Jump to content

kahdah

Experts
  • Posts

    4,024
  • Joined

  • Last visited

Everything posted by kahdah

  1. Ok that tells me what I need to know. Please go to start>run then type in this devmgmt.msc then hit ok. This will open the device manager. Click the plus sign next to sounds video and game controllers. Look there after clicking the plus sign and tell me if you see anything listed with a mark next to it. If you do please tell me the name of what is marked. If nothing is marked also tell me the names of all the devices listed there under the sounds video and game controllers section.
  2. Was it present before uninstalling flv media player? I need to know details in order to troubleshoot this issue please.
  3. Ok that is fine it may have been partially removed and no longer has an add\remove listing, go ahead and see if the browser plays audio fine. If so update and run mbam and remove what it finds. Reboot and see if the audio plays normally. Post the log as well please.
  4. In the add\remove programs list uninstall it from there it will be listed just as it is shown here as Flv media player. To get to that panel go to Start> Control Panel> add\Remove programs. There should be an entry there select it then hit the change\remove button.
  5. Hello Welcome to Malwarebytes. It is NOT a conflict it is an infection. ========================== One or more of the identified infections is a backdoor trojan or rootkit. This type of infection has the capabilities to allows hacker to remotely control your computer, steal critical system information and download and execute files. I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation. Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information: How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud? When Should I Format, How Should I Reinstall We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you still want to clean it please do the following =================== Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop. Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan. If an infected file is detected, the default action will be Cure, click on Continue. If a suspicious file is detected, the default action will be Skip, click on Continue. It may ask you to reboot the computer to complete the process. Click on Reboot Now. If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here. If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. ======== Download ComboFix from one of these locations: Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  6. Hello chrismo4136 Welcome to Malwarebytes. Please try the following to see if it keeps your sound working properly. First let's try to uninstall the programs that I suspect are the issue. Please uninstall the following programs from the Add\remove programs list. flv direct player Zwangi After doing this reboot then run mbam again let it remove the items and reboot again. This time tell me if the sound issues persist. Also please post the new mbam too after the removal.
  7. Hello CaseyJ000 Welcome to Malwarebytes. I would like to see the OTL log files as well please to see if anything is left over as you do have sign of infection in the dds log. ===================== Download OTL to your desktop. Double click on OTL to run it. When the window appears, underneath Output at the top change it to Minimal Output. Under the Standard Registry box change it to All. Check the boxes beside LOP Check and Purity Check. Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  8. Hello JiaWen Welcome to Malwarebytes. ===================== Download OTL to your desktop. Double click on OTL to run it. When the window appears, underneath Output at the top change it to Minimal Output. Under the Standard Registry box change it to All. Check the boxes beside LOP Check and Purity Check. Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. ==================== Download This file. Note its name and save it to your root folder, such as C:\. Disconnect from the Internet and close all running programs. Temporarily disable any real-time active protection so your security program drivers will not conflict with this file. Click on this link to see a list of programs that should be disabled. Double-click on the downloaded file to start the program. (If running Vista, right click on it and select "Run as an Administrator") Allow the driver to load if asked. You may be prompted to scan immediately if it detects rootkit activity. If you are prompted to scan your system click "Yes" to begin the scan. If not prompted, click the "Rootkit/Malware" tab. On the right-side, all items to be scanned should be checked by default except for "Show All". Leave that box unchecked. Select all drives that are connected to your system to be scanned. Click the Scan button to begin. (Please be patient as it can take some time to complete) When the scan is finished, click Save to save the scan results to your Desktop. Save the file as Results.log and copy/paste the contents in your next reply. Exit the program and re-enable all active protection when done.
  9. It is just a toolbar search setting. Please reset IE back to default to get rid of it. To do that open Ie go to tools Internet options> Advanced> click reset and check the box to delete personal settings as well. Close Ie then reopen it the problem will be gone.
  10. Have you tried removing all traces of the alps software rebooting then reinstalling it?
  11. Yes you can resume all normal functions of computer usage. The first 2 folder you can delete yes. The others in the Windows folder can be technically deleted but are good to have if something goes wrong with an update you can uninstall it but yes technically you can delete them. Some temp cleaners do this for you. One such temp cleaner is this one > http://download.cnet.com/Temp-File-Cleaner/3000-2094_4-10628816.html Leaving all the settings at the default level will delete these windows update cache folders automatically. So give that a shot. After that however I recommend upgrading to service pack 3 this will apply a lot more folders like this but also applies security fixes that patch vulnerabilities. You can do that when you have some time since it will take maybe an hour to install it. Sometimes less sometimes more. For the mouse you should be able to disable it. Go to start > Run then type in devmgmt.msc then hit ok. In the window that opens look for a device listed that has a yellow mark next to it. It may say unknown device. If you do not see it then expand the + sign next to mice. It should be listed there with an error symbol next to it. Right click on it and choose disable. Hit yes and it should stop it from trying to install. Once that is done reboot and let me know if that helps out at all.
  12. That is ok just proceed with the rest of the steps. Also delete Combofix from off of the desktop. It is only a switch to uninstall it nothing to worry about.
  13. Great. Sure the following will take care of system restore points as well as remove the leftovers of what we used. =======Cleanup======= Click START then RUN Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the Uninstall, it needs to be there. ======Next====== Double click on OTL to run it. Click on the Cleanup button at the top. You will be asked to reboot the machine to finish the Cleanup process. Choose Yes. This will remove itself and other tools we may have used. ===============Update Java=============== Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update: Download the latest version of Java SE Runtime Environment (JRE) and save it to your desktop. Scroll down to where it says "(JRE) then click on it Click the "Download" button to the right. Select your Platform: "Windows". Select your Language: "Multi-language". Read the License Agreement, and then check the box that says: "Accept License Agreement". Click Continue and the page will refresh. Click on the link to download Windows Offline Installation and save the file to your desktop. Close any programs you may have running - especially your web browser. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-6u25-windows-i586.exe to install the newest version. ======================Clear out infected System Restore points====================== Then we need to reset your System Restore points. The link below shows how to do this. How to Turn On and Turn Off System Restore in Windows XP http://support.microsoft.com/kb/310405/en-us If you are using Vista then see this link: http://www.bleepingcomputer.com/tutorials/...143.html#manual Delete\uninstall anything else that we have used that is leftover. After that your all set. ===The following are some articles and a Windows Update link that I like to suggest to people to prevent malware and general PC maintenance=== Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there. Prevention article Some great guidelines to follow to prevent future infections please read the Prevention artice by Miekiemoes. How did I get infected in the first place? Also this one by Tony Klein. If your computer is slow Things you can do if your computer is slow. PC Safety and Security - What Do I Need? Security suggestions and general hints and tips for PC security. File sharing program dangers Reasons to stay away from File sharing programs for ex: BitTorrent,Limewire,Kazaa,emule,Utorrent etc... ===Free antimalware tools used for on demand scanning and cleaning no real time unless purchased=== Malwarebytes Antimalware superantispyware ===Free antivirus links=== This is antivirus and antispyware. Microsoft Security Essentials This is free antispyware protection and Antivirus protection. AVG free This is just antivirus protection. Antivir This is antivirus and antispyware protection. Avast
  14. Sure another free one is Microsoft security essentials Try to open system restore now and see if it works correctly. See if security essentials will update let me now if it does or doesn't.
  15. We will not need system restore at all. Did you try the different antivirus? Run OTL Under the Custom Scans/Fixes box at the bottom, paste in the following :OTL O4 - HKCU..\Run: [Csulihirewapan] File not found Then click the Run Fix button at the top Let the program run unhindered,when it is done it will say "Fix Complete press ok to open log" Please post that log in your next reply.
  16. Ok the OTL scan seems to be run in safe mode please boot normally and run it again please it is not showing me anything new. So boot normally open OTL click on run scan then post the newest log. As far as system restore we do not need to use it the only thing I ever have anyone do is manually delete all restore points. We will do this before we are done. Leave Combofix for now it will get removed shortly. Also try to install another antivirus such as AVG or Avast your choice and see if hte same thing happens.
  17. It will not create a log if no infections are found. Please open OTL once more and click on Run scan. Please post the new OTL.txt that opens. Also let me know of any remaining issues.
  18. Yes you can re-enable it now. Run OTL Under the Custom Scans/Fixes box at the bottom, paste in the following :OTL O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found. O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O4 - HKCU..\RunOnce: [scan_after_setup] File not found [2011/05/11 23:49:09 | 000,007,558 | -HS- | M] () -- C:\Documents and Settings\All Users\Application Data\t5h3710btkyvc7ysrur63f5pk32e0x8r082s66 :Commands [emptytemp] [resethosts] Then click the Run Fix button at the top Let the program run unhindered, reboot when it is done It will produce a log for you on reboot, please post that log in your next reply. ================================Malwarebytes' Anti-Malware================================= Please update\run Malwarebytes' Anti-Malware. Double Click the Malwarebytes Anti-Malware icon to run the application. Click on the update tab then click on Check for updates. If an update is found, it will download and install the latest version. Once the update has loaded, go to the Scanner tab and select "Perform Full Scan", then click Scan. The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply. Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley. ================================Online scan================================= ESET OnlineScan Click on the following link to open ESET OnlineScan in a new window. ESET OnlineScan Click the button. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps) Click on to download the ESET Smart Installer. Save it to your desktop. Double click on the icon on your desktop. Check Click the button. Accept any security warnings from your browser. Under scan settings, check and check Remove found threats Click Advanced settings and select the following:Scan potentially unwanted applications Scan for potentially unsafe applications Enable Anti-Stealth technology [*]ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time. [*]When the scan completes, push [*]Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply. [*]Push the button. [*]Push
  19. Sure that is fine just thinking it was the version difference causing the crash. Please open OTL once more and click on the run scan tab at the top and post the log that opens up please it will be OTL.txt.
  20. Great I would like to still run Combofix please delete it off of your desktop then redownload a newer copy. You can download it from one of these locations save it to your desktop. Link 1 Link 2
  21. The malware can be removed I just wanted to let you know of the dangers associated with it. OTL will not remove the main infection. Continue on with the steps no need for a system restore as it will bring the infection back. Post those logs and we can continue.
  22. Hello kavv Welcome to Malwarebytes. ===================== One or more of the identified infections is a backdoor trojan or rootkit. This type of infection has the capabilities to allows hacker to remotely control your computer, steal critical system information and download and execute files. I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation. Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information: How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud? When Should I Format, How Should I Reinstall We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you still want to clean it please do the following =================== Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop. Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan. If an infected file is detected, the default action will be Cure, click on Continue. If a suspicious file is detected, the default action will be Skip, click on Continue. It may ask you to reboot the computer to complete the process. Click on Reboot Now. If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here. If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. ======== Download ComboFix from one of these locations: Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  23. Ok. Download ComboFix from one of these locations: Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  24. You are welcome. Can you tell me if you have created this file: D:\WINDOWS\Tasks\Xwdrtu.job
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.