Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
2 Pages V  < 1 2  
Closed TopicStart new topic
Please Help! Too many viruses :-( [CLOSED]
RatHat
post Nov 16 2008, 09:19 PM
Post #16


GeekU Mod
Group Icon
Posts: 7,823
From: Lake Mabprachan, Thailand
OS: XP SP2 ~ Vista Ultimate



thumbsup.gif
Go to the top of the page
 
+Quote Post
karen7787
post Nov 16 2008, 10:36 PM
Post #17


New Member
*
Posts: 9
OS: Windows XP



Hi Rat Hat,

Thanks again for your help. Here is the log.

Regards,

Karen
;*******************************************************************************
*********************************************************************************
*******************
ANALYSIS: 2008-11-16 20:19:39
PROTECTIONS: 2
MALWARE: 25
SUSPECTS: 2
;*******************************************************************************
*********************************************************************************
*******************
PROTECTIONS
Description Version Active Updated
;===============================================================================
=================================================================================
===================
McAfee Internet Security Suite 2007 8.1 No Yes
McAfee VirusScan Plus 12.1 No No
;===============================================================================
=================================================================================
===================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===============================================================================
=================================================================================
===================
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@trafficmp[2].txt
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@casalemedia[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@atdmt[1].txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@fastclick[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@tribalfusion[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@mediaplex[2].txt
00145807 Cookie/Linksynergy TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@linksynergy[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@statcounter[1].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@ad.yieldmanager[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@apmebf[2].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@advertising[2].txt
00169287 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@media.adrevolver[1].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@ads.pointroll[2].txt
00170554 Cookie/Overture TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@overture[2].txt
00171633 Cookie/Cgi-bin TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@www5.addfreestats[1].txt
00171765 Trj/Redbind.A Virus/Trojan No 0 Yes No C:\Documents and Settings\Karen\My Documents\hjred103.zip[HijackReader.exe]
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@questionmarket[1].txt
00184846 Cookie/Adrevolver TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@adrevolver[2].txt
00187950 Cookie/bravenetA TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@bravenet[2].txt
00207338 Cookie/Target TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@target[1].txt
00207862 Cookie/did-it TrackingCookie No 0 Yes No C:\Documents and Settings\Karen\Cookies\karen@did-it[1].txt
00431194 Adware/AdsRevenue Adware No 0 Yes No C:\Documents and Settings\Karen\Local Settings\Temporary Internet Files\Content.IE5\SLTTU1ZC\mm[1].js
01185375 Application/Psexec.A HackTools No 0 Yes No C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP125\A0017613.EXE
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP125\A0017593.sys
;===============================================================================
=================================================================================
===================
SUSPECTS
Sent Location /
;===============================================================================
=================================================================================
===================
No C:\Documents and Settings\Karen\Desktop\ComboFix.exe[32788R22FWJFW\psexec.cfexe] /
No C:\Qoobox\Quarantine\C\WINDOWS\n.vir /
;===============================================================================
=================================================================================
===================
VULNERABILITIES
Id Severity Description /
;===============================================================================
=================================================================================
===================
182048 HIGH MS07-069 /
176382 HIGH MS07-057 /
170906 HIGH MS07-045 /
164913 HIGH MS07-033 /
160623 HIGH MS07-027 /
150253 HIGH MS07-016 /
;===============================================================================
=================================================================================
===================
Go to the top of the page
 
+Quote Post
RatHat
post Nov 16 2008, 10:48 PM
Post #18


GeekU Mod
Group Icon
Posts: 7,823
From: Lake Mabprachan, Thailand
OS: XP SP2 ~ Vista Ultimate



Karen,

That looks very good! All that is showing is some cookies, a temporary internet file, and a couple of infected restore points.

Run ATF Cleaner again, to remove the cookies and temporary internet file.

Now lets Reset and Re-enable your System Restore to remove the infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs from changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected, but that's good news).

Turn OFF System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore.
  • Click Apply, and then click OK.

Restart your computer.

Turn ON System Restore.
  • On the Desktop, right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore.
  • Click Apply, and then click OK.


System Restore will now be active again.

Let me know how your computer is running after doing all this, and any other problems you have with it.

Regards,
RatHat

Go to the top of the page
 
+Quote Post
RatHat
post Nov 20 2008, 09:04 PM
Post #19


GeekU Mod
Group Icon
Posts: 7,823
From: Lake Mabprachan, Thailand
OS: XP SP2 ~ Vista Ultimate



Due to lack of feedback, this topic has been closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic.
Go to the top of the page
 
+Quote Post

2 Pages V  < 1 2
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

RSS Time is now: 21st November 2009 - 01:32 AM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising