Jump to content

Please help


Recommended Posts

Hi Dog1 And

:(

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Stay with me until given the 'all clear' even if symptoms diminish. Lack of symptoms does not always mean the job is complete.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by me or another helper.

---------------------------------------------------------------------------------------------

  1. Download ComboFix from below:
    Combofix download
    * IMPORTANT !!! Place combofix.exe on your Desktop
  2. Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  3. Double click on combofix.exe & follow the prompts.
  4. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
    cfRC_screen_1.png
    The Windows recovery console will allow you to boot up into a special recovery mode that allows us to help you in the case that your computer has a problem after an attempted removal of malware.
    With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.
    Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement.
    ComboFix will now automatically install the Microsoft Windows Recovery Console onto your computer, which will show up as a new option when booting up your computer. Do not select the Microsoft Windows Recovery Console option when you start your computer unless requested to by a helper.
    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see a message that says:
    The Recovery Console was successfully installed.
    cfRC_screen_2.png
    Click on Yes, to continue scanning for malware.
  5. Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  6. When finished, it shall produce a log for you. Post that log in your next reply
    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
    ---------------------------------------------------------------------------------------------
  7. Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ---------------------------------------------------------------------------------------------

Link to post
Share on other sites

ComboFix 10-06-14.02 - HP_Owner 06/14/2010 20:17:12.1.1 - x86

Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.503.173 [GMT -5:00]

Running from: c:\documents and settings\HP_Owner\Desktop\ComboFix.exe

AV: CyberDefender Internet Security *On-access scanning enabled* (Updated) {7B5A026C-C0B3-4231-A72F-BFF18A64C940}

AV: Norton Internet Security *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}

FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\docume~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll

c:\documents and settings\All Users\Start Menu\Programs\CyberDefender

c:\documents and settings\All Users\Start Menu\Programs\CyberDefender\Registry Cleaner\CyberDefender Registry Cleaner.lnk

c:\documents and settings\All Users\Start Menu\Programs\CyberDefender\Registry Cleaner\Uninstall CyberDefender Registry Cleaner.lnk

c:\documents and settings\HP_Owner\Application Data\CyberDefender

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\cdrcupdate.ini

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\lastresults.cdr

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275074505.reg

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275075364.reg

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275075734.reg

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\Regclean\1275076115.reg

c:\documents and settings\HP_Owner\Application Data\CyberDefender\Registry Cleaner\SystemRestore.dat

c:\documents and settings\HP_Owner\Local Settings\Temp\IadHide5.dll

c:\program files\CyberDefender

c:\program files\CyberDefender\AntiVirus\CDAVcfg.ini

c:\program files\CyberDefender\AntiVirus\CDAVFS.dll

c:\program files\CyberDefender\AntiVirus\CDAVFS.inf

c:\program files\CyberDefender\AntiVirus\CDAVFS.INF.OLD

c:\program files\CyberDefender\AntiVirus\CDAVFS.sys

c:\program files\CyberDefender\AntiVirus\cdavpat.dat.03

c:\program files\CyberDefender\AntiVirus\cdavpat.dat.04

c:\program files\CyberDefender\AntiVirus\cdavpat.dat.05

c:\program files\CyberDefender\AntiVirus\cdavpat.dat.06

c:\program files\CyberDefender\AntiVirus\CDAVSettings.ini

c:\program files\CyberDefender\AntiVirus\CDAVUpdateHost.ini

c:\program files\CyberDefender\AntiVirus\cdspnsrv.dll

c:\program files\CyberDefender\AntiVirus\CybDefAV.dll

c:\program files\CyberDefender\AntiVirus\CybDefAVUI.dll

c:\program files\CyberDefender\AntiVirus\CybDefExt.dll

c:\program files\CyberDefender\AntiVirus\DisableWindowsFirewall.exe

c:\program files\CyberDefender\AntiVirus\EnableWindowsFirewall.exe

c:\program files\CyberDefender\AntiVirus\UserGuide\CybDefAV.set

c:\program files\CyberDefender\AntiVirus\UserGuide\CybDefAVchk.ini

c:\program files\CyberDefender\AntiVirus\uwcdsoe.dll

c:\program files\CyberDefender\AntiVirus\uwcdsolk.dll

c:\program files\CyberDefender\AntiVirus\uwhook32.dll

c:\program files\CyberDefender\AntiVirus\wslvucfg.ini

c:\program files\CyberDefender\cdinstx.log

c:\program files\CyberDefender\cdrun.exe

c:\program files\CyberDefender\earlySpam\cdaspm.dll

c:\program files\CyberDefender\earlySpam\cdinstx.log

c:\program files\CyberDefender\earlySpam\images\block_normal.bmp

c:\program files\CyberDefender\earlySpam\images\block_over.bmp

c:\program files\CyberDefender\earlySpam\images\earlySPAMBtn.bmp

c:\program files\CyberDefender\earlySpam\images\grant_normal.bmp

c:\program files\CyberDefender\earlySpam\images\grant_over.bmp

c:\program files\CyberDefender\earlySpam\images\options_normal.bmp

c:\program files\CyberDefender\earlySpam\images\options_over.bmp

c:\program files\CyberDefender\earlySpam\images\spy_normal.bmp

c:\program files\CyberDefender\earlySpam\images\spy_over.bmp

c:\program files\CyberDefender\earlySpam\oeapiinitcom.dll

c:\program files\CyberDefender\earlySpam\oecom.dll

c:\program files\CyberDefender\earlySpam\oestore.dll

c:\program files\CyberDefender\earlySpam\uwmyjunk.ini

c:\program files\CyberDefender\eula.rtf

c:\program files\CyberDefender\Registry Cleaner\CDRC.dll

c:\program files\CyberDefender\Registry Cleaner\CDRCU.DLL

c:\program files\CyberDefender\Registry Cleaner\CDregclean.exe

c:\program files\CyberDefender\Registry Cleaner\cduninstx.exe

c:\program files\Shared

c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf

c:\windows\msv1_0.dll

c:\windows\patch.exe

D:\Autorun.inf

.

((((((((((((((((((((((((( Files Created from 2010-05-15 to 2010-06-15 )))))))))))))))))))))))))))))))

.

2010-06-12 19:20 . 2010-06-12 18:20 6153352 ----a-w- C:\mbam-setup-1.46.exe

2010-06-03 21:09 . 2010-06-03 21:09 262672 ----a-w- c:\program files\Common Files\noon.dll

2010-05-31 14:08 . 2010-04-29 20:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-05-31 14:08 . 2010-04-29 20:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys

2010-05-29 17:22 . 2010-05-29 17:22 -------- d-----w- c:\windows\system32\wbem\Repository

2010-05-28 22:17 . 2010-05-28 22:17 -------- d-----w- c:\program files\Microsoft

2010-05-28 22:17 . 2010-05-28 22:17 -------- d-----w- c:\program files\MSN Toolbar

2010-05-28 22:09 . 2010-05-28 22:18 -------- d-----w- c:\program files\Bing Bar Installer

2010-05-28 18:51 . 2010-05-28 18:51 3291736 ----a-w- C:\Registry_Cleaner_PAID.exe

2010-05-25 00:38 . 2010-05-25 00:39 -------- d-----w- c:\program files\ATT Internet Tools

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{25E76F98-E9A4-8ED4-013D-359B62A4E5A6}]

2010-06-03 21:09 262672 ----a-w- c:\program files\Common Files\noon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]

@="{95A27763-F62A-4114-9072-E81D87DE3B68}"

[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]

2009-12-03 22:52 574096 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]

@="{E300CD91-100F-4E67-9AF3-1384A6124015}"

[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]

2009-12-03 22:52 574096 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]

@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"

[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]

2009-12-03 22:52 574096 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-01-23 126976]

"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2004-08-27 58488]

"URLLSTCK.exe"="c:\program files\Norton Internet Security\UrlLstCk.exe" [2004-08-31 33936]

"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-02-26 245760]

"LSBWatcher"="c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe" [2004-10-14 253952]

"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2005-05-06 180269]

"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb09.exe" [2003-07-25 188416]

"YBrowser"="c:\program files\Yahoo!\browser\ybrwicon.exe" [2006-07-21 129536]

"IPInSightLAN 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" [2003-06-11 380928]

"IPInSightMonitor 02"="c:\program files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe" [2003-06-11 122880]

"ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2009-10-22 1577984]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-11 417792]

"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2009-12-03 670864]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-02-16 141608]

"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]

"HPHmon06"="c:\windows\system32\hphmon06.exe" [2004-06-07 659456]

"blspcloader"="c:\program files\ATT Internet Tools\blsloader.exe" [2010-05-25 111952]

"Bing Bar"="c:\program files\MSN Toolbar\Platform\5.0.1423.0\mswinext.exe" [2010-03-24 243544]

"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-11-11 288088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]

"RunNarrator"="Narrator.exe" [2004-08-04 53760]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-4-23 29696]

Anonymizer Total Net Shield.lnk - c:\program files\Anonymizer TNS\AnonTns.exe [2009-8-21 1630944]

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-11-5 258048]

Online plug-in.lnk - c:\windows\Installer\{B8A2256E-6225-4D9E-B1C9-C26CA1E22FEB}\pnaico.exe.20FBBF0A_A7E5_4BDE_9798_9811C3D135AC.exe [2010-2-17 73728]

SBC Self Support Tool.lnk - c:\program files\SBC Self Support Tool\bin\matcli.exe [2005-8-14 217088]

Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2005-5-6 45056]

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]

"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]

"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=

"c:\\Program Files\\iTunes\\iTunes.exe"=

"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=

R1 9lN5C76;9lN5C76;c:\windows\system32\drivers\9lN5C76.sys [8/4/2004 1:00 PM 417088]

R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [9/8/2009 7:13 PM 65584]

--- Other Services/Drivers In Memory ---

*Deregistered* - IPVNMon

.

Contents of the 'Scheduled Tasks' folder

2010-06-08 c:\windows\Tasks\AppleSoftwareUpdate.job

- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 18:34]

2010-06-12 c:\windows\Tasks\Google Software Updater.job

- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-02-15 00:50]

2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 03:34]

2010-06-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-29 03:34]

2010-06-12 c:\windows\Tasks\HP DArC Task 2003-08-20 09:23ewlett-Packard79002003-08-20 20:57N39O321P1EV.job

- c:\program files\HP\hpcoretech\comp\hpdarc.exe [2003-08-20 20:57]

2010-06-13 c:\windows\Tasks\HP Usg Daily.job

- c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\pexpress\hphped05.exe [2007-11-11 21:23]

2005-05-06 c:\windows\Tasks\Symantec NetDetect.job

- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2005-05-06 07:26]

2010-06-15 c:\windows\Tasks\User_Feed_Synchronization-{546B28E4-36CF-4B98-90C0-994BF883EFEE}.job

- c:\windows\system32\msfeedssync.exe [2009-03-08 10:31]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.msn.com

uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q305&bd=pavilion&pf=desktop

mSearch Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.html

uInternet Settings,ProxyOverride = *.local

uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com

IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html

IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html

IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html

IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000

IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html

IE: Translate into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html

IE: Yahoo! Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm

IE: Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm

Trusted Zone: sbcglobal.net

Trusted Zone: yahoo.com

DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-CyberDefender Early Detection Center - c:\program files\CyberDefender\AntiSpyware\cdas3.exe

HKCU-Run-CyberDefender Registry Cleaner - c:\program files\CyberDefender\Registry Cleaner\CDregclean.exe

HKLM-Run-CyberDefender Registry Cleaner - (no file)

SafeBoot-9lN5C76

AddRemove-{AA63780B-DDB7-417b-8A13-E5AFBE08E807} - c:\program files\CyberDefender\cdinstx.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2010-06-14 20:55

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(4640)

c:\windows\system32\WININET.dll

c:\docume~1\HP_Owner\LOCALS~1\Temp\IadHide5.dll

c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll

c:\program files\ATT Internet Tools\blshook_win32.dll

c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll

c:\windows\system32\msi.dll

c:\windows\system32\ieframe.dll

c:\windows\system32\webcheck.dll

c:\program files\Microsoft Office\OFFICE11\msohev.dll

.

------------------------ Other Running Processes ------------------------

.

c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

c:\program files\Bonjour\mDNSResponder.exe

c:\program files\Common Files\LightScribe\LSSrvc.exe

c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

c:\windows\system32\HPZipm12.exe

c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe

c:\windows\system32\wdfmgr.exe

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

c:\progra~1\Yahoo!\browser\ycommon.exe

c:\program files\Citrix\ICA Client\wfcrun32.exe

c:\program files\SBC Self Support Tool\bin\mpbtn.exe

c:\program files\iPod\bin\iPodService.exe

c:\hp\KBD\KBD.EXE

c:\windows\ALCXMNTR.EXE

c:\windows\AGRSMMSG.exe

c:\windows\system\hpsysdrv.exe

c:\program files\Carbonite\Carbonite Backup\carboniteservice.exe

.

**************************************************************************

.

Completion time: 2010-06-14 21:08:55 - machine was rebooted

ComboFix-quarantined-files.txt 2010-06-15 02:08

Pre-Run: 118,360,031,232 bytes free

Post-Run: 121,248,317,440 bytes free

- - End Of File - - 570D7D727056FEE398F4874CCB343FE7

Link to post
Share on other sites

Please download ATF Cleaner by Atribune.

  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

Click Exit on the Main menu to close the program.

Next

Update Run Malwarebytes

  • Launch Malwarebytes' Anti-Malware
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.

Link to post
Share on other sites

Malwarebytes' Anti-Malware 1.46

www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 2

Internet Explorer 8.0.6001.18702

6/16/2010 6:32:38 PM

mbam-log-2010-06-16 (18-32-38).txt

Scan type: Quick scan

Objects scanned: 126643

Time elapsed: 11 minute(s), 9 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 2

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Link to post
Share on other sites

Hi Dog1. Were almost done. How is your PC doing?

Please download the OTM by OldTimer.

  • Save it to your desktop.
  • Please double-click OTM.exe to run it. (Vista users, please right click on OTM.exe and select "Run as an Administrator")
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    :Processes

    :Services

    :Reg

    :Files
    C:\Registry_Cleaner_PAID.exe


    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [EMPTYFLASH]
    [Reboot]


  • Return to OTM, right click in the "Paste instructions for items to be Move" window (under the light Yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • A log of files and folders moved will be created in the c:\_OTM\MovedFiles folder in the form of Date and Time (mmddyyyy_hhmmss.log). Please open this log in Notepad and post its contents in your next reply.
  • Close OTM

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Link to post
Share on other sites

Internet was faster but after OTM it all seems slower.

ll processes killed

Error: Unable to interpret <Processes> in the current context!

========== SERVICES/DRIVERS ==========

========== REGISTRY ==========

========== FILES ==========

C:\Registry_Cleaner_PAID.exe moved successfully.

========== COMMANDS ==========

C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.

HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

User: All Users

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

User: HP_Owner

->Temp folder emptied: 181279 bytes

->Temporary Internet Files folder emptied: 60896072 bytes

->Java cache emptied: 0 bytes

->Flash cache emptied: 1996234 bytes

User: LocalService

->Temp folder emptied: 65748 bytes

->Temporary Internet Files folder emptied: 735582 bytes

->Flash cache emptied: 0 bytes

User: NetworkService

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 33170 bytes

->Flash cache emptied: 6316 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 0 bytes

%systemroot%\System32 .tmp files removed: 2577 bytes

%systemroot%\System32\dllcache .tmp files removed: 0 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes

%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes

RecycleBin emptied: 0 bytes

Total Files Cleaned = 61.00 mb

Restore point Set: OTM Restore Point (0)

OTM by OldTimer - Version 3.1.12.2 log created on 06162010_201107

Files moved on Reboot...

C:\Documents and Settings\HP_Owner\Local Settings\Temp\IadHide5.dll moved successfully.

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF5EBD.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF5ED3.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF60AD.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF60E4.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF6369.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF63B3.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF64EA.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DF64F5.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFCF34.tmp not found!

File C:\Documents and Settings\HP_Owner\Local Settings\Temp\~DFEBF1.tmp not found!

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\A1TCXSN0\iframe[1].html moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\A1TCXSN0\index[3].htm moved successfully.

C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

Registry entries deleted on Reboot...

Link to post
Share on other sites

We'll speed your Internet at the end. We to check your Security so this will not happen again.

Download Security Check from here or here.

  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

Link to post
Share on other sites

Results of screen317's Security Check version 0.99.4

Windows XP Service Pack 2

Out of date service pack!!

Internet Explorer 8

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Disabled!

Norton AntiVirus 2005

Norton Internet Security 2005 (Symantec Corporation)

Norton Internet Security

```````````````````````````````

Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware

Adobe Flash Player

Adobe Reader 6.0.1

Out of date Adobe Reader installed!

````````````````````````````````

Process Check:

objlist.exe by Laurent

Norton Internet Security Norton AntiVirus navapsvc.exe

````````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

``````````End of Log````````````

Link to post
Share on other sites

To remove Norton, Click on Start > Settings > Control Panel

double click on Add/Remove Programs, search for every item that belongs to Norton, Symantec, or LiveUpdate and remove them, reboot when prompt, or reboot manually if your computer hasn't automatically rebooted. To remove the leftovers download and run the Norton Removal Tool, read HERE

Download Avira free:

  • Avira AntiVir Personal - Free anti-virus software for Windows. Detects and removes more than 50000 viruses. Free support.

And enjoyed you new virus program. If you have any problems let me know OK?

Next

Download the latest version of Adobe Reader:

http://get.adobe.com/reader/

Your Computer is Clean

CLEAN-1.jpg

Some final items:

Follow these steps to uninstall Combofix and tools used in the removal of malware

  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the x and /)
    CF_Uninstall-1.jpg
  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.

This will uninstall Combofix and anything assoicated with it.

Here are some additional links for you to check out to help you with your computer security.

Browsers

Just because your computer came loaded with Internet Explorer doesn't mean that you have to use it, there are other free alternatives, FIREFOX and OPERA, both are free to use and are more secure than IE.

If you are using firefox you can stay more secure by adding NoScript and WOT (Web Of Trust)

NoScript stops Java scripts from starting on a web page unless you give permission for them, and WOT (Web Of Trust) has a comprehensive list of ratings for different websites allowing you to easily see if a website that you are about to go to has a bad reputation; in fact it will warn you to check if you are sure that you want to continue to a bad website.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.

Additional Security Measures

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

SpywareBlaster- SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

Cookienator- Scans your PC for tracking cookies in multiple browsers as well as in Adobe Flash.

Winpatrol Download and install the free version of Winpatrol. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.

Secunia software inspector & update checker

My Blog Malware And Spyware Tips

Also, see here for system improvement: Help! My computer is slow!

It was a pleasure working with you Dog1

6567E80CC55576485246E130E48A9FA8.png

Link to post
Share on other sites

Go ahead and use Norton Removal Tool and Install Avira AntiVir. Then lets to a online scan.

Establish an internet connection & perform an online scan with Internet Explorer at Kaspersky Online Scanner

Click Accept, when prompted to download and install the program files and database of malware definitions.

  • Click Run at the Security prompt.
  • The program will then begin downloading and installing and will also update the database.
  • Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.
  • Click the Save Report As... button.
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.

**Note**

To optimize scanning time and produce a more sensible report for review:

  • Close any open programs.
  • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.

Link to post
Share on other sites

  • 2 weeks later...
  • Root Admin

Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you.

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.