sigtaba
Members-
Posts
16 -
Joined
-
Last visited
Reputation
0 Neutral-
I don't see a ESET folder in C:\Program Files\
-
Yes. I ran the online scan and it came back "no infections found". Shortly after that I lost my internet connection due to a power outage. Do you need to see a log file? Is there a way to retrieve it now or do I need to run the scan again?
-
Here it is Combofix2.txt
-
Attached is the combo fix log combofix_log.txt
-
I ran the GMER is safemode and this is the result: GMER 1.0.15.15281 - http://www.gmer.net Rootkit scan 2010-05-29 13:53:54 Windows 5.1.2600 Service Pack 3 Running: 6ysw04ry.exe; Driver: C:\DOCUME~1\Chris\LOCALS~1\Temp\pxtoapog.sys ---- Devices - GMER 1.0.15 ---- Device \FileSystem\Fastfat \Fat B9CE0D20 AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation) ---- EOF - GMER 1.0.15 ---- When I ran it in safemode the list that populated on the screen only had 2 items but when I ran it in non-safemode there was a long list. My computer now is running very slow and freezes up alot. I received another blue screen that said "fatal error". I have never seen these blue screens before.
-
I was able to run Defogger and the GMER but after awhile I got this blue screen I have never seen before stating that Windows detected an error and had to shut down. Driver_IRQL_Not_Less_or_ Equal and alot of other verbage and telling me to try to restart and contact the administrator. Should I try again?
-
OK, Here it is: All processes killed ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe\\@|"exefile" /E : value set successfully! ========== COMMANDS ========== Restore point Set: OTM Restore Point (0) C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: All Users User: Chris ->Temp folder emptied: 33639 bytes ->Temporary Internet Files folder emptied: 4882333 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 0 bytes ->Flash cache emptied: 405 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 5.00 mb OTM by OldTimer - Version 3.1.12.0 log created on 05242010_152142 Files moved on Reboot... C:\Documents and Settings\Chris\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully. C:\Documents and Settings\Chris\Local Settings\Temp\~DFC68E.tmp moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\ZHYLWPHC\CAEZMJSJ.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\ZHYLWPHC\CAG4OFNN.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\ZHYLWPHC\CAMFOPI5.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\ZHYLWPHC\CAO1QR4Z.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\ZHYLWPHC\CAT7V97L.php%3Fen%3Dcp1252,;ord=1274732391 moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\ZHYLWPHC\CAWDUZ4H.php%3Fen%3Dcp1252,;ord=1274732400 moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\JV0ICOYP\CA0123S5.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\JV0ICOYP\CAB57ZQ8.php%3Fen%3Dcp1252,;ord=1274732383 moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\JV0ICOYP\CAYPE1SP.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\JV0ICOYP\iframe[1].htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\JV0ICOYP\index[1].php moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\IR401KJR\welcome[1].rand=e76epeascvhbc moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\3NJ2GF8M\CA61K9YH.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\3NJ2GF8M\CAF5T447.php%3Fen%3Dcp1252,;ord=1274732400 moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\3NJ2GF8M\CAKD2V01.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\3NJ2GF8M\CAPF4L1Y.htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\3NJ2GF8M\md[1].htm moved successfully. Registry entries deleted on Reboot...
-
I think I have it now. Notepad opens up when I double click the folder in "Moved Files": All processes killed Error: Unable to interpret <reg> in the current context! Error: Unable to interpret <[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.exe]> in the current context! Error: Unable to interpret <@="exefile"> in the current context! ========== COMMANDS ========== Restore point Set: OTM Restore Point (0) C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Administrator ->Temp folder emptied: 376832 bytes ->Temporary Internet Files folder emptied: 25856125 bytes ->Flash cache emptied: 1320 bytes User: All Users User: Chris ->Temp folder emptied: 5622899 bytes ->Temporary Internet Files folder emptied: 202740466 bytes ->Java cache emptied: 5122617 bytes ->FireFox cache emptied: 58808486 bytes ->Flash cache emptied: 19302 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: LocalService ->Temp folder emptied: 65984 bytes ->Temporary Internet Files folder emptied: 15816694 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 4348145 bytes User: Owner %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 19569 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 216415784 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes RecycleBin emptied: 250940955 bytes Total Files Cleaned = 750.00 mb OTM by OldTimer - Version 3.1.12.0 log created on 05222010_142059 Files moved on Reboot... File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\OOAMF4VI\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGV4dGZyb20DBGZiAzAEZ nJjb2RlA2NzY195bWFpbGNsBGlzZXh0AzAEaXQDc2hvcnRjdXRzOi91cy9pbnN0YW5jZS9pZGVudGlm[ 1 ].adNoOp&fr=csc_ymailcl not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\OOAMF4VI\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\OOAMF4VI\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\OOAMF4VI\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\OOAMF4VI\ShopsLogout-outside;lang=en_US;acct=;resid=US;DC=F;bcapp=F;bcpre=F;ver=F;F1=f;F2=f;F3=f;F4=f ;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;F18=f; [ 2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\OOAMF4VI\ShopsLogout-outside;lang=en_US;acct=;resid=US;DC=F;bcapp=F;bcpre=F;ver=F;F1=f;F2=f;F3=f;F4=f ;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;F18=f; [ 3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[4] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[5] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\I26L2YSW\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[4] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[4] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\Fym%2Fshowfolder%3Fsearch%3D%26npos%3D6%26next%3D1%26yy%3D16729%26y5beta%3Dyes%26y5beta%3Dyes%26inc%3D25%26order%3Ddown%26sort%3Ddate%26pos%3D5%26view%3Da%26head%3Db%26box%3Dinbox, not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\ShopsLogout-outside;lang=en_US;acct=;resid=US;DC=F;bcapp=F;bcpre=F;ver=F;F1=f;F2=f;F3=f;F4=f ;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;F18=f; [ 2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\H1EN0HN4\ShopsLogout-outside;lang=en_US;acct=;resid=US;DC=F;bcapp=F;bcpre=F;ver=F;F1=f;F2=f;F3=f;F4=f ;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;F18=f; [ 2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[3] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[4] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[5] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;[6] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\AccountOverview-inside;lang=en_US;acct=biz;resid=US;DC=F;bcapp=F;bcpre=F;ver=T;F1=f;F2=f;F3=f;F4 =f;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;[2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\ShopsLogout-outside;lang=en_US;acct=;resid=US;DC=F;bcapp=F;bcpre=F;ver=F;F1=f;F2=f;F3=f;F4=f ;F5=f;F6=f;F7=f;F8=f;F9=f;F10=f;F11=f;F12=f;F13=t;F14=f;F15=f;F16=f;F17=f;F18=f; [ 2] not found! File C:\Documents and Settings\Chris\Local Settings\Temp\Temporary Internet Files\Content.IE5\5F3BW09R\ShopsLogout-outside;lang=en_US;acct=;resid=US;DC=F;bcapp=F;bcpre=F;ver=F;F1=f;F2=f;F3=f;F4=f ;F5=f;F6=f;F7=f;F8=t;F9=t;F10=t;F11=t;F12=f;F13=f;F14=f;F15=f;F16=f;F17=f;F18=f; [ 2] not found! C:\Documents and Settings\Chris\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully. C:\Documents and Settings\Chris\Local Settings\Temp\~DF91E8.tmp moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\X6UGJICK\md[1].htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\TMDVKKI4\180[1].htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\TMDVKKI4\welcome[1].rand=2jpqa4k5s16u4 moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\KNTR7GSB\iframe[1].htm moved successfully. C:\Documents and Settings\Chris\Local Settings\Temporary Internet Files\Content.IE5\9OHFBJLQ\direct=MNW&rn=1274555856765&em=%7B%22site-attribute%22%3A%20%22content%3Dno_expandable%3Bajax_cert_expandable%3BATT_Mail_Portal_Block%22%7D&tgt=_blank&vw=showMessage moved successfully. File C:\WINDOWS\temp\mcmsc_fIHFRgRCATUJdOX not found! File C:\WINDOWS\temp\mcmsc_raSv9f3jpGEWdfQ not found! Registry entries deleted on Reboot...
-
I found the moved files folder but I get this message when I try to upload any of the contents: Upload failed. You are not permitted to upload this type of file
-
How do I find the file?
-
I was able to do everything but I can't open Notepad to paste the results because Notepad won't open like most of the other applications.
-
Here are the updadted DDS. DDS3.txt DDS4.txt
-
As I stated in my message, I was unable to run Defogger and also GMER Root Kit scanner. The virus won't let me run them. The virus will only let me run the DDS. I attached the results and also the malewarebytes file in my prior post. Are you able to help me? Currently when I try to run almost any program a screen pops up stating that "windows can not open this file" and asking me to select a program from a list.
-
-
As I was instructed in a prior forum, I was unable to run Defogger and also GMER Root Kit scanner. The virus will only let me run the DDS. Attached are the results and also the malewarebytes file. Please help. DDS1.zip dds2.zip virus.zip