Malware On my computer (help please) [Solved] |
![]() ![]() |
Malware On my computer (help please) [Solved] |
Nov 7 2009, 02:47 PM
Post
#16
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
okay now its says a problem has been detected and windows has been shut down to prevent damage to your computer. It was a blue screen and then it just Shut down completely.
|
|
|
Nov 7 2009, 02:50 PM
Post
#17
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
That was when Combofix ran is that correct ?
If so restart the computer and select F8 to get the menu up and select Safe mode |
|
|
Nov 7 2009, 02:52 PM
Post
#18
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
Correct, I selected safe mode and now it says loading windows files.
Edit: I also wasnt able to save the report form OTL because the system rebooted unexpectedly, would you like me to run it again or not? This post has been edited by onkaloonka: Nov 7 2009, 02:57 PM |
|
|
Nov 7 2009, 03:03 PM
Post
#19
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
The report should be at c:\ OTS
|
|
|
Nov 7 2009, 03:05 PM
Post
#20
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
Well I'm on a different computer, and if that one is in safe mode how do you want me to get the reports to you?
|
|
|
Nov 7 2009, 03:15 PM
Post
#21
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
If you could now run combofix in safe mode it should go back to normal mode on completion
|
|
|
Nov 7 2009, 03:16 PM
Post
#22
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
Oh, I'm supposed to run combofix once im in safe mode?
|
|
|
Nov 7 2009, 03:17 PM
Post
#23
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Aye sorry I should have been clearer in my instructions
|
|
|
Nov 7 2009, 03:21 PM
Post
#24
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
Alrite, Its fine, running it now, Ha, cant believe zonealarm firewall works in safe mode, do I really need to disable it for combofix to run?
|
|
|
Nov 7 2009, 03:27 PM
Post
#25
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Nope
|
|
|
Nov 7 2009, 03:37 PM
Post
#26
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
Alrite, I guess it worked, now my pc is shutdown, should I start it back up into normal mode?
|
|
|
Nov 7 2009, 03:38 PM
Post
#27
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Should do - it should start automatically
|
|
|
Nov 7 2009, 03:42 PM
Post
#28
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
It didnt automaticly, but im starting up right now
|
|
|
Nov 7 2009, 03:48 PM
Post
#29
|
|
![]() Member ![]() ![]() Posts: 57 From: USA :) OS: Vista home premium |
Heres the reports of avenger and OTL:
OTL: All processes killed ========== OTL ========== No active process named MWSOEMON.EXE was found! Process MWSSVC.EXE killed successfully! No active process named M3SRCHMN.EXE was found! Service Akamai stopped successfully! Service Akamai deleted successfully! c:\Program Files\Common Files\Akamai\rswin_3600.dll moved successfully. Service MyWebSearchService stopped successfully! Service MyWebSearchService deleted successfully! C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44cf-8957-5838F569A31D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}\ deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{01dfd24d-73eb-497f-8dfd-7ea79365af4a} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}\ deleted successfully. File C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{01dfd24d-73eb-497f-8dfd-7ea79365af4a} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01dfd24d-73eb-497f-8dfd-7ea79365af4a}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ deleted successfully. File C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{01DFD24D-73EB-497F-8DFD-7EA79365AF4A} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{01DFD24D-73EB-497F-8DFD-7EA79365AF4A}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}\ not found. File C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar Search Scope Monitor deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Plugin deleted successfully. C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\PopRock not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\sl1000 not found. C:\Users\Administrator.BluhmBros-PC\AppData\Local\TempImages\sl1000.exe moved successfully. Starting removal of ActiveX control {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} C:\Windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}\ not found. C:\WINDOWS\win32k.sys moved successfully. C:\WINDOWS\System32\BF58954A04.dll moved successfully. ========== FILES ========== C:\Program Files\MyWebSearch\bar\Settings folder moved successfully. C:\Program Files\MyWebSearch\bar\Notifier folder moved successfully. C:\Program Files\MyWebSearch\bar\Message folder moved successfully. C:\Program Files\MyWebSearch\bar\icons folder moved successfully. C:\Program Files\MyWebSearch\bar\History folder moved successfully. C:\Program Files\MyWebSearch\bar\Game folder moved successfully. C:\Program Files\MyWebSearch\bar\Avatar folder moved successfully. C:\Program Files\MyWebSearch\bar\1.bin folder moved successfully. C:\Program Files\MyWebSearch\bar folder moved successfully. C:\Program Files\MyWebSearch folder moved successfully. File\Folder C:\Program Files\freevideomaster not found. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator User: Administrator.BluhmBros-PC ->Temp folder emptied: 687272 bytes ->Temporary Internet Files folder emptied: 3238314 bytes ->Java cache emptied: 0 bytes User: All Users User: Bluhm Bros ->Temp folder emptied: 455955 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 70727528 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes Windows Temp folder emptied: 3050 bytes RecycleBin emptied: 2934 bytes Total Files Cleaned = 71.67 mb OTL by OldTimer - Version 3.1.4.0 log created on 11072009_151631 Files\Folders moved on Reboot... C:\Users\Bluhm Bros\AppData\Local\Temp\~DFA325.tmp moved successfully. File\Folder C:\Windows\temp\ZLT06559.TMP not found! Registry entries deleted on Reboot... This post has been edited by onkaloonka: Nov 7 2009, 03:49 PM
Attached File(s)
|
|
|
Nov 7 2009, 03:51 PM
Post
#30
|
|
![]() GeekU Moderator Posts: 19,158 From: Darkest Cornwall OS: Vista Ultimate & Windows 7 |
Could you post the combofix log please it should be at C:\combofix.txt
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
0 / 219 | 7th November 2005 - 08:49 AM lmr4angels started - last by lmr4angels |
|||||
![]() |
8 / 1,230 | 22nd November 2005 - 08:14 AM whokiid started - last by Rawe |
|||||
![]() |
8 / 552 | 1st June 2006 - 06:58 AM tcdor started - last by therock247uk |
|||||
![]() |
0 / 391 | 11th March 2008 - 02:10 AM Toohottohandle started - last by Toohottohandle |
|||||
|
Time is now: 20th November 2009 - 09:31 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising