Welcome Guest ( Log In | Join )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide. Want to reply to a topic, start a new one, or remove the advertising? Join today (always free).
      
 
Closed TopicStart new topic
Pop Ups, Windows Update Impossible [CLOSED], help, first tme hijack this log
puppetpimp
post Oct 3 2008, 11:33 AM
Post #1


New Member
*
Posts: 2
OS: XP



hello,
I continue to get full screen popups every few minutes while using IE.
It also seems that any connection to windows.com has been disabled, this includes hotmail as well as windows updates.

Spyware search & destroy finds nothing:

Here is my log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:45:14 PM, on 10/2/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Mirra\Mirra.Client.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
c:\program files\mirra\mirra.service.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [3cca309c] rundll32.exe "C:\WINDOWS\system32\bodgcugv.dll",b
O4 - HKLM\..\Run: [BM3ff90300] Rundll32.exe "C:\WINDOWS\system32\yxvuhjcy.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: Mirra.lnk = ?
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: Bonjour - {7F9DB11C-E358-4ca6-A83D-ACC663939424} - C:\Program Files\Bonjour\ExplorerPlugin.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1222591429062
O20 - AppInit_DLLs: fwedjr.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MirraSync Service (Mirra.Service) - Seagate Technology - c:\program files\mirra\mirra.service.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

--
End of file - 5400 bytes


THANK YOU
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 3 2008, 12:47 PM
Post #2


GeekU Teacher
Group Icon
Posts: 19,791
From: Dublin
OS: XP



Hello

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.



Disable resident protections (Antivirus...); you'll re-enable them after the scan

Download Lop S&D < here

Double-click Lop S&D.exe
Choose the language, then choose Option 1 (Search)
Wait till the end of the scan
Post the log which is created: (%SystemDrive%\lopR.txt)



Go to the top of the page
 
+Quote Post
puppetpimp
post Oct 3 2008, 01:27 PM
Post #3


New Member
*
Posts: 2
OS: XP



wow, thank you so much for the fast help and of course sharing your time!
i did the vubdofix and it found nothing.

Here is my log from Loop S&D



--------------------\\ Lop S&D 4.2.4-5 XP/Vista

Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel® Pentium® 4 CPU 3.00GHz )
BIOS : BIOS Date: 11/04/04 20:48:18 Ver: 08.00.09
USER : Generations Beyond ( Administrator )
BOOT : Normal boot
A:\ (USB)
C:\ (Local Disk) - NTFS - Total : 465 Go Free : 381 Go
D:\ (CD or DVD) - CDFS - Total : 2 Go Free : 0 Go
E:\ (CD or DVD)

"C:\Lop SD" ( MAJ : 02-10-2008|23:42 )
Option : [1] ( Fri 10/03/2008|15:14 )

--------------------\\ Listing folders in APPLIC~1

[09/28/2008|02:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> acccore
[10/03/2008|02:06] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe
[09/28/2008|04:05] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Adobe Systems
[09/28/2008|02:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL
[09/28/2008|02:10] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> AOL OCP
[09/29/2008|11:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple
[09/28/2008|03:57] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Apple Computer
[09/30/2008|11:30] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> eFax Messenger 4.4 Output
[09/29/2008|12:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> FLEXnet
[09/28/2008|04:13] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Macromedia
[09/29/2008|03:24] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Microsoft
[10/03/2008|03:03] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Mirra
[09/28/2008|03:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Quark
[10/02/2008|12:31] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Spybot - Search & Destroy
[09/28/2008|02:11] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Viewpoint
[09/28/2008|01:44] C:\DOCUME~1\ALLUSE~1\APPLIC~1\<DIR> Windows Genuine Advantage

[09/28/2008|12:39] C:\DOCUME~1\DEFAUL~1\APPLIC~1\<DIR> Microsoft

[09/28/2008|04:41] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> .BitTornado
[09/28/2008|02:11] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> acccore
[10/03/2008|02:07] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Adobe
[09/28/2008|04:06] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> AdobeUM
[09/28/2008|03:59] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Apple Computer
[10/01/2008|03:13] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Canon
[09/28/2008|05:27] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> DivX
[09/30/2008|11:30] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> eFax Messenger
[09/28/2008|04:42] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> GlobalSCAPE
[09/28/2008|01:38] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Identities
[09/29/2008|03:55] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> InstallShield
[10/01/2008|11:16] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> j2 Global
[09/28/2008|04:14] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Macromedia
[10/01/2008|11:05] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Microsoft
[09/28/2008|03:47] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Microsoft Web Folders
[09/28/2008|03:44] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Quark
[09/28/2008|04:10] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> Winamp
[09/28/2008|03:56] C:\DOCUME~1\GENERA~1\APPLIC~1\<DIR> WinRAR

[09/28/2008|03:35] C:\DOCUME~1\LOCALS~1\APPLIC~1\<DIR> Microsoft

[10/01/2008|01:09] C:\DOCUME~1\NETWOR~1\APPLIC~1\<DIR> Microsoft

--------------------\\ Scheduled Tasks located in C:\WINDOWS\Tasks

[10/03/2008 02:32 PM][--ah-----] C:\WINDOWS\tasks\User_Feed_Synchronization-{66FC435F-2269-4576-B52A-49E4E87F23F4}.job
[10/03/2008 02:51 PM][--ah-----] C:\WINDOWS\tasks\SA.DAT
[03/31/2003 05:00 AM][-r-h-----] C:\WINDOWS\tasks\desktop.ini

--------------------\\ Listing Folders in C:\Program Files

[10/03/2008|02:07] C:\Program Files\<DIR> Adobe
[09/28/2008|02:02] C:\Program Files\<DIR> Adobe Type Manager
[09/28/2008|04:52] C:\Program Files\<DIR> Ahead
[09/28/2008|02:11] C:\Program Files\<DIR> AIM6
[09/28/2008|05:22] C:\Program Files\<DIR> Analog Devices
[09/29/2008|11:31] C:\Program Files\<DIR> Apple Software Update
[09/28/2008|02:29] C:\Program Files\<DIR> Audacity
[09/28/2008|02:03] C:\Program Files\<DIR> BitTornado
[09/29/2008|11:34] C:\Program Files\<DIR> Bonjour
[09/28/2008|04:52] C:\Program Files\<DIR> Common Files
[09/28/2008|12:37] C:\Program Files\<DIR> ComPlus Applications
[09/28/2008|02:08] C:\Program Files\<DIR> DivX
[09/30/2008|11:30] C:\Program Files\<DIR> eFax Messenger 4.4
[09/28/2008|04:15] C:\Program Files\<DIR> FXhome VisionLab Studio
[09/28/2008|04:42] C:\Program Files\<DIR> GlobalSCAPE
[09/28/2008|04:47] C:\Program Files\<DIR> InstallShield Installation Information
[09/28/2008|04:38] C:\Program Files\<DIR> Internet Explorer
[09/28/2008|04:47] C:\Program Files\<DIR> Macromedia
[09/28/2008|04:35] C:\Program Files\<DIR> Messenger
[09/28/2008|03:47] C:\Program Files\<DIR> microsoft frontpage
[09/28/2008|03:47] C:\Program Files\<DIR> Microsoft Office
[09/28/2008|03:49] C:\Program Files\<DIR> Microsoft Visual Studio
[09/28/2008|02:34] C:\Program Files\<DIR> Microsoft Works
[09/29/2008|03:56] C:\Program Files\<DIR> Mirra
[09/28/2008|02:15] C:\Program Files\<DIR> Movie Maker
[09/28/2008|12:37] C:\Program Files\<DIR> MSN
[09/28/2008|12:37] C:\Program Files\<DIR> MSN Gaming Zone
[09/28/2008|02:14] C:\Program Files\<DIR> NetMeeting
[09/28/2008|12:37] C:\Program Files\<DIR> Online Services
[09/28/2008|02:14] C:\Program Files\<DIR> Outlook Express
[09/28/2008|03:43] C:\Program Files\<DIR> Quark
[09/28/2008|03:58] C:\Program Files\<DIR> QuickTime
[10/02/2008|12:31] C:\Program Files\<DIR> Spybot - Search & Destroy
[10/02/2008|09:20] C:\Program Files\<DIR> Trend Micro
[09/28/2008|02:32] C:\Program Files\<DIR> True BoxShot
[09/28/2008|01:38] C:\Program Files\<DIR> Uninstall Information
[09/28/2008|02:11] C:\Program Files\<DIR> Viewpoint
[09/28/2008|02:44] C:\Program Files\<DIR> Winamp
[09/28/2008|03:41] C:\Program Files\<DIR> Windows Media Connect 2
[09/28/2008|04:17] C:\Program Files\<DIR> Windows Media Player
[09/28/2008|02:14] C:\Program Files\<DIR> Windows NT
[09/28/2008|12:37] C:\Program Files\<DIR> WindowsUpdate
[09/28/2008|03:56] C:\Program Files\<DIR> WinRAR
[09/28/2008|02:19] C:\Program Files\<DIR> WinZip
[09/28/2008|12:39] C:\Program Files\<DIR> xerox
[09/28/2008|02:06] C:\Program Files\<DIR> Xvid

--------------------\\ Listing Folders in C:\Program Files\Common Files

[10/03/2008|02:06] C:\Program Files\Common Files\<DIR> Adobe
[09/28/2008|04:05] C:\Program Files\Common Files\<DIR> Adobe Systems Shared
[09/28/2008|04:52] C:\Program Files\Common Files\<DIR> Ahead
[09/28/2008|02:10] C:\Program Files\Common Files\<DIR> AOL
[09/28/2008|03:49] C:\Program Files\Common Files\<DIR> Designer
[09/29/2008|03:50] C:\Program Files\Common Files\<DIR> InstallShield
[09/28/2008|04:03] C:\Program Files\Common Files\<DIR> Macromedia
[09/28/2008|04:44] C:\Program Files\Common Files\<DIR> Macrovision Shared
[09/28/2008|03:49] C:\Program Files\Common Files\<DIR> Microsoft Shared
[09/28/2008|12:37] C:\Program Files\Common Files\<DIR> MSSoap
[09/27/2008|05:25] C:\Program Files\Common Files\<DIR> ODBC
[09/28/2008|12:37] C:\Program Files\Common Files\<DIR> Services
[09/27/2008|05:25] C:\Program Files\Common Files\<DIR> SpeechEngines
[09/28/2008|03:48] C:\Program Files\Common Files\<DIR> System

--------------------\\ Process

( 33 Processes )

iexplore.exe ~ [PID:3216]

--------------------\\ Searching with S_Lop

No Lop folder found !

--------------------\\ Searching for Lop Files - Folders

C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@adultfriendfinder[2].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@advertisingworksinc[2].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@advertising[1].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@adin.bigpoint[2].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@bigpoint[1].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@us.seafight.bigpoint[2].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@us1.darkorbit.bigpoint[2].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@adopt.euroclick[2].txt
C:\DOCUME~1\GENERA~1\Cookies\generations_beyond@us.seafight.bigpoint[2].txt

--------------------\\ Searching within the Registry

..... OK !

--------------------\\ Checking the Hosts file

Hosts file CLEAN


--------------------\\ Searching for hidden files with Catchme

catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-03 15:19:56
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden files: 0

--------------------\\ Searching for other infections

C:\WINDOWS\system32\fOWyyccf.ini
C:\WINDOWS\system32\fOWyyccf.ini2
==> VUNDO <==

--------------------\\ ROOTKIT !!

Rootkit Tibs ! .. [HKLM\..\ControlSet001\Enum\Root\LEGACY_TDSSSERV]
Rootkit Tibs ! .. [HKLM\..\ControlSet001\Services\tdssserv]
Rootkit Tibs ! .. [HKLM\..\ControlSet001\Enum\Root\tdssserv]


Trojan ! .. C:\WINDOWS\system32\drivers\tdssserv.sys
Trojan ! .. C:\WINDOWS\system32\tdssservers.dat
Trojan ! .. C:\WINDOWS\system32\tdssserf.dll
Trojan ! .. C:\WINDOWS\system32\tdssmain.dll
Trojan ! .. C:\WINDOWS\system32\tdssinit.dll
Trojan ! .. C:\WINDOWS\system32\tdssadw.dll
Trojan ! .. C:\WINDOWS\system32\tdsslog.dll
Trojan ! .. C:\WINDOWS\system32\tdssl.dll

--------------------\\ Suspect ..

C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\TDSSl.dll
C:\WINDOWS\system32\tdsslog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\tdssserf.dll
C:\WINDOWS\system32\tdssserf1.dll
C:\WINDOWS\system32\tdssservers.dat

--------------------\\ Cracks & Keygens ..

C:\DOCUME~1\GENERA~1\My Documents\My Music\mp3s\BagOfHammers-HulkHoganOnCrack-juggalodotcom.mp3
C:\DOCUME~1\GENERA~1\My Documents\My Music\mp3s\SOD - the crackhead song.mp3
C:\DOCUME~1\GENERA~1\My Documents\My Music\mp3s\Comedy\DVDA - Everybody Is On Crack LIVE.mp3
C:\DOCUME~1\GENERA~1\My Documents\My Music\mp3s\Kanye West\Late_Registration\08-kanye_west-crack_music_(feat_the_game).mp3
C:\DOCUME~1\GENERA~1\Recent\Crack.lnk
C:\DOCUME~1\GENERA~1\Recent\Orion_Keygen_nero6.6.0.14.zip.lnk


[F:66][D:19]-> C:\DOCUME~1\GENERA~1\LOCALS~1\Temp
[F:547][D:0]-> C:\DOCUME~1\GENERA~1\Cookies
[F:401][D:6]-> C:\DOCUME~1\GENERA~1\LOCALS~1\TEMPOR~1\content.IE5

1 - "C:\Lop SD\LopR_1.txt" - Fri 10/03/2008|15:24 - Option : [1]

--------------------\\ Scan completed at 15:24:55
Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 3 2008, 01:36 PM
Post #4


GeekU Teacher
Group Icon
Posts: 19,791
From: Dublin
OS: XP



Hello

Please visit this web page for instructions for downloading and running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

This includes installing the Windows XP Recovery Console in case you have not installed it yet.

For more information on the Windows XP Recovery Console read http://support.microsoft.com/kb/314058.

Once you install the Recovery Console, when you reboot your computer, you'll see the option for the Recovery Console now as well. Don't select Recovery Console as we don't need it. By default, your main OS is selected there. The screen stays for 2 seconds and then it proceeds to load Windows. That is normal.

Post the log from ComboFix when you've accomplished that, along with a new HijackThis log.




Go to the top of the page
 
+Quote Post
Rorschach112
post Oct 12 2008, 02:00 PM
Post #5


GeekU Teacher
Group Icon
Posts: 19,791
From: Dublin
OS: XP



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 


RSS Time is now: 2nd December 2008 - 06:31 PM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.