Jump to content

kahdah

Experts
  • Posts

    4,023
  • Joined

  • Last visited

Everything posted by kahdah

  1. Network diagnostic does disable then is supposed to re-enable the adapter. If it does not re-enable then their could be a problem with the device itself. Have you tried to update the drivers? If not try doing that.
  2. Which drive is drive 1 what is on it? Is it external?
  3. Internet issues are separate from hard drive issues. The check disk did not start up again did it? You may have a network card issue or a faulty cable or intermittent issues with your isp. Try to reboot the modem you have. To do this just power it down then back on again. See then if the issue persists.
  4. thank you. Run OTL Under the Custom Scans/Fixes box at the bottom, paste in the following :Files c:\windows\system32\drivers\rurfmsvnl.sys :Commands [emptytemp] Then click the Run Fix button at the top Let the program run unhindered, reboot when it is done It will produce a log for you on reboot, please post that log in your next reply. ================================Malwarebytes' Anti-Malware================================= Please update\run Malwarebytes' Anti-Malware. Double Click the Malwarebytes Anti-Malware icon to run the application. Click on the update tab then click on Check for updates. If an update is found, it will download and install the latest version. Once the update has loaded, go to the Scanner tab and select "Perform Full Scan", then click Scan. The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply. Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley. ================================Online scan================================= * Go here to run an online scannner from ESET. Note: You will need to use Internet explorer for this scan Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activex control to install Click Start Check next options: Remove found threats and Scan unwanted applications. Click Scan Wait for the scan to finish Use notepad to open the logfile located at C:\Program Files\ESET\ESET Online Scanner\log.txt Copy and paste that log as a reply to this topic
  5. Hi you uploaded the wrong file please upload the following .zip C:\Qoobox\Quarantine\[4]-Submit_Date_Time.zip Thank you.
  6. Reboot and the message will quit. 1. Please open Notepad Click Start , then Run type in notepad in the Run Box then hit ok. 2. Now copy/paste the entire content of the codebox below into the Notepad window: http://forums.malwarebytes.org/index.php?showtopic=72156 Driver:: rurfmsvnl Collect:: C:\Windows\system32\drivers\rurfmsvnl.sys 3. Save the above as CFScript.txt Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. 4. During this run Combofix will collect and attempt to automatically upload some sample files. You will see it say Combofix needs to upload some samples. If it fails to do that do the requested steps at the bottom of this post to manually upload the samples. 5. After reboot, (in case it asks to reboot), please post the following report/log into your next reply: Combofix.txt =========== Note:: If Combofix fails to upload anything please do the following: Go to Start > My Computer > C:\ Then Navigate to C:\Qoobox\Quarantine\[4]-Submit_Date_Time.zip Click Here to upload the submit.zip please.
  7. Please run tdsskiller once more and choose cure reboot and run it again and let me know if it still finds the infection.
  8. @dunmer2007 please do not post in some one else's thread. @Deadpuck It depends what kind of drive is it? Typically if the drive is showing signs of failing the only sure way to fix it is ti replace the drive. Sometimes diagnostic tests can fix some sectors for a while but the problem will return eventually.
  9. One or more of the identified infections is a backdoor trojan or rootkit. This type of infection has the capabilities to allows hacker to remotely control your computer, steal critical system information and download and execute files. I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation. Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information: How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud? When Should I Format, How Should I Reinstall We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you still want to clean it please do the following =================== Please visit this webpage for download links, and instructions for running ComboFix: http://www.bleepingcomputer.com/combofix/how-to-use-combofix * Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix. Please include the C:\ComboFix.txt in your next reply for further review.
  10. Hello Wofstar Welcome to Malwarebytes. ===================== That detection is a false positive it is a setup file for AOL Instant messenger. You can safely ignore it.
  11. Hello Deadpuck Welcome to Malwarebytes. ===================== That usually means that the hard drive is failing and that the files are corrupted. The more you use it the worse it will get.
  12. Hello tec Welcome to Malwarebytes. ===================== One or more of the identified infections is a backdoor trojan or rootkit. This type of infection has the capabilities to allows hacker to remotely control your computer, steal critical system information and download and execute files. I would counsel you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation. Though the trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very likely compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information: How Do I Handle Possible Identity Theft, Internet Fraud and CC Fraud? When Should I Format, How Should I Reinstall We can still clean this machine but I can't guarantee that it will be 100% secure afterwards. Let me know what you decide to do. If you still want to clean it please do the following =================== Download TDSSKiller and save it to your Desktop. Extract its contents to your desktop. Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan. If an infected file is detected, the default action will be Cure, click on Continue. If a suspicious file is detected, the default action will be Skip, click on Continue. It may ask you to reboot the computer to complete the process. Click on Reboot Now. If no reboot is required, click on Report. A log file should appear. Please copy and paste the contents of that file here. If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here. ======== Download ComboFix from one of these locations: Link 1 Link 2 * IMPORTANT !!! Save ComboFix.exe to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools Double click on ComboFix.exe & follow the prompts. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
  13. Hello needhelpplz Welcome to Malwarebytes. ===================== Download OTL to your desktop. Double click on OTL to run it. When the window appears, underneath Output at the top change it to Minimal Output. Under the Standard Registry box change it to All. Check the boxes beside LOP Check and Purity Check. Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  14. Hello henkis Welcome to Malwarebytes. Please also post the tdsskiller log showing the infection. ===================== Download OTL to your desktop. Double click on OTL to run it. When the window appears, underneath Output at the top change it to Minimal Output. Under the Standard Registry box change it to All. Check the boxes beside LOP Check and Purity Check. Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long. When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL. Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  15. Not sure but I think it actually hijacks the dns and sends your system mal sites to click on. Glad it is sorted now though.
  16. Hi I asked you to download it in this post. http://forums.malwarebytes.org/index.php?s...st&p=367113
  17. Yes I will have someone remove the logs. Please visit this page and install the latest version of Adobe reader: http://get.adobe.com/reader/ =======Cleanup======= Click START then RUN Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the Uninstall, it needs to be there. ===============Update Java=============== Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update: Download the latest version of Java SE Runtime Environment (JRE) and save it to your desktop. Scroll down to where it says "(JRE) then click on it Click the "Download" button to the right. Select your Platform: "Windows". Select your Language: "Multi-language". Read the License Agreement, and then check the box that says: "Accept License Agreement". Click Continue and the page will refresh. Click on the link to download Windows Offline Installation and save the file to your desktop. Close any programs you may have running - especially your web browser. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-6u23-windows-i586.exe to install the newest version. ============ Delete\uninstall anything else that we have used that is leftover. After that your all set. ===The following are some articles and a Windows Update link that I like to suggest to people to prevent malware and general PC maintenance=== Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there. Prevention article Some great guidelines to follow to prevent future infections please read the Prevention artice by Miekiemoes. How did I get infected in the first place? Also this one by Tony Klein. If your computer is slow Things you can do if your computer is slow. PC Safety and Security - What Do I Need? Security suggestions and general hints and tips for PC security. File sharing program dangers Reasons to stay away from File sharing programs for ex: BitTorrent,Limewire,Kazaa,emule,Utorrent etc... ===Free antimalware tools used for on demand scanning and cleaning no real time unless purchased===
  18. The only way to tell is to disable the antivirus then redownload it. Try that first then let me know.
  19. Great. Please install the newest version of Adobe reader from here > http://get.adobe.com/reader/ It will automatically uninstall the old version. ======Next====== Double click on OTL to run it. Click on the Cleanup button at the top. You will be asked to reboot the machine to finish the Cleanup process. Choose Yes. This will remove itself and other tools we may have used. ===============Update Java=============== Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to exploit and infect your system. Please follow these steps to remove older version Java components and update: Download the latest version of Java SE Runtime Environment (JRE) and save it to your desktop. Scroll down to where it says "(JRE) then click on it Click the "Download" button to the right. Select your Platform: "Windows". Select your Language: "Multi-language". Read the License Agreement, and then check the box that says: "Accept License Agreement". Click Continue and the page will refresh. Click on the link to download Windows Offline Installation and save the file to your desktop. Close any programs you may have running - especially your web browser. Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. Reboot your computer once all Java components are removed. Then from your desktop double-click on jre-6u23-windows-i586.exe to install the newest version. ======================Clear out infected System Restore points====================== Then we need to reset your System Restore points. The link below shows how to do this. How to Turn On and Turn Off System Restore in Windows XP http://support.microsoft.com/kb/310405/en-us If you are using Vista then see this link: http://www.bleepingcomputer.com/tutorials/...143.html#manual Delete\uninstall anything else that we have used that is leftover. After that your all set. ===The following are some articles and a Windows Update link that I like to suggest to people to prevent malware and general PC maintenance=== Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there. Prevention article Some great guidelines to follow to prevent future infections please read the Prevention artice by Miekiemoes. How did I get infected in the first place? Also this one by Tony Klein. If your computer is slow Things you can do if your computer is slow. PC Safety and Security - What Do I Need? Security suggestions and general hints and tips for PC security. File sharing program dangers Reasons to stay away from File sharing programs for ex: BitTorrent,Limewire,Kazaa,emule,Utorrent etc... ===Free antimalware tools used for on demand scanning and cleaning no real time unless purchased=== Malwarebytes Antimalware superantispyware ===Free antivirus links=== This is antivirus and antispyware. Microsoft Security Essentials This is free antispyware protection and Antivirus protection. AVG free This is just antivirus protection. Antivir This is antivirus and antispyware protection. Avast
  20. Run OTL Under the Custom Scans/Fixes box at the bottom, paste in the following :OTL O33 - MountPoints2\{b0ee2afb-ed81-11de-9fd5-001320a6946f}\Shell\AutoRun\command - "" = G:\MI.exe -- File not found [2010/12/29 14:57:22 | 000,000,324 | -HS- | M] () -- C:\WINDOWS\tasks\ZAHIASCLS.job :Commands [emptytemp] Then click the Run Fix button at the top Let the program run unhindered, reboot when it is done It will produce a log for you on reboot, please post that log in your next reply. ================================Malwarebytes' Anti-Malware================================= Please update\run Malwarebytes' Anti-Malware. Double Click the Malwarebytes Anti-Malware icon to run the application. Click on the update tab then click on Check for updates. If an update is found, it will download and install the latest version. Once the update has loaded, go to the Scanner tab and select "Perform Full Scan", then click Scan. The scan may take some time to finish,so please be patient. When the scan is complete, click OK, then Show Results to view the results. Make sure that everything is checked, and click Remove Selected. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note) The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM. Copy&Paste the entire report in your next reply. Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatley. ================================Online scan================================= * Go here to run an online scannner from ESET. Note: You will need to use Internet explorer for this scan Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the activex control to install Click Start Check next options: Remove found threats and Scan unwanted applications. Click Scan Wait for the scan to finish Use notepad to open the logfile located at C:\Program Files\ESET\ESET Online Scanner\log.txt Copy and paste that log as a reply to this topic
  21. Could be a newer variant but it is just a renamed copy of explorer that was not detected yet but by norton. Actually simply deleting the file will remove that. That was simply a leftover from before so it is nothing to worry about. Other than that how are things running?
  22. Hello csaul Welcome to Malwarebytes. ===================== You will need to reset the router to get rid of this infection. It is inside of the router. Do that then you will be fine. Let me know if that does not fix it.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.