Dog1 Posted June 13, 2010 ID:266875 Share Posted June 13, 2010 I cannot open iTunes, Add/Remove programs to name a couple. I can access the internet.ark.zip Link to post Share on other sites More sharing options...
Kenny94 Posted June 14, 2010 ID:267365 Share Posted June 14, 2010 Hi Dog1 And Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. Stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete. Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by me or another helper.--------------------------------------------------------------------------------------------- Download ComboFix from below:Combofix download* IMPORTANT !!! Place combofix.exe on your DesktopDisable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.You can get help on disabling your protection programs hereDouble click on combofix.exe & follow the prompts.As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed.Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware.With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement.ComboFix will now automatically install the Microsoft Windows Recovery Console onto your computer, which will show up as a new option when booting up your computer. Do not select the Microsoft Windows Recovery Console option when you start your computer unless requested to by a helper.Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see a message that says:The Recovery Console was successfully installed.Click on Yes, to continue scanning for malware.Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal. When finished, it shall produce a log for you. Post that log in your next replyNote:Do not mouseclick combofix's window whilst it's running. That may cause it to stall.---------------------------------------------------------------------------------------------Ensure your AntiVirus and AntiSpyware applications are re-enabled.--------------------------------------------------------------------------------------------- Link to post Share on other sites More sharing options...
Dog1 Posted June 15, 2010 Author ID:267652 Share Posted June 15, 2010 Link to post Share on other sites More sharing options...
Kenny94 Posted June 15, 2010 ID:267956 Share Posted June 15, 2010 Hi Dog1The ComboFix log was cut off on the top. Can you post it again please. The ComboFix.txt is in your C: Drive:And copy and paste the log here. Link to post Share on other sites More sharing options...
Dog1 Posted June 15, 2010 Author ID:268218 Share Posted June 15, 2010 Here is the text file. Thank you Link to post Share on other sites More sharing options...
Dog1 Posted June 15, 2010 Author ID:268219 Share Posted June 15, 2010 ComboFix 10-06-14.02 - HP_Owner 06/14/2010 20:17:12.1.1 - x86Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.173 [GMT -5:00]Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exeAV: CyberDefender Internet Security *On-access scanning enabled* (Updated) {7B5A026C-C0B3-4231-A72F-BFF18A64C940}AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\docume~1\HP_Owner\LOCALS~1\Temp\IadHide5.dllc:\documents and settings\All Users\Start Menu\Programs\CyberDefenderc:\documents and settings\All Users\Start Menu\Programs\CyberDefender\Registry Cleaner\CyberDefender Registry Cleaner.lnkc:\documents and settings\All Users\Start Menu\Programs\CyberDefender\Registry Cleaner\Uninstall CyberDefender Registry Cleaner.lnkc:\documents and settings\HP_Owner\Application Data\CyberDefenderc:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\cdrcupdate.inic:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\lastresults.cdrc:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275074505.regc:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275075364.regc:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275075734.regc:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275076115.regc:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\SystemRestore.datc:\documents and settings\HP_Owner\Local Settings\Temp\IadHide5.dllc:\program files\CyberDefenderc:\program files\CyberDefender\AntiVirus\CDAVcfg.inic:\program files\CyberDefender\AntiVirus\CDAVFS.dllc:\program files\CyberDefender\AntiVirus\CDAVFS.infc:\program files\CyberDefender\AntiVirus\CDAVFS.INF.OLDc:\program files\CyberDefender\AntiVirus\CDAVFS.sysc:\program files\CyberDefender\AntiVirus\cdavpat.dat.03c:\program files\CyberDefender\AntiVirus\cdavpat.dat.04c:\program files\CyberDefender\AntiVirus\cdavpat.dat.05c:\program files\CyberDefender\AntiVirus\cdavpat.dat.06c:\program files\CyberDefender\AntiVirus\CDAVSettings.inic:\program files\CyberDefender\AntiVirus\CDAVUpdateHost.inic:\program files\CyberDefender\AntiVirus\cdspnsrv.dllc:\program files\CyberDefender\AntiVirus\CybDefAV.dllc:\program files\CyberDefender\AntiVirus\CybDefAVUI.dllc:\program files\CyberDefender\AntiVirus\CybDefExt.dllc:\program files\CyberDefender\AntiVirus\DisableWindowsFirewall.exec:\program files\CyberDefender\AntiVirus\EnableWindowsFirewall.exec:\program files\CyberDefender\AntiVirus\UserGuide\CybDefAV.setc:\program files\CyberDefender\AntiVirus\UserGuide\CybDefAVchk.inic:\program files\CyberDefender\AntiVirus\uwcdsoe.dllc:\program files\CyberDefender\AntiVirus\uwcdsolk.dllc:\program files\CyberDefender\AntiVirus\uwhook32.dllc:\program files\CyberDefender\AntiVirus\wslvucfg.inic:\program files\CyberDefender\cdinstx.logc:\program files\CyberDefender\cdrun.exec:\program files\CyberDefender\earlySpam\cdaspm.dllc:\program files\CyberDefender\earlySpam\cdinstx.logc:\program files\CyberDefender\earlySpam\images\block_normal.bmpc:\program files\CyberDefender\earlySpam\images\block_over.bmpc:\program files\CyberDefender\earlySpam\images\earlySPAMBtn.bmpc:\program files\CyberDefender\earlySpam\images\grant_normal.bmpc:\program files\CyberDefender\earlySpam\images\grant_over.bmpc:\program files\CyberDefender\earlySpam\images\options_normal.bmpc:\program files\CyberDefender\earlySpam\images\options_over.bmpc:\program files\CyberDefender\earlySpam\images\spy_normal.bmpc:\program files\CyberDefender\earlySpam\images\spy_over.bmpc:\program files\CyberDefender\earlySpam\oeapiinitcom.dllc:\program files\CyberDefender\earlySpam\oecom.dllc:\program files\CyberDefender\earlySpam\oestore.dllc:\program files\CyberDefender\earlySpam\uwmyjunk.inic:\program files\CyberDefender\eula.rtfc:\program files\CyberDefender\Registry Cleaner\CDRC.dllc:\program files\CyberDefender\Registry Cleaner\CDRCU.DLLc:\program files\CyberDefender\Registry Cleaner\CDregclean.exec:\program files\CyberDefender\Registry Cleaner\cduninstx.exec:\program files\Sharedc:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.infc:\windows\msv1_0.dllc:\windows\patch.exeD:\Autorun.inf.((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 ))))))))))))))))))))))))))))))).2010-06-12 19:20 . 2010-06-12 18:20 6153352 ----a-w- C:\mbam-setup-1.46.exe2010-06-03 21:09 . 2010-06-03 21:09 262672 ----a-w- c:\program files\Common Files\noon.dll2010-05-31 14:08 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2010-05-31 14:08 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys2010-05-29 17:22 . 2010-05-29 17:22 -------- d-----w- c:\windows\system32\wbem\Repository2010-05-28 22:17 . 2010-05-28 22:17 -------- d-----w- c:\program files\Microsoft2010-05-28 22:17 . 2010-05-28 22:17 -------- d-----w- c:\program files\MSN Toolbar2010-05-28 22:09 . 2010-05-28 22:18 -------- d-----w- c:\program files\Bing Bar Installer2010-05-28 18:51 . 2010-05-28 18:51 3291736 ----a-w- C:\Registry_Cleaner_PAID.exe2010-05-25 00:38 . 2010-05-25 00:39 -------- d-----w- c:\program files\ATT Internet Tools.(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))..((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25E76F98-E9A4-8ED4-013D-359B62A4E5A6}]2010-06-03 21:09 262672 ----a-w- c:\program files\Common Files\noon.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]@="{95A27763-F62A-4114-9072-E81D87DE3B68}"[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]2009-12-03 22:52 574096 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]@="{E300CD91-100F-4E67-9AF3-1384A6124015}"[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]2009-12-03 22:52 574096 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]2009-12-03 22:52 574096 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 58488]"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2004-08-31 33936]"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-05-06 180269]"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 188416]"YBrowser"="c:\program files\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]"IPInSightLAN 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" [2003-06-11 380928]"IPInSightMonitor 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" [2003-06-11 122880]"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2009-10-22 1577984]"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-12-03 670864]"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608]"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]"blspcloader"="c:\program files\ATT Internet Tools\blsloader.exe" [2010-05-25 111952]"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe" [2010-03-24 243544]"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]"RunNarrator"="Narrator.exe" [2004-08-04 53760]c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]Anonymizer Total Net Shield.lnk - c:\program files\Anonymizer TNS\AnonTns.exe [2009-8-21 1630944]HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-5 258048]Online plug-in.lnk - c:\windows\Installer\{B8A2256E-6225-4D9E-B1C9-C26CA1E22FEB}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe [2010-2-17 73728]SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2005-8-14 217088]Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2005-5-6 45056][HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]"DisableMonitoring"=dword:00000001[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]"DisableMonitoring"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"="c:\\Program Files\\iTunes\\iTunes.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"=R1 9lN5C76;9lN5C76;c:\windows\system32\drivers\9lN5C76.sys [8/4/2004 1:00 PM 417088]R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [9/8/2009 7:13 PM 65584]--- Other Services/Drivers In Memory ---*Deregistered* - IPVNMon.Contents of the 'Scheduled Tasks' folder2010-06-08 c:\windows\Tasks\AppleSoftwareUpdate.job- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]2010-06-12 c:\windows\Tasks\Google Software Updater.job- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-15 00:50]2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 03:34]2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 03:34]2010-06-12 c:\windows\Tasks\HP DArC Task 2003-08-20 09:23ewlett-Packard79002003-08-20 20:57N39O321P1EV.job- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2003-08-20 20:57]2010-06-13 c:\windows\Tasks\HP Usg Daily.job- c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe [2007-11-11 21:23]2005-05-06 c:\windows\Tasks\Symantec NetDetect.job- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-05-06 07:26]2010-06-15 c:\windows\Tasks\User_Feed_Synchronization-{546B28E4-36CF-4B98-90C0-994BF883EFEE}.job- c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]..------- Supplementary Scan -------.uStart Page = hxxp://www.msn.comuDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktopmSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.htmluInternet Settings,ProxyOverride = *.localuSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.comIE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.htmlIE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.htmlIE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.htmlIE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.htmlIE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.htmlIE: Yahoo! Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htmIE: Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htmTrusted Zone: sbcglobal.netTrusted Zone: yahoo.comDPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab.- - - - ORPHANS REMOVED - - - -HKCU-Run-CyberDefender Early Detection Center - c:\program files\CyberDefender\AntiSpyware\cdas3.exeHKCU-Run-CyberDefender Registry Cleaner - c:\program files\CyberDefender\Registry Cleaner\CDregclean.exeHKLM-Run-CyberDefender Registry Cleaner - (no file)SafeBoot-9lN5C76AddRemove-{AA63780B-DDB7-417b-8A13-E5AFBE08E807} - c:\program files\CyberDefender\cdinstx.exe**************************************************************************catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2010-06-14 20:55Windows 5.1.2600 Service Pack 2 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'explorer.exe'(4640)c:\windows\system32\WININET.dllc:\docume~1\HP_Owner\LOCALS~1\Temp\IadHide5.dllc:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dllc:\program files\ATT Internet Tools\blshook_win32.dllc:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dllc:\windows\system32\msi.dllc:\windows\system32\ieframe.dllc:\windows\system32\webcheck.dllc:\program files\Microsoft Office\OFFICE11\msohev.dll.------------------------ Other Running Processes ------------------------.c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exec:\program files\Bonjour\mDNSResponder.exec:\program files\Common Files\LightScribe\LSSrvc.exec:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEc:\windows\system32\HPZipm12.exec:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exec:\windows\system32\wdfmgr.exec:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXEc:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exec:\progra~1\Yahoo!\browser\ycommon.exec:\program files\Citrix\ICA Client\wfcrun32.exec:\program files\SBC Self Support Tool\bin\mpbtn.exec:\program files\iPod\bin\iPodService.exec:\hp\KBD\KBD.EXEc:\windows\ALCXMNTR.EXEc:\windows\AGRSMMSG.exec:\windows\system\hpsysdrv.exec:\program files\Carbonite\Carbonite Backup\carboniteservice.exe.**************************************************************************.Completion time: 2010-06-14 21:08:55 - machine was rebootedComboFix-quarantined-files.txt 2010-06-15 02:08Pre-Run: 118,360,031,232 bytes freePost-Run: 121,248,317,440 bytes free- - End Of File - - 570D7D727056FEE398F4874CCB343FE7 Link to post Share on other sites More sharing options...
Kenny94 Posted June 16, 2010 ID:268221 Share Posted June 16, 2010 Please download ATF Cleaner by Atribune. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button.Click Exit on the Main menu to close the program. NextUpdate Run MalwarebytesLaunch Malwarebytes' Anti-MalwareIf an update is found, it will download and install the latest version.Once the program has loaded, select "Perform Quick Scan", then click Scan.The scan may take some time to finish,so please be patient.When the scan is complete, click OK, then Show Results to view the results.Make sure that everything is checked, and click Remove Selected.When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.Copy&Paste the entire report in your next reply.Extra Note:If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Link to post Share on other sites More sharing options...
Dog1 Posted June 17, 2010 Author ID:268782 Share Posted June 17, 2010 Malwarebytes' Anti-Malware 1.46www.malwarebytes.orgDatabase version: 4052Windows 5.1.2600 Service Pack 2Internet Explorer 8.0.6001.187026/16/2010 6:32:38 PMmbam-log-2010-06-16 (18-32-38).txtScan type: Quick scanObjects scanned: 126643Time elapsed: 11 minute(s), 9 second(s)Memory Processes Infected: 0Memory Modules Infected: 0Registry Keys Infected: 0Registry Values Infected: 0Registry Data Items Infected: 2Folders Infected: 0Files Infected: 0Memory Processes Infected:(No malicious items detected)Memory Modules Infected:(No malicious items detected)Registry Keys Infected:(No malicious items detected)Registry Values Infected:(No malicious items detected)Registry Data Items Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.Folders Infected:(No malicious items detected)Files Infected:(No malicious items detected) Link to post Share on other sites More sharing options...
Kenny94 Posted June 17, 2010 ID:268794 Share Posted June 17, 2010 Hi Dog1. Were almost done. How is your PC doing?Please download the OTM by OldTimer. Save it to your desktop. Please double-click OTM.exe to run it. (Vista users, please right click on OTM.exe and select "Run as an Administrator")Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)::Processes:Services:Reg:FilesC:\Registry_Cleaner_PAID.exe:Commands[purity][resethosts][emptytemp][CREATERESTOREPOINT][EMPTYFLASH][Reboot] Return to OTM, right click in the "Paste instructions for items to be Move" window (under the light Yellow bar) and choose Paste.Click the red Moveit! button.A log of files and folders moved will be created in the c:\_OTM\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.Close OTMIf a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. Link to post Share on other sites More sharing options...
Dog1 Posted June 17, 2010 Author ID:268802 Share Posted June 17, 2010 Internet was faster but after OTM it all seems slower.ll processes killedError: Unable to interpret <Processes> in the current context!========== SERVICES/DRIVERS ==================== REGISTRY ==================== FILES ==========C:\Registry_Cleaner_PAID.exe moved successfully.========== COMMANDS ==========C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.HOSTS file reset successfully[EMPTYTEMP]User: Administrator->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 67 bytesUser: All UsersUser: Default User->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 0 bytesUser: HP_Owner->Temp folder emptied: 181279 bytes->Temporary Internet Files folder emptied: 60896072 bytes->Java cache emptied: 0 bytes->Flash cache emptied: 1996234 bytesUser: LocalService->Temp folder emptied: 65748 bytes->Temporary Internet Files folder emptied: 735582 bytes->Flash cache emptied: 0 bytesUser: NetworkService->Temp folder emptied: 0 bytes->Temporary Internet Files folder emptied: 33170 bytes->Flash cache emptied: 6316 bytes%systemdrive% .tmp files removed: 0 bytes%systemroot% .tmp files removed: 0 bytes%systemroot%\System32 .tmp files removed: 2577 bytes%systemroot%\System32\dllcache .tmp files removed: 0 bytes%systemroot%\System32\drivers .tmp files removed: 0 bytesWindows Temp folder emptied: 0 bytes%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytesRecycleBin emptied: 0 bytesTotal Files Cleaned = 61.00 mbRestore point Set: OTM Restore Point (0)OTM by OldTimer - Version 3.1.12.2 log created on 06162010_201107Files moved on Reboot...C:\Documents and Settings\HP_Owner\Local Settings\Temp\IadHide5.dll moved successfully.File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF5EBD.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF5ED3.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF60AD.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF60E4.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF6369.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF63B3.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF64EA.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF64F5.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFCF34.tmp not found!File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFEBF1.tmp not found!C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\A1TCXSN0\iframe[1].html moved successfully.C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\A1TCXSN0\index[3].htm moved successfully.C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.Registry entries deleted on Reboot... Link to post Share on other sites More sharing options...
Kenny94 Posted June 17, 2010 ID:268982 Share Posted June 17, 2010 We'll speed your Internet at the end. We to check your Security so this will not happen again.Download Security Check from here or here.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.A Notepad document should open automatically called checkup.txt; please post the contents of that document. Link to post Share on other sites More sharing options...
Dog1 Posted June 18, 2010 Author ID:269351 Share Posted June 18, 2010 Results of screen317's Security Check version 0.99.4 Windows XP Service Pack 2 Out of date service pack!! Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Norton AntiVirus 2005 Norton Internet Security 2005 (Symantec Corporation) Norton Internet Security ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Adobe Flash Player Adobe Reader 6.0.1 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Norton Internet Security Norton AntiVirus navapsvc.exe ````````````````````````````````DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning) ``````````End of Log```````````` Link to post Share on other sites More sharing options...
Kenny94 Posted June 18, 2010 ID:269356 Share Posted June 18, 2010 Norton AntiVirus 2005 Norton Internet Security 2005 (Symantec Corporation) Norton Internet SecurityIs Norton Internet Security up to date? Link to post Share on other sites More sharing options...
Dog1 Posted June 18, 2010 Author ID:269358 Share Posted June 18, 2010 No, it expired some time ago but still keeps showing up Link to post Share on other sites More sharing options...
Kenny94 Posted June 18, 2010 ID:269360 Share Posted June 18, 2010 Do have virus program with AT&T? If not, I have a free one for you that I use. Link to post Share on other sites More sharing options...
Kenny94 Posted June 18, 2010 ID:269374 Share Posted June 18, 2010 To remove Norton, Click on Start > Settings > Control Panel double click on Add/Remove Programs, search for every item that belongs to Norton, Symantec, or LiveUpdate and remove them, reboot when prompt, or reboot manually if your computer hasn't automatically rebooted. To remove the leftovers download and run the Norton Removal Tool, read HEREDownload Avira free:Avira AntiVir Personal - Free anti-virus software for Windows. Detects and removes more than 50000 viruses. Free support.And enjoyed you new virus program. If you have any problems let me know OK?NextDownload the latest version of Adobe Reader:http://get.adobe.com/reader/Your Computer is CleanSome final items:Follow these steps to uninstall Combofix and tools used in the removal of malwarePlease press the Windows Key and R on your keyboard. This will bring up the Run... command.Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the x and /)Please follow the prompts to uninstall Combofix.You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.This will uninstall Combofix and anything assoicated with it.Here are some additional links for you to check out to help you with your computer security. BrowsersJust because your computer came loaded with Internet Explorer doesn't mean that you have to use it, there are other free alternatives, FIREFOX and OPERA, both are free to use and are more secure than IE. If you are using firefox you can stay more secure by adding NoScript and WOT (Web Of Trust)NoScript stops Java scripts from starting on a web page unless you give permission for them, and WOT (Web Of Trust) has a comprehensive list of ratings for different websites allowing you to easily see if a website that you are about to go to has a bad reputation; in fact it will warn you to check if you are sure that you want to continue to a bad website.Make your Internet Explorer more secure - This can be done by following these simple instructions:From within Internet Explorer click on the Tools menu and then click on Options.Click once on the Security tabClick once on the Internet icon so it becomes highlighted.Click once on the Custom Level button.Change the Download signed ActiveX controls to PromptChange the Download unsigned ActiveX controls to DisableChange the Initialize and script ActiveX controls not marked as safe to DisableChange the Installation of desktop items to PromptChange the Launching programs and files in an IFRAME to PromptChange the Navigate sub-frames across different domains to PromptWhen all these settings have been made, click on the OK buttonIf it prompts you as to whether or not you want to save the settings, press the Yes button.Next press the Apply button and then the OK to exit the Internet Properties page.Additional Security MeasuresVisit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.SpywareBlaster- SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.Cookienator- Scans your PC for tracking cookies in multiple browsers as well as in Adobe Flash.Winpatrol Download and install the free version of Winpatrol. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.Secunia software inspector & update checker My Blog Malware And Spyware TipsAlso, see here for system improvement: Help! My computer is slow!It was a pleasure working with you Dog1 Link to post Share on other sites More sharing options...
Dog1 Posted June 18, 2010 Author ID:269388 Share Posted June 18, 2010 Thanks, but I still cannot access Add/Remove Programs. Link to post Share on other sites More sharing options...
Kenny94 Posted June 18, 2010 ID:269419 Share Posted June 18, 2010 Go ahead and use Norton Removal Tool and Install Avira AntiVir. Then lets to a online scan.Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online ScannerClick Accept, when prompted to download and install the program files and database of malware definitions. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes. Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan. Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it. Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined. Click View scan report at the bottom. Click the Save Report As... button. Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.**Note**To optimize scanning time and produce a more sensible report for review:Close any open programs.Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted June 29, 2010 Root Admin ID:276342 Share Posted June 29, 2010 Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Thanks!The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you. Link to post Share on other sites More sharing options...
Recommended Posts