Fake Security Center Alert Win32.Conflicker.C [Solved], Fake alert pops up warning of Win32.Conflicker.C |
![]() ![]() |
Fake Security Center Alert Win32.Conflicker.C [Solved], Fake alert pops up warning of Win32.Conflicker.C |
Oct 28 2009, 04:43 AM
Post
#16
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
All processes killed
========== OTL ========== Process explorer.exe killed successfully! ========== FILES ========== C:\Admin\antispy\ewido_micro.exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Doylechiro File delete failed. C:\Documents and Settings\Doylechiro\Local Settings\Temp\~DF8D03.tmp scheduled to be deleted on reboot. ->Temp folder emptied: 86850359 bytes File delete failed. C:\Documents and Settings\Doylechiro\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 15524515 bytes ->Java cache emptied: 25684707 bytes ->FireFox cache emptied: 0 bytes File delete failed. C:\Documents and Settings\Doylechiro\Local Settings\Application Data\Apple Computer\Safari\Cache.db scheduled to be deleted on reboot. File delete failed. C:\Documents and Settings\Doylechiro\Local Settings\Application Data\Apple Computer\Safari\WebpageIcons.db scheduled to be deleted on reboot. ->Apple Safari cache emptied: 22059123 bytes User: DRB777~1~COD User: LocalService ->Temp folder emptied: 0 bytes File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. ->Temporary Internet Files folder emptied: 32902 bytes ->Apple Safari cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 6928 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Phyllis ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Apple Safari cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_bd4.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\spnserv.dat scheduled to be deleted on reboot. File delete failed. C:\WINDOWS\temp\spserv.dat scheduled to be deleted on reboot. Windows Temp folder emptied: 34215 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 143.27 mb OTL by OldTimer - Version 3.0.21.0 log created on 10282009_053741 Files\Folders moved on Reboot... C:\Documents and Settings\Doylechiro\Local Settings\Temp\~DF8D03.tmp moved successfully. C:\Documents and Settings\Doylechiro\Local Settings\Application Data\Apple Computer\Safari\Cache.db moved successfully. C:\Documents and Settings\Doylechiro\Local Settings\Application Data\Apple Computer\Safari\WebpageIcons.db moved successfully. File\Folder C:\WINDOWS\temp\Perflib_Perfdata_bd4.dat not found! File move failed. C:\WINDOWS\temp\spnserv.dat scheduled to be moved on reboot. File move failed. C:\WINDOWS\temp\spserv.dat scheduled to be moved on reboot. Registry entries deleted on Reboot... |
|
|
Oct 28 2009, 05:17 AM
Post
#17
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
Hello bitterbuck
congratulations, your logs are clean and another fix is in the can QUOTE If we can fix the SQL issue asap, that would help. I am unable to open an important program.... i cant see a quick fix and given i am at work at the moment i would advise you go through Steps 1 and 2 below and then post your issue about the SQL in this part of the forums. say that your machine has been cleaned of malware. i will keep an eye on the thread, but someone else of better knowledge in this area will be able to help you faster.the malwarebytes scan found and cleared some infected files, as did the super antispyware scan. the kaspersky scan only found items in the system restore which we will clear now as well as some uninfected files. in this post we will clear away the fix tools (this is so that should you ever be re-infected, you will download updated versions and it will also remove the quarantined Malware from your computer), reset your restore points (there will be infections lurking in there) and i will leave you with some ideas on how to enhance the protection of your machine against future infection. ====STEP 1==== Follow these steps to uninstall Combofix, some of the tools used in the removal of malware and to flush your system restore points
====STEP 2==== Double-click OTL to run it. (Vista users, please right click on OTListIt.exe and select "Run as an Administrator")
====IDEAS TO SPEED UP YOUR MACHINE==== this page http://users.telenet.be/bluepatchy/miekiem...owcomputer.html gives some good ideas on how to improve the efficiency of your machine and has one or two useful links to help you further. ====AND FINALLY==== The following is a list of free tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein best wishes andrewuk |
|
|
Oct 28 2009, 07:53 AM
Post
#18
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
If I were to do a system restore to before we cleaned the system, would the malware be back?
|
|
|
Oct 28 2009, 09:32 AM
Post
#19
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
QUOTE If I were to do a system restore to before we cleaned the system, would the malware be back? yes, it would.that is one of the problems with malware. uninstalling the combofix will clear the system restore points, which is your best bet here. i am pretty sure that the SQL issue can be resolved without a system restore. |
|
|
Oct 28 2009, 09:38 AM
Post
#20
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
So if I have already uninstalled combofix I can not restore it??? Oh no!!!!
|
|
|
Oct 28 2009, 09:49 AM
Post
#21
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
I am being told that we somehow damaged windows? Does this sound possible?
|
|
|
Oct 28 2009, 10:15 AM
Post
#22
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
very unlikely that we damaged any critical part of windows. i dont see anything that we did that damaged any other part of windows - but removing malware does come with some risks, though rarely are those risks unrecoverable.
i will consult others on this and see what the view is on how to recover it. andrewuk |
|
|
Oct 28 2009, 10:28 AM
Post
#23
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
Thanks!
|
|
|
Oct 28 2009, 02:40 PM
Post
#24
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
lets check a few settings:
QUOTE @Echo OFF
cd /d %~dp0 Reg Query "HKLM\SYSTEM\CurrentControlSet\Services\MSSQLServer" /s >Results.txt Start Results.txt Exit |
|
|
Oct 28 2009, 02:59 PM
Post
#25
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
! REG.EXE VERSION 3.0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServer Type REG_DWORD 0x10 Start REG_DWORD 0x2 ErrorControl REG_DWORD 0x1 ImagePath REG_EXPAND_SZ C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe -sMSSQLSERVER DisplayName REG_SZ MSSQLSERVER ObjectName REG_SZ LocalSystem HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServer\Linkage Export REG_MULTI_SZ MSSQLSERVER\0\0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServer\Performance Library REG_SZ C:\PROGRA~1\MI6841~1\MSSQL\Binn\sqlctr80.dll Open REG_SZ OpenSQLPerformanceData Close REG_SZ CloseSQLPerformanceData Collect REG_SZ CollectSQLPerformanceData Last Counter REG_DWORD 0xdae Last Help REG_DWORD 0xdaf First Counter REG_DWORD 0xc9a First Help REG_DWORD 0xc9b WbemAdapFileSignature REG_BINARY D170DCF8A7755EE49EE6DD919ECD0665 WbemAdapFileTime REG_BINARY 0096398E23A6C201 WbemAdapFileSize REG_DWORD 0x8238 WbemAdapStatus REG_DWORD 0x0 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServer\Security Security REG_BINARY 01001480900000009C000000140000003000000002001C000100000002801400FF010F00010100000000000100000000020060000400000000001400 FD01020001010000000000051200000000001800FF010F0001020000000000052000000020020000000014008D01020001010000000000050B0000000 0001800FD01020001020000000000052000000023020000010100000000000512000000010100000000000512000000 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSSQLServer\Enum 0 REG_SZ Root\LEGACY_MSSQLSERVER\0000 Count REG_DWORD 0x1 NextInstance REG_DWORD 0x1 |
|
|
Oct 28 2009, 05:00 PM
Post
#26
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
i cant see anything wrong there.
try these links for ideas - where other people have had similar problems: http://www.sqlmonster.com/Uwe/Forum.aspx/s...r-error-on-boot http://www.microsoft.com/communities/newsg...p;sloc=&p=1 http://www.sqlteam.com/FORUMS/topic.asp?TOPIC_ID=38692 http://help.wugnet.com/office/SQL-server-e...pict675465.html keep in mind that this is outside my knowledge, so, for example, i dont know what information you would lose, if any, if you reinstalled it. also, can you give me some idea as to what program you are trying to run? andrewuk |
|
|
Oct 28 2009, 05:27 PM
Post
#27
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
andrewuk,
I am trying to run my office mgmt soft ware Chiro8000. It needs SQL Server to run. When we tried to uninstall the SQL server using add/remove programs we got an error. We can't uninstall. Basically, if i can unstall the sql server I can reinstall and should be ok. |
|
|
Oct 29 2009, 08:55 AM
Post
#28
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
what version of SGL Server is it? 2005?
|
|
|
Oct 29 2009, 09:00 AM
Post
#29
|
|
|
Member ![]() ![]() Posts: 18 OS: XP |
2000
|
|
|
Oct 29 2009, 10:47 AM
Post
#30
|
|
![]() Trusted Helper Posts: 4,595 From: London, UK OS: XP |
this link here takes you through a step by step proceedure to uninstall it.
there are two parts: 1. backing up data <<< need to do first, obviously 2. the uninstallation its not as long as it looks. if you need help in deleting files / folders / registry items, then let me know and i can help. before you start entering the registry, i would back it up first with the instructions below: Backing Up Your Registry
![]() andrewuk |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
10 / 675 | 17th December 2008 - 12:21 AM DazWolf started - last by emeraldnzl |
|||||
![]() |
0 / 171 | 28th February 2009 - 02:16 PM dontottem started - last by dontottem |
|||||
![]() |
8 / 2,204 | 19th May 2009 - 12:28 PM djbrag started - last by andrewuk |
|||||
![]() |
3 / 588 | 3rd July 2009 - 02:20 PM sailerman started - last by heir |
|||||
|
Time is now: 21st November 2009 - 08:36 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising