6b000 C:\WINDOWS\system32\ADVAPI32.dll 0x77e70000 - 0x77f02000 C:\WINDOWS\system32\RPCRT4.dll 0x77fe0000 - 0x77ff1000 C:\WINDOWS\system32\Secur32.dll 0x5cb70000 - 0x5cb96000 C:\WINDOWS\system32\ShimEng.dll 0x71590000 - 0x71609000 C:\WINDOWS\AppPatch\AcLayers.DLL 0x7e410000 - 0x7e4a1000 C:\WINDOWS\system32\USER32.dll 0x77f10000 - 0x77f59000 C:\WINDOWS\system32\GDI32.dll 0x7c9c0000 - 0x7d1d7000 C:\WINDOWS\system32\SHELL32.dll 0x77c10000 - 0x77c68000 C:\WINDOWS\system32\msvcrt.dll 0x77f60000 - 0x77fd6000 C:\WINDOWS\system32\SHLWAPI.dll 0x774e0000 - 0x7761d000 C:\WINDOWS\system32\ole32.dll 0x769c0000 - 0x76a74000 C:\WINDOWS\system32\USERENV.dll 0x73000000 - 0x73026000 C:\WINDOWS\system32\WINSPOOL.DRV 0x76390000 - 0x763ad000 C:\WINDOWS\system32\IMM32.DLL 0x773d0000 - 0x774d3000 C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll 0x76bf0000 - 0x76bfb000 C:\WINDOWS\system32\psapi.dll 0x3d930000 - 0x3da01000 C:\WINDOWS\system32\wininet.dll 0x003e0000 - 0x003e9000 C:\WINDOWS\system32\Normaliz.dll 0x3dfd0000 - 0x3e015000 C:\WINDOWS\system32\iertutil.dll 0x71ab0000 - 0x71ac7000 C:\WINDOWS\system32\ws2_32.dll 0x71aa0000 - 0x71aa8000 C:\WINDOWS\system32\WS2HELP.dll 0x71ad0000 - 0x71ad9000 C:\WINDOWS\system32\wsock32.dll 0x77a80000 - 0x77b15000 C:\WINDOWS\system32\crypt32.dll 0x77b20000 - 0x77b32000 C:\WINDOWS\system32\MSASN1.dll 0x77c00000 - 0x77c08000 C:\WINDOWS\system32\VERSION.dll 0x5b860000 - 0x5b8b5000 C:\WINDOWS\system32\netapi32.dll 0x68000000 - 0x68036000 C:\WINDOWS\system32\rsaenh.dll 0x7c340000 - 0x7c396000 C:\Program Files\Java\jre6\bin\msvcr71.dll 0x6d800000 - 0x6da8b000 C:\Program Files\Java\jre6\bin\client\jvm.dll 0x76b40000 - 0x76b6d000 C:\WINDOWS\system32\WINMM.dll 0x6d7b0000 - 0x6d7bc000 C:\Program Files\Java\jre6\bin\verify.dll 0x6d330000 - 0x6d34f000 C:\Program Files\Java\jre6\bin\java.dll 0x6d290000 - 0x6d298000 C:\Program Files\Java\jre6\bin\hpi.dll 0x6d7f0000 - 0x6d7ff000 C:\Program Files\Java\jre6\bin\zip.dll 0x6d430000 - 0x6d436000 C:\Program Files\Java\jre6\bin\jp2native.dll 0x6d1d0000 - 0x6d1e3000 C:\Program Files\Java\jre6\bin\deploy.dll 0x77120000 - 0x771ab000 C:\WINDOWS\system32\OLEAUT32.dll 0x78130000 - 0x78258000 C:\WINDOWS\system32\urlmon.dll 0x6d6b0000 - 0x6d6f3000 C:\Program Files\Java\jre6\bin\regutils.dll 0x7d1e0000 - 0x7d49c000 C:\WINDOWS\system32\msi.dll 0x6d610000 - 0x6d623000 C:\Program Files\Java\jre6\bin\net.dll 0x6d630000 - 0x6d639000 C:\Program Files\Java\jre6\bin\nio.dll 0x6d000000 - 0x6d14a000 C:\Program Files\Java\jre6\bin\awt.dll 0x5ad70000 - 0x5ada8000 C:\WINDOWS\system32\uxtheme.dll 0x74720000 - 0x7476c000 C:\WINDOWS\system32\MSCTF.dll 0x77b40000 - 0x77b62000 C:\WINDOWS\system32\apphelp.dll 0x755c0000 - 0x755ee000 C:\WINDOWS\system32\msctfime.ime 0x6d230000 - 0x6d284000 C:\Program Files\Java\jre6\bin\fontmanager.dll 0x71a50000 - 0x71a8f000 C:\WINDOWS\system32\mswsock.dll 0x662b0000 - 0x66308000 C:\WINDOWS\system32\hnetcfg.dll 0x71a90000 - 0x71a98000 C:\WINDOWS\System32\wshtcpip.dll VM Arguments: jvm_args: -D__jvm_launched=36107607242 -Xbootclasspath/a:C:\PROGRA~1\Java\jre6\lib\deploy.jar;C:\PROGRA~1\Java\jre6\lib\javaws.jar;C:\PROGRA~1\Java\jre6\lib\plugin.jar java_command: sun.plugin2.main.client.PluginMain write_pipe_name=jpi2_pid2896_pipe6,read_pipe_name=jpi2_pid2896_pipe5 Launcher Type: SUN_STANDARD Environment Variables: PATH=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\adabas\bin;C:\adabas\pgm;C:\Program Files\Common Files\Teleca Shared;C:\Program Files\QuickTime\QTSystem\;C:\adabas\bin;C:\adabas\pgm USERNAME=Nathan OS=Windows_NT PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 8, GenuineIntel --------------- S Y S T E M --------------- OS: Windows XP Build 2600 Service Pack 3 CPU:total 1 (1 cores per cpu, 1 threads per core) family 6 model 13 stepping 8, cmov, cx8, fxsr, mmx, sse, sse2 Memory: 4k page, physical 1039408k(414428k free), swap 2499048k(1873708k free) vm_info: Java HotSpot(TM) Client VM (14.3-b01) for windows-x86 JRE (1.6.0_17-b04), built on Oct 11 2009 00:52:06 by "java_re" with MS VC++ 7.1 time: Mon Apr 05 00:59:23 2010 elapsed time: 4 seconds Please visit this webpage for a tutorial on downloading and running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix See the area: Using ComboFix, and when done, post the log back here.boFix 10-04-05.06 - Nathan 06/04/2010 19:40:58.1.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.44.1033.18.1015.684 [GMT 0:00] Running from: c:\documents and settings\Nathan\Desktop\ComboFix.exe AV: ESET NOD32 Antivirus 3.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0} * Created a new restore point * Resident AV is active WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !! . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\docume~1\Nathan\LOCALS~1\Temp\tmp2.tmp c:\recycler\S-1-5-21-2226665520-4189811108-2719964761-1003 c:\recycler\S-1-5-21-3504028335-655725818-2494886574-1003 c:\recycler\S-1-5-21-4193448610-1243597163-2470444081-1003 c:\recycler\S-1-5-21-839522115-1383384898-527237240-1003 c:\windows\run.log c:\windows\system32\lowsec c:\windows\system32\lowsec\local.ds c:\windows\system32\lowsec\user.ds c:\windows\system32\lowsec\user.ds.lll c:\windows\system32\sdra64.exe c:\windows\system32\Thumbs.db . ((((((((((((((((((((((((( Files Created from 2010-03-06 to 2010-04-06 ))))))))))))))))))))))))))))))) . 2010-04-05 19:19 . 2010-04-05 21:33--------d-----w-c:\documents and settings\All Users\Application Data\RegCure 2010-04-05 19:19 . 2010-04-05 21:31--------d-----w-c:\program files\RegCure 2010-04-04 23:48 . 2010-04-05 21:18--------d-----w-c:\documents and settings\All Users\Application Data\NOS 2010-04-04 23:48 . 2010-04-04 23:48--------d-----w-c:\program files\NOS 2010-03-13 21:52 . 2010-03-13 21:52152576----a-w-c:\documents and settings\Nathan\Application Data\Sun\Java\jre1.6.0_17\lzma.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2010-04-06 19:15 . 2009-02-03 18:22--------d-----w-c:\documents and settings\Nathan\Application Data\StarOffice8 2010-04-05 22:12 . 2009-03-05 04:52--------d-----w-c:\program files\SeekeenSrch 2010-04-05 21:42 . 2009-03-05 04:52--------d-----w-c:\documents and settings\All Users\Application Data\SeekeenSrch 2010-04-04 14:50 . 2009-02-03 18:256952----a-w-c:\documents and settings\Nathan\Application Data\wklnhst.dat 2010-04-04 14:41 . 2009-02-10 20:33--------d-----w-c:\documents and settings\Nathan\Application Data\Teleca 2010-04-04 14:40 . 2009-02-10 20:29--------d-----w-c:\program files\Common Files\Teleca Shared 2010-03-17 00:41 . 2009-02-10 19:29--------d-----w-c:\documents and settings\Nathan\Application Data\LimeWire 2010-03-13 21:54 . 2008-07-05 02:39--------d-----w-c:\program files\Java 2010-03-13 21:52 . 2009-11-11 00:3679488----a-w-c:\documents and settings\Nathan\Application Data\Sun\Java\jre1.6.0_17\gtapi.dll 2010-03-11 12:38 . 2008-07-03 04:32832512----a-w-c:\windows\system32\wininet.dll 2010-03-11 12:38 . 2008-07-03 04:3178336----a-w-c:\windows\system32\ieencode.dll 2010-03-11 12:38 . 2008-07-03 04:3117408----a-w-c:\windows\system32\corpol.dll 2010-02-12 10:03 . 2010-02-25 15:00293376------w-c:\windows\system32\browserchoice.exe 2008-05-07 08:34 . 2008-07-05 02:5515523560----a-w-c:\program files\U1 Setup.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-09-24 104984] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-09-24 121368] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-09-24 100888] "AsusTray"="c:\program files\EeePC\ACPI\AsTray.exe" [2008-06-03 98304] "AsusACPIServer"="c:\program files\EeePC\ACPI\AsAcpiSvr.exe" [2008-06-03 479232] "AsusEPCMonitor"="c:\program files\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208] "RTHDCPL"="RTHDCPL.EXE" [2008-07-16 16806400] "ETDWare"="c:\program files\Elantech\ETDCtrl.exe" [2008-07-23 335872] "ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe" [2004-04-17 196608] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-04-13 69632] "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136] "SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280] "egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-10-07 1461080] c:\documents and settings\Nathan\Start Menu\Programs\Startup\ StarOffice 8.lnk - c:\program files\Sun\StarOffice 8\program\quickstart.exe [2007-8-18 122880] c:\documents and settings\All Users\Start Menu\Programs\Startup\ SuperHybridEngine.lnk - c:\program files\Asus\EeePC\Super Hybrid Engine\SuperHybridEngine.exe [2008-7-5 303104] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2007-10-11 02:5139792----a-w-c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr] 2008-06-19 08:2057344----a-w-c:\windows\Alcmtr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcWzrd] 2008-06-19 08:422808832----a-w-c:\windows\alcwzrd.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr] 2009-07-26 16:443883856----a-w-c:\program files\Windows Live\Messenger\msnmsgr.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan] 2008-06-18 10:0177824----a-w-c:\windows\SoundMan.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "%windir%\\system32\\sessmgr.exe"= "c:\\Program Files\\Messenger\\msmsgs.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\LimeWire\\LimeWire.exe"= "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"= R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [13/03/2008 21:52 35168] R2 EKRN;Eset Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [07/10/2009 09:16 472280] S1 driubrsb;driubrsb;\??\c:\windows\system32\drivers\driubrsb.sys --> c:\windows\system32\drivers\driubrsb.sys [?] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] getPlusHelperREG_MULTI_SZ getPlusHelper . Contents of the 'Scheduled Tasks' folder 2010-03-25 c:\windows\Tasks\AppleSoftwareUpdate.job - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34] 2010-04-05 c:\windows\Tasks\RegCure Program Check.job - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20] 2010-04-06 c:\windows\Tasks\RegCure Startup.job - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20] 2010-04-05 c:\windows\Tasks\RegCure.job - c:\program files\RegCure\RegCure.exe [2010-02-23 23:20] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.facebook.com/ uInternet Connection Wizard,ShellNext = hxxp://eeepc.asus.com/global uInternet Settings,ProxyOverride = *.local . - - - - ORPHANS REMOVED - - - - WebBrowser-{D0523BB4-21E7-11DD-9AB7-415B56D89593} - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2010-04-06 19:47 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2010-04-06 19:50:09 ComboFix-quarantined-files.txt 2010-04-06 19:49 Pre-Run: 28,739,575,808 bytes free Post-Run: 30,070,956,032 bytes free - - End Of File - - CA2EDE311A4535339C36392BCBDED7EA That was scary :-sThere is a dangerous backdoor trojan on your system. This is a sign of total system compromise. Backdoor trojans are very dangerous because they compromise system integrity by making changes that allow it to by used by the attacker for malicious purposes. Remote attackers use backdoors as a means of accessing and taking control of a computer that bypasses security mechanisms. This type of exploit allows them to steal SENSITIVE information like passwords, personal and financial data which is send back to the hacker. To learn more about these types of infections, you can refer to: http://www.viruslist.com/en/viruses/glossary?glossid=189208417 I would counsel you to immediately disconnect this PC from the Internet and from your network if it is on a network. Disconnect the infected computer until the computer can be cleaned. Then, access this information from a non-compromised computer to follow the steps needed. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable. Do NOT change passwords or do any transactions while using the infected computer because the attacker may get the new passwords and transaction information. (If using a router, you need to reset it with a strong logon/password so the malware cannot gain control before connecting again.) Banking and credit card institutions should be notified to apprise them of your situation (possible security breach). To protect your information that may have been compromised, I recommend reading these references:
Though the backdoor has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. It is dangerous and incorrect to assume the computer is secure even if the malware appears to have been removed. In some instances an infection may have caused so much damage to your system that it cannot be completely cleaned or repaired so you can never be sure that you have completely removed a backdoor trojan. The malware may leave so many remnants behind that security tools cannot find them. Tools that claim to be able to remove backdoor trojans cannot guarantee that all traces of it will be removed. Many experts in the security community believe that once infected with such a piece of malware, the best course of action would be a reformat and clean reinstall of the OS. This is something I don't like to recommend normally, but in most cases it is the best solution for your safety. Making this decision is based on what the computer is used for, and what information can be accessed from it. For more information, please read these references very carefully:
http://www.helpmyos.com/tutorials-software-alternatives-to-proprietary-f19/how-to-reformat-and-reinstall-your-operating-system-the-easy-way-t1307.htm#3143 However, if you do not have the resources to reinstall your computer's OS and would like me to attempt to clean it, I will be happy to do so. But please consider carefully before deciding against a reformat. If you do make that decision, I will do my best to help you clean the computer of any infections, but you must understand that once a machine has been taken over by this type of malware, I cannot guarantee that it will be 100% secure even after disinfection or that the removal will be successful. Please let me KNOW what you have decided to do in your next post. Should you have any questions, please feel free to ask. |
|
| 148. |
Solve : Possible malware; unable to enable firewall, system errors, etc. . .? |
|
Answer» Hello! Thank you for all the work you guys do to help us; I really appreciate it!
You are using Microsoft Security essentials which has Windows Defender built into it so that's why you can not turn it on. You might need to defrag your hard drive. You can use the built in Windows defrag by clicking the Start button and then type in disk defragmenter then click on the Disk Defragmenter shortcut. Or use a faster FREE program. Defraggler is very effective and easy to use. Important! Be sure to uncheck Install optional Yahoo! Toolbar or Google Chrome during the install process to avoid installing them. Note: Be sure to clean out temp files and restart the computer just before beginning a defrag. Other than that I believe the computer is malware free. Use the Secunia Software Inspector to check for out of date software. * Click Start Scanner * Check the box next to Enable thorough system inspection. * Click Start * Allow the scan to finish and scroll down to see if any updates are NEEDED. * Update anything listed. You can also download and use the Secunia Personal Software Inspector (PSI) which is FREE for Home Users. This will allow Secunia to run in real time and alert you to potential security threats from outdated software installed on your computer. ---------- Go to Microsoft Windows Update and get all critical updates. ---------- If you are using or have installed IE6 you are using an outdated and soon to be unsupported version of Internet Explorer and I strongly suggest you update to the latest version directly from Microsoft Internet Explorer 8: Home page. ---------- I recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no realtime protection so will not interfere with each other. They do not use any significant amount of resources (except a little disk space) until you run a scan. I also suggest keeping CCleaner Slim. It is an excellent and safe disk cleaner. Running CCleaner on a daily basis helps to protect your privacy and make your computer faster and more secure. I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. * Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Thank you so much for all of your help! It's much appreciated.Sorry, I posted in the wrong feed. |
|
| 149. |
Solve : HiJack This Problem? |
|
Answer» I am in the process of getting rid of VIRUSES on my BUDDY's computer. He has vista and HiJack this V2.0.3 |
|
| 150. |
Solve : HiJackThis logfile, anything wrong?? |
|
Answer» Just posting a HiJackThis logfile. Nothing is wrong with my PC at all, however, with Internet Explorer 8, it does take a painfully long time to start up (once going, it's FAST). I've SWITCHED to Chrome anyhow. My system specs are: AMD Turion ML-37 1.99Ghz, 2.00 GB RAM, 80GB HD, ATI Radeon Xpress 200M.
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.Due to lack of feedback, this topic is now closed. If you need the topic re-opened, PM a moderator and they shall unlock it. =>CLOSED |
|