Need a geek? Geeks to Go offers free, quality tech support -- in terms anyone can understand. Volunteers are waiting to help, friendly, technology experts who have knowledge to share, and enjoy helping others. Feel free to browse the site as a guest. However, you must log in to reply to existing topics, or to start a new topic of your own. Other benefits of joining include richer forum features, and removal of all advertising. Learn more in our Welcome Guide Infected? Malware and Spyware Cleaning Guide. What are you waiting for? Click here to join for free today!
cannot download anything since switching to firefox from ie7 [Solved]
logari
post Jun 21 2009, 10:58 AM
Post #1


Member
**
Posts: 13
OS: windows 98



Hello,

Thanks for all your help and work you people put into this site helping people with their computing problems. I recently had many malware and trojans on my computer and followed your guide to removing them and so far avg and malwarebytes say my computer is clean. So next i followed your advice on preventing malware and trojans by getting rid of IE 7 and downloading firefox 3 with the addons you recommended. But after i removed ie 7 i had to reboot and then i could not load explorer.exe because iertutil.dll was missing and windows would stop loading. So i fixed that by opening task manager and running firefox and downloading a new iertutil.dll from dll-files.com and put it in system32 folder and all was good after that except now i cannot download anything because there is some type of glitch where you can not uninstall ie7 after installing service pack 3. I went to follow mozillas advice on the situation but i cannot open my internet properties from control panel because it says "Ordinal 56 could not be located in the dynamic link library iertutil.dll". I only have malwarebytes log to post as i cannot download the other programs and post those other logs you asked for. I have 3 logs from malwarebytes so i will post them in order.(last log shows everything clean so i will not post that)Any help would be greatly appreciated, thank you.

Malwarebytes' Anti-Malware 1.38
Database version: 2308
Windows 5.1.2600 Service Pack 3

6/19/2009 11:00:00 AM
mbam-log-2009-06-19 (11-00-00).txt

Scan type: Quick Scan
Objects scanned: 84650
Time elapsed: 2 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 13
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 9

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bad4551d-9b24-42cb-9bcd-818ca2da7b63} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bad4551d-9b24-42cb-9bcd-818ca2da7b63} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\glaide32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\glaide32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\glaide32 (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{5b035261-40f9-11d1-aaec-00805fc1270e} (Spyware.OnlineGames) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\driver (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\driverdrv (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\driver (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\driver (Trojan.Downloader) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\driver (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\8085:tcp (Malware.Trace) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\msa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\glaide32.sys (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netcfgx.dll:Zone.Identifier (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Program Files\driver\driver.dll (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\010112010146118114.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
C:\WINDOWS\010112010146118114.lso (Worm.KoobFace) -> Quarantined and deleted successfully.


Malwarebytes' Anti-Malware 1.38
Database version: 2308
Windows 5.1.2600 Service Pack 3

6/20/2009 6:35:24 PM
mbam-log-2009-06-20 (18-35-24).txt

Scan type: Full Scan (C:\|D:\|E:\|F:\|)
Objects scanned: 125714
Time elapsed: 27 minute(s), 2 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{bad4551d-9b24-42cb-9bcd-818ca2da7b63} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bad4551d-9b24-42cb-9bcd-818ca2da7b63} (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\system volume information\_restore{4d8844db-2f7c-4669-b8c7-0a47ee2c3f6d}\RP1\A0000116.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\system volume information\_restore{4d8844db-2f7c-4669-b8c7-0a47ee2c3f6d}\RP1\A0000120.dll (Trojan.Agent) -> Quarantined and deleted successfully.
Go to the top of the page
 
+Quote Post
2 Pages V   1 2 >  
Start new topic
Replies (1 - 14)
Rorschach112
post Jun 21 2009, 11:36 AM
Post #2


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



hi

Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum.



Please download ComboFix from Here or Here to your Desktop.

**Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
  1. If you are using Firefox, make sure that your download settings are as follows:
    • Tools->Options->Main tab
    • Set to "Always ask me where to Save the files".
  2. During the download, rename Combofix to Combo-Fix as follows:





  3. It is important you rename Combofix during the download, but not after.
  4. Please do not rename Combofix to other names, but only to the one indicated.
  5. Close any open browsers.
  6. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    -----------------------------------------------------------

    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
      -----------------------------------------------------------

    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

    -----------------------------------------------------------
  7. Double click on combo-Fix.exe & follow the prompts.
  8. When finished, it will produce a report for you.
  9. Please post the "C:\Combo-Fix.txt" for further review.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**
Go to the top of the page
 
+Quote Post
logari
post Jun 21 2009, 03:23 PM
Post #3


Member
**
Posts: 13
OS: windows 98



hello,


thank you for taking the time to respond to my problem but as the heading of the topic states i cannot download anything. when i do try and download things it says"this dowload has been blocked by your security zone policy". The fix for this as stated by mozilla requires me to go internet properties in the control panel but when i click that it says "Ordinal 56 could not be located in the dynamic link library iertutil.dll". Thanks again in advance for your time.


Logari
Go to the top of the page
 
+Quote Post
Rorschach112
post Jun 21 2009, 03:26 PM
Post #4


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



can you try it with internet explorer or transfer it over from another pc ?
Go to the top of the page
 
+Quote Post
logari
post Jun 21 2009, 06:46 PM
Post #5


Member
**
Posts: 13
OS: windows 98



hello,

i removed internet explorer so it is not working. i can download from torrents if you know of a safe torrent to download from. i dont know if i have access to another pc. thank you.

Logari
Go to the top of the page
 
+Quote Post
Rorschach112
post Jun 21 2009, 06:51 PM
Post #6


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



try download k-meleon and download it with that
Go to the top of the page
 
+Quote Post
logari
post Jun 22 2009, 12:13 AM
Post #7


Member
**
Posts: 13
OS: windows 98



nope could not download it from website and no torrents for it
Go to the top of the page
 
+Quote Post
logari
post Jun 22 2009, 01:08 AM
Post #8


Member
**
Posts: 13
OS: windows 98



i downloaded internet explorer 7 from a torrent and i installed ie7 again and now i am able to download things again so i went back to your first post and ran sdfix and here is the log. Should i also do the combofix part also or do things look good? Thanks again


SDFix: Version 1.240
Run by Administrator on Sun 06/21/2009 at 11:57 PM

Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix

Checking Services :


Restoring Default Security Values
Restoring Default Hosts File

Rebooting


Checking Files :

No Trojan Files Found






Removing Temp Files

ADS Check :



Final Check :

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 00:03:10
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"hdf12"=hex:d5,70,ff,a6,24,7f,fe,ce,42,a8,3a,22,43,4f,34,99,0f,d2,34,08,13,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,ca,d7,b6,94,d5,67,f2,2c,96,a7,5d,a2,ba,89,55,01,ec,..
"hdf12"=hex:12,75,cb,8e,07,8c,c1,f5,ee,b4,14,8f,1e,e0,6e,0d,a1,06,a1,5a,18,..

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:43,e6,c8,a4,74,92,84,be,5f,89,3a,2c,cf,55,82,75,cd,55,9a,21,de,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC]
"p0"="C:\Program Files\DAEMON Tools Lite\"
"h0"=dword:00000000
"hdf12"=hex:d5,70,ff,a6,24,7f,fe,ce,42,a8,3a,22,43,4f,34,99,0f,d2,34,08,13,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001]
"a0"=hex:20,01,00,00,ca,d7,b6,94,d5,67,f2,2c,96,a7,5d,a2,ba,89,55,01,ec,..
"hdf12"=hex:12,75,cb,8e,07,8c,c1,f5,ee,b4,14,8f,1e,e0,6e,0d,a1,06,a1,5a,18,..

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0]
"hdf12"=hex:43,e6,c8,a4,74,92,84,be,5f,89,3a,2c,cf,55,82,75,cd,55,9a,21,de,..

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services :




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"="C:\\Program Files\\AVG\\AVG8\\avgupd.exe:*:Enabled:avgupd.exe"
"C:\\Program Files\\AVG\\AVG8\\avgemc.exe"="C:\\Program Files\\AVG\\AVG8\\avgemc.exe:*:Enabled:avgemc.exe"
"C:\\Program Files\\Symantec\\Ghost\\ngctw32.exe"="C:\\Program Files\\Symantec\\Ghost\\ngctw32.exe:*:Enabled:Symantec Ghost Client Agent"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:ćTorrent"
"C:\\Program Files\\World of Warcraft\\Launcher.exe"="C:\\Program Files\\World of Warcraft\\Launcher.exe:*:Enabled:Blizzard Launcher"
"C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"="C:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Mozilla Firefox\\firefox.exe"="C:\\Program Files\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Symantec\\Ghost\\ngctw32.exe"="C:\\Program Files\\Symantec\\Ghost\\ngctw32.exe:*:Enabled:Symantec Ghost Client Agent"

Remaining Files :



Files with Hidden Attributes :

Mon 14 Apr 2008 1,695,232 ..SH. --- "C:\Program Files\Messenger\msmsgs.exe"
Mon 14 Apr 2008 60,416 A.SH. --- "C:\Program Files\Outlook Express\msimn.exe"
Mon 26 Jan 2009 1,740,632 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 26 Jan 2009 5,365,592 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Thu 5 Mar 2009 2,260,480 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Fri 10 Apr 2009 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Wed 17 Nov 2004 94,458 ...H. --- "C:\Program Files\Nero\data\Nero PhotoShow Express.exe"
Mon 15 Dec 2008 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Wed 3 Jun 2009 3,633 ...HR --- "C:\Documents and Settings\Administrator\Application Data\SecuROM\UserData\securom_v7_01.bak"

Finished!

Go to the top of the page
 
+Quote Post
Rorschach112
post Jun 22 2009, 06:58 AM
Post #9


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



yes do the combofix step

you shouldn't remove IE by the way
Go to the top of the page
 
+Quote Post
logari
post Jun 22 2009, 10:31 AM
Post #10


Member
**
Posts: 13
OS: windows 98



hello again,

here is the combofix log


ComboFix 09-06-21.01 - Administrator 06/22/2009 9:19.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2038.1619 [GMT -7:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\driver
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500
c:\recycler\S-1-5-21-839522115-1993962763-725345543-1003
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\Thumbs.db
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tindex.htm
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\titlepg0.htm
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\titlepg2.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\titlepg3.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\titlepga.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools010.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools011.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools012.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools013.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools014.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools015.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools016.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools017.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools018.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools019.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools02.htm
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools020.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools021.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools022.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools023.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools024.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools025.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools026.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools027.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools028.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools029.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\tools02a.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa22.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa23.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa24.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa25.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa26.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa27.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\toolsa28.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\warrnty0.htm
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\xpfeat02.htm
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\xpfeat03.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\xpfeat04.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\xpfeat05.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\xpfeat0a.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc1\Temp\280 Web issue\xpfeata2.jpg
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\Dc2.exe
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\desktop.ini
c:\recycler\S-1-5-21-2886987307-2056298120-17957552-500\INFO2
c:\recycler\S-1-5-21-839522115-1993962763-725345543-1003\desktop.ini
c:\recycler\S-1-5-21-839522115-1993962763-725345543-1003\INFO2

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_DRIVER
-------\Legacy_DRIVERDRV


((((((((((((((((((((((((( Files Created from 2009-05-22 to 2009-06-22 )))))))))))))))))))))))))))))))
.

2009-06-22 06:56 . 2009-06-22 06:56 578560 -c--a-w- c:\windows\system32\dllcache\user32.dll
2009-06-22 06:55 . 2009-06-22 06:55 -------- d-----w- c:\windows\ERUNT
2009-06-22 06:33 . 2009-06-22 07:04 -------- d-----w- C:\SDFix
2009-06-22 06:25 . 2009-06-22 06:25 -------- d-----w- c:\documents and settings\LocalService\Application Data\SACore
2009-06-22 06:25 . 2009-06-22 06:25 -------- d-----w- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-06-21 19:25 . 2009-06-21 19:25 -------- d-----w- c:\documents and settings\User.DELL25640\Local Settings\Application Data\Mozilla
2009-06-21 00:48 . 2009-06-22 16:10 -------- d-----w- c:\documents and settings\Administrator\EurekaLog
2009-06-20 06:50 . 2009-06-20 06:50 -------- d-----w- c:\program files\AskBarDis
2009-06-20 06:50 . 2009-06-20 06:50 -------- d-----w- c:\program files\Foxit Software
2009-06-20 06:50 . 2009-06-20 06:50 -------- d-----w- c:\documents and settings\Administrator\Application Data\Foxit
2009-06-20 06:42 . 2009-06-20 06:42 -------- d-----w- c:\documents and settings\All Users\Application Data\SiteAdvisor
2009-06-20 06:40 . 2009-06-20 06:40 -------- d-----w- c:\program files\Common Files\McAfee
2009-06-20 06:39 . 2009-06-20 06:40 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-06-20 06:39 . 2009-06-20 06:40 -------- d-----w- c:\program files\McAfee
2009-06-20 06:35 . 2009-06-21 01:47 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-20 06:35 . 2009-06-20 06:39 -------- d-----w- c:\program files\SpywareBlaster
2009-06-20 06:35 . 2005-08-26 02:18 118784 ----a-w- c:\windows\system32\MSSTDFMT.DLL
2009-06-20 06:33 . 2009-06-20 06:33 0 ----a-w- c:\windows\nsreg.dat
2009-06-20 06:33 . 2009-06-20 06:33 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2009-06-20 06:30 . 2009-06-20 06:30 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Opera
2009-06-20 06:30 . 2009-06-20 06:47 -------- d-----w- c:\program files\Opera
2009-06-19 17:56 . 2009-06-19 17:56 -------- d-----w- c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-06-19 17:56 . 2009-06-17 18:27 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-19 17:56 . 2009-06-19 17:56 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-19 17:56 . 2009-06-19 17:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-19 17:56 . 2009-06-17 18:27 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-19 17:55 . 2009-06-19 17:55 -------- d-----w- c:\program files\ERUNT
2009-06-19 06:42 . 2009-06-19 06:42 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-06-15 07:29 . 2009-06-15 16:02 -------- d-----w- c:\documents and settings\Administrator\Application Data\Alarm
2009-06-15 07:28 . 2009-06-15 07:28 -------- d-----w- c:\program files\Alarm
2009-06-10 10:54 . 2009-06-10 10:54 3888 ----a-w- c:\windows\system32\drivers\NTHANDLE.SYS
2009-06-09 05:52 . 2009-02-25 01:42 116736 ----a-w- c:\windows\system32\drivers\mcdbus.sys
2009-06-09 05:52 . 2009-06-09 05:53 -------- d-----w- c:\program files\MagicDisc
2009-06-09 05:51 . 2009-06-09 05:51 -------- d-----w- c:\program files\MagicISO
2009-06-05 06:14 . 2009-06-05 06:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Trymedia
2009-06-04 21:00 . 2009-06-04 21:00 -------- d-----w- c:\program files\Sierra
2009-06-04 17:53 . 2009-06-04 17:56 21840 ----atw- c:\windows\system32\SIntfNT.dll
2009-06-04 17:53 . 2009-06-04 17:56 17212 ----atw- c:\windows\system32\SIntf32.dll
2009-06-04 17:53 . 2009-06-04 17:56 12067 ----atw- c:\windows\system32\SIntf16.dll
2009-06-04 17:50 . 2009-06-04 21:08 -------- d-----w- c:\program files\Diablo II
2009-06-04 04:28 . 2009-06-09 18:58 -------- d-----w- c:\program files\EA GAMES
2009-06-03 15:14 . 2009-06-03 15:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\Bioshock
2009-06-03 15:10 . 2009-06-03 15:10 107888 ----a-w- c:\windows\system32\CmdLineExt.dll
2009-06-03 15:10 . 2009-06-03 15:10 -------- d--h--r- c:\documents and settings\Administrator\Application Data\SecuROM
2009-06-02 20:06 . 2009-06-02 20:06 -------- d-----w- c:\documents and settings\All Users\Application Data\DAEMON Tools Lite
2009-06-02 20:06 . 2009-06-02 20:06 -------- d-----w- c:\program files\DAEMON Tools Toolbar
2009-06-02 20:06 . 2009-06-02 20:06 -------- d-----w- c:\program files\DAEMON Tools Lite
2009-06-02 20:02 . 2009-06-02 20:02 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-06-02 20:02 . 2009-06-02 20:09 -------- d-----w- c:\documents and settings\Administrator\Application Data\DAEMON Tools Lite
2009-05-31 19:15 . 2009-06-17 19:51 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-05-31 19:15 . 2009-05-31 19:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-05-31 19:09 . 2009-05-31 19:09 -------- d-----w- c:\program files\Trend Micro

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-22 16:06 . 2009-04-03 06:15 -------- d-----w- c:\documents and settings\Administrator\Application Data\uTorrent
2009-06-19 21:37 . 2009-05-02 03:20 -------- d-----w- c:\documents and settings\User\Application Data\Move Networks
2009-06-19 18:01 . 2008-12-16 14:58 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-17 18:22 . 2009-04-03 06:04 -------- d-----w- c:\documents and settings\Administrator\Application Data\AdobeUM
2009-06-17 05:56 . 2009-04-10 09:41 -------- d-----w- c:\documents and settings\User\Application Data\uTorrent
2009-06-16 06:35 . 2008-12-16 14:59 15664 ----a-w- c:\documents and settings\User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-15 07:28 . 2009-04-03 06:07 15664 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-06-11 11:12 . 2008-12-15 17:21 -------- d-----w- c:\program files\Windows Desktop Search
2009-06-08 19:22 . 2008-12-15 15:29 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-02 20:03 . 2009-04-03 06:19 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-05-31 18:08 . 2009-05-19 08:26 -------- d-----w- c:\program files\Solveig Multimedia
2009-05-27 06:01 . 2009-04-09 04:45 -------- d-----w- c:\documents and settings\User\Application Data\OpenOffice.org2
2009-05-25 07:24 . 2008-05-27 03:18 350208 ----a-w- c:\windows\system32\mssph.dll
2009-05-12 22:12 . 2008-12-15 15:55 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-05-07 15:32 . 2004-08-04 10:00 345600 ----a-w- c:\windows\system32\localspl.dll
2009-04-30 23:39 . 2009-04-30 23:39 -------- d-----w- c:\documents and settings\User\Application Data\Windows Search
2009-04-30 23:06 . 2009-04-30 23:06 415390 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{09B1AF25-4C86-447D-8C2F-001471B29BC4}\_FA94A8E44781A4345C4441.exe
2009-04-30 23:06 . 2009-04-30 23:06 415390 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{09B1AF25-4C86-447D-8C2F-001471B29BC4}\_6FEFF9B68218417F98F549.exe
2009-04-30 23:06 . 2009-04-30 23:06 415390 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{09B1AF25-4C86-447D-8C2F-001471B29BC4}\_07A3C6218253C8AF1D6390.exe
2009-04-30 23:06 . 2009-04-30 23:06 10134 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{09B1AF25-4C86-447D-8C2F-001471B29BC4}\_6C5C3828C661EBFCE439E3.exe
2009-04-30 23:06 . 2009-04-30 23:06 10134 ----a-r- c:\documents and settings\Administrator\Application Data\Microsoft\Installer\{09B1AF25-4C86-447D-8C2F-001471B29BC4}\_5837292E6900EBCB16DDB7.exe
2009-04-30 23:06 . 2009-04-30 23:06 -------- d-----w- c:\program files\Wide Angle Software
2009-04-29 19:58 . 2009-04-29 19:58 -------- d-----w- c:\documents and settings\Administrator\Application Data\Media Player Classic
2009-04-29 19:49 . 2009-04-29 19:49 -------- d-----w- c:\program files\Essentials Codec Pack
2009-04-29 04:56 . 2006-03-04 03:33 827392 ------w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2004-08-04 10:00 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-17 12:26 . 2004-08-04 10:00 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2004-08-04 10:00 585216 ----a-w- c:\windows\system32\rpcrt4.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-11-18 19:58 333192 ----a-w- c:\program files\AskBarDis\bar\bin\askBar.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="c:\program files\Analog Devices\Core\smax4pnp.exe" [2004-10-14 1404928]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-10-14 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-10-14 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-10-14 114688]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-02-04 1601304]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]

c:\documents and settings\User\Start Menu\Programs\Startup\
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2009-6-8 576000]

c:\documents and settings\Administrator\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-02-04 21:22 10520 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=c:\windows\pss\Windows Search.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WMPNetworkSvc"=3 (0x3)
"NGCLIENT"=2 (0x2)
"idsvc"=3 (0x3)
"Bonjour Service"=2 (0x2)
"iPod Service"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"wuauserv"=2 (0x2)
"BITS"=3 (0x3)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"SpybotSD TeaTimer"=c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\Symantec\\Ghost\\ngctw32.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [12/16/2008 7:58 AM 325128]
R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [12/16/2008 7:58 AM 107272]
R2 avg8emc;AVG8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [12/16/2008 8:17 AM 903960]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [12/16/2008 8:17 AM 298264]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [6/19/2009 11:40 PM 210216]
S2 0168721245480046mcinstcleanup;McAfee Application Installer Cleanup (0168721245480046);c:\docume~1\ADMINI~1\LOCALS~1\Temp\016872~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service --> c:\docume~1\ADMINI~1\LOCALS~1\Temp\016872~1.EXE c:\progra~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini -cleanup -nolog -service [?]
S4 NGCLIENT;Symantec Ghost Client Agent;c:\program files\Symantec\Ghost\ngctw32.exe [4/19/2007 7:01 PM 632456]
.
Contents of the 'Scheduled Tasks' folder

2009-06-15 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 19:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uInternet Connection Wizard,ShellNext = iexplore
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
FF - ProfilePath -
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-22 09:23
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------

[HKEY_USERS\S-1-5-21-674021076-1309942469-828848780-500\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:4d,ae,27,54,67,f6,6d,f4,9d,c7,9a,c1,18,98,3f,30,cf,45,4c,b3,54,ce,de,
b0,9d,c3,29,80,92,6f,0f,49,0c,1d,49,2d,24,6f,6a,93,bd,fd,db,09,e9,eb,6a,e2,\
"??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'explorer.exe'(3496)
c:\program files\McAfee\SiteAdvisor\saHook.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-06-22 9:25 - machine was rebooted
ComboFix-quarantined-files.txt 2009-06-22 16:25

Pre-Run: 33,200,283,648 bytes free
Post-Run: 33,067,032,576 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

269
Go to the top of the page
 
+Quote Post
Rorschach112
post Jun 22 2009, 11:36 AM
Post #11


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



hi

Download TFC to your desktop
  • Open the file and close any other windows.
  • It will close all programs itself when run, make sure to let it run uninterrupted.
  • Click the Start button to begin the process. The program should not take long to finish its job
  • Once its finished it should reboot your machine, if not, do this yourself to ensure a complete clean





Please download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.






Go to Kaspersky website and perform an online antivirus scan.

  1. Read through the requirements and privacy statement and click on Accept button.
  2. It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  3. When the downloads have finished, click on Settings.
  4. Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
      Spyware, Adware, Dialers, and other potentially dangerous programs
      Archives
      Mail databases
  5. Click on My Computer under Scan.
  6. Once the scan is complete, it will display the results. Click on View Scan Report.
  7. You will see a list of infected items there. Click on Save Report As....
  8. Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
Go to the top of the page
 
+Quote Post
logari
post Jun 22 2009, 01:58 PM
Post #12


Member
**
Posts: 13
OS: windows 98



kaspersky found no problems so there was no log to save and this is malware bytes log, also clean.


Malwarebytes' Anti-Malware 1.38
Database version: 2308
Windows 5.1.2600 Service Pack 3

6/22/2009 12:31:48 PM
mbam-log-2009-06-22 (12-31-48).txt

Scan type: Quick Scan
Objects scanned: 91303
Time elapsed: 5 minute(s), 8 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
Go to the top of the page
 
+Quote Post
Rorschach112
post Jun 22 2009, 02:08 PM
Post #13


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



hi

CLICK HERE to download the HijackThis Installer:
  1. Save HJTInstall.exe to your desktop.
  2. Double-click on HJTInstall.exe to run the program.
  3. By default it will install to C:\Program Files\Trend Micro\HijackThis.
  4. Accept the license agreement by clicking the "I Accept" button.
  5. Click on the "Do a system scan and save a log file" button. It will scan and then ask you to save the log.
  6. Click "Save log" to save the log file and then the log will open in Notepad.
  7. Click on "Edit -> Select All" then click on "Edit -> Copy" to copy the entire contents of the log.
  8. Come back here to this thread and paste the log in your next reply.
  9. Do NOT have HijackThis fix anything yet! Most of what it finds will be harmless or even required.
Go to the top of the page
 
+Quote Post
logari
post Jun 22 2009, 02:33 PM
Post #14


Member
**
Posts: 13
OS: windows 98



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:32:40 PM, on 6/22/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.yahoo.com/search?fr=mcafee&p=%s
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: Foxit Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5727FF4C-EF4E-4d96-A96C-03AD91910448} (System Requirements Lab) - http://www.srtest.com/srl_bin/sysreqlab_ind.cab
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/sit...b?1245435469281
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1245434655718
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: McAfee Application Installer Cleanup (0168721245480046) (0168721245480046mcinstcleanup) - Unknown owner - C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\016872~1.EXE (file missing)
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe

--
End of file - 5662 bytes
Go to the top of the page
 
+Quote Post
Rorschach112
post Jun 23 2009, 05:35 AM
Post #15


GeekU Teacher
Group Icon
Posts: 35,171
From: Dublin
OS: XP



Your logs are clean


Follow these steps to uninstall Combofix and tools used in the removal of malware
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.




  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.


Below I have included a number of recommendations for how to protect your computer against malware infections.
  • Keep Windows updated by regularly checking their website at :
    http://windowsupdate.microsoft.com/
    This will ensure your computer has always the latest security updates available installed on your computer.

  • SpywareBlaster protects against bad ActiveX, it immunizes your PC against them.

  • SpywareGuard offers realtime protection from spyware installation attempts. Make sure you are only running one real-time anti-spyware protection program ( eg : TeaTimer, Windows Defender ) or there will be a conflict.

  • Make Internet Explorer more secure
    • Click Start > Run
    • Type Inetcpl.cpl & click OK
    • Click on the Security tab
    • Click Reset all zones to default level
    • Make sure the Internet Zone is selected & Click Custom level
    • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to "Prompt", and ("Initialize and Script ActiveX controls not marked as safe") to "Disable".
    • Next Click OK, then Apply button and then OK to exit the Internet Properties page.

  • ATF Cleaner - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.

  • MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more
    secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in pop up
    blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from
    Here


    If you choose to use Firefox, I highly recommend these add-ons to keep your PC even more secure.
    • NoScript - for blocking ads and other potential website attacks
    • McAfee SiteAdvisor - this tells you whether the sites you are about to visit are safe or not. A must if you do a lot of Googling


  • Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

  • ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

  • FileHippo Update Checker is an extremely helpful program that will tell you which of your programs need to be updated. Its important to keep programs up to date so that malware doesn't exploit any old security flaws.

  • Recovery Console - Recent trends appear to indicate that future infections will include attacks to the boot sector of the computer. The installation of the Recovery Console in the computer will be our only defense against this threat. For more information and steps to install the Recovery Console see This Article. Should you need assistance in installing the Recovery Console, please do not hesitate to ask.

  • Please read my guide on how to prevent malware and about safe computing here

Thank you for your patience, and performing all of the procedures requested.


Go to the top of the page
 
+Quote Post

2 Pages V   1 2 >
Closed TopicStart new topic
1 User(s) are reading this topic (1 Guests and 0 Anonymous Users)
0 Members:

 

Collapse

> Similar Topics

    Topic Title Replies / Views Topic Information
No New Posts   2 / 448 29th August 2007 - 07:30 PM
amartin07 started - last by wannabe1
No New Posts   0 / 935 18th January 2009 - 06:24 AM
stimutaxx started - last by stimutaxx
No New Posts   1 / 317 20th June 2009 - 08:53 PM
logari started - last by cbarnard
No new   19 / 338 15th September 2009 - 05:47 PM
Big Country started - last by BillSnapWire

RSS Time is now: 21st November 2009 - 11:53 PM

Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.

© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising