help with a search engine virus [Closed] |
help with a search engine virus [Closed] |
Oct 6 2009, 07:51 PM
Post
#1
|
|
|
Member ![]() ![]() Posts: 14 OS: windows XP |
It does not matter which search engine I use whether its google or yahoo when I search and click on a result, I will get redirected to another random search engine I never heard before or random ads. It does not slow down my computer or give me porn pop ups as other people who has the same problem. I ran avira, malwarebytes, super anti-spyware, and spybot and removed virus but still didn't fix the problem. I was going to try the combofix or hijack this, but decided not to sense I do not know to use them. Please help |
|
|
![]() |
Oct 7 2009, 06:04 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 42,897 From: Dublin OS: XP |
hi
Please download ComboFix from Here or Here to your Desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall** |
|
|
Oct 7 2009, 01:50 PM
Post
#3
|
|
|
Member ![]() ![]() Posts: 14 OS: windows XP |
Thanks for helping rorschach112
There were some problems Before combofix started scanning it warned me I still had Norton 360 and Spysweeper with Antivirus scanning, but I deleted them over a year ago from the add or remove program window because Spysweeper was out of date and Norton kept locking up my computer. When it restarted my avira software re-enabled it self after reboot and detected combofix. I clicked ignore as one of the actions and let combo-fix do its thing. But everything seems to work fine now and hear is the combo-fix txt ComboFix 09-10-06.04 - owner 10/07/2009 12:20.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.60 [GMT -7:00] Running from: c:\documents and settings\owner\Desktop\Combo-Fix.exe AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7} AV: Norton 360 *On-access scanning enabled* (Updated) {A5F1BC7C-EA33-4247-961C-0217208396C4} AV: Spy Sweeper with AntiVirus *On-access scanning enabled* (Updated) {B3891867-7230-459B-9987-E7CCFA7A7D1D} AV: Spyware Doctor with AntiVirus *On-access scanning disabled* (Updated) {D3C23B96-C9DC-477F-8EF1-69AF17A6EFF6} AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} FW: Norton 360 *enabled* {371C0A40-5A0C-4AD2-A6E5-69C02037FBF3} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\recycler\S-1-5-21-3868997124-911790988-508925577-500 c:\windows\kb913800.exe c:\windows\system32\_003408_.tmp.dll c:\windows\system32\_003409_.tmp.dll c:\windows\system32\_003410_.tmp.dll c:\windows\system32\_003411_.tmp.dll c:\windows\system32\_003416_.tmp.dll c:\windows\system32\_003417_.tmp.dll c:\windows\system32\_003418_.tmp.dll c:\windows\system32\_003419_.tmp.dll c:\windows\system32\_003420_.tmp.dll c:\windows\system32\_003421_.tmp.dll c:\windows\system32\_003422_.tmp.dll c:\windows\system32\_003423_.tmp.dll c:\windows\system32\_003424_.tmp.dll c:\windows\system32\_003425_.tmp.dll c:\windows\system32\_003426_.tmp.dll c:\windows\system32\_003427_.tmp.dll c:\windows\system32\_003428_.tmp.dll c:\windows\system32\_003429_.tmp.dll c:\windows\system32\_003430_.tmp.dll c:\windows\system32\_003431_.tmp.dll c:\windows\system32\_003432_.tmp.dll c:\windows\system32\_003433_.tmp.dll c:\windows\system32\_003434_.tmp.dll c:\windows\system32\_003435_.tmp.dll c:\windows\system32\_003436_.tmp.dll c:\windows\system32\_003437_.tmp.dll c:\windows\system32\_003438_.tmp.dll c:\windows\system32\_003439_.tmp.dll c:\windows\system32\_003440_.tmp.dll c:\windows\system32\_003441_.tmp.dll c:\windows\system32\_003442_.tmp.dll c:\windows\system32\_003443_.tmp.dll c:\windows\system32\_003444_.tmp.dll c:\windows\system32\_003445_.tmp.dll c:\windows\system32\_003446_.tmp.dll c:\windows\system32\_003447_.tmp.dll c:\windows\system32\_003448_.tmp.dll c:\windows\system32\_003449_.tmp.dll c:\windows\system32\_003450_.tmp.dll c:\windows\system32\_003451_.tmp.dll c:\windows\system32\_003452_.tmp.dll c:\windows\system32\_003453_.tmp.dll c:\windows\system32\_003454_.tmp.dll c:\windows\system32\_003455_.tmp.dll c:\windows\system32\_003457_.tmp.dll c:\windows\system32\_003458_.tmp.dll c:\windows\system32\_003459_.tmp.dll c:\windows\system32\_003460_.tmp.dll c:\windows\system32\_003461_.tmp.dll c:\windows\system32\_003462_.tmp.dll c:\windows\system32\_003463_.tmp.dll c:\windows\system32\_003465_.tmp.dll c:\windows\system32\_003466_.tmp.dll c:\windows\system32\_003467_.tmp.dll c:\windows\system32\_003468_.tmp.dll c:\windows\system32\_003469_.tmp.dll c:\windows\system32\_003470_.tmp.dll c:\windows\system32\_003471_.tmp.dll c:\windows\system32\_003472_.tmp.dll c:\windows\system32\_003473_.tmp.dll c:\windows\system32\_003474_.tmp.dll c:\windows\system32\_003475_.tmp.dll c:\windows\system32\_003476_.tmp.dll c:\windows\system32\_003478_.tmp.dll c:\windows\system32\_003479_.tmp.dll c:\windows\system32\_003480_.tmp.dll c:\windows\system32\_003481_.tmp.dll c:\windows\system32\_003483_.tmp.dll c:\windows\system32\_003485_.tmp.dll c:\windows\system32\_003486_.tmp.dll c:\windows\system32\_003487_.tmp.dll c:\windows\system32\_003488_.tmp.dll c:\windows\system32\_003489_.tmp.dll c:\windows\system32\_003490_.tmp.dll c:\windows\system32\_003491_.tmp.dll c:\windows\system32\_003493_.tmp.dll c:\windows\system32\_003494_.tmp.dll c:\windows\system32\_003495_.tmp.dll c:\windows\system32\_003496_.tmp.dll c:\windows\system32\_003497_.tmp.dll c:\windows\system32\_003498_.tmp.dll c:\windows\system32\_003499_.tmp.dll c:\windows\system32\_003500_.tmp.dll c:\windows\system32\_003501_.tmp.dll c:\windows\system32\_003502_.tmp.dll c:\windows\system32\_003503_.tmp.dll c:\windows\system32\_003504_.tmp.dll c:\windows\system32\_003505_.tmp.dll c:\windows\system32\_003506_.tmp.dll c:\windows\system32\_003507_.tmp.dll c:\windows\system32\_003508_.tmp.dll c:\windows\system32\_003510_.tmp.dll c:\windows\system32\_003511_.tmp.dll c:\windows\system32\_003512_.tmp.dll c:\windows\system32\_003513_.tmp.dll c:\windows\system32\_003515_.tmp.dll c:\windows\system32\_003517_.tmp.dll c:\windows\system32\_003518_.tmp.dll c:\windows\system32\_003519_.tmp.dll c:\windows\system32\_003520_.tmp.dll c:\windows\system32\_003521_.tmp.dll c:\windows\system32\_003522_.tmp.dll c:\windows\system32\_003523_.tmp.dll c:\windows\system32\_003525_.tmp.dll c:\windows\system32\_003526_.tmp.dll c:\windows\system32\_003527_.tmp.dll c:\windows\system32\_003528_.tmp.dll c:\windows\system32\_003529_.tmp.dll c:\windows\system32\_003530_.tmp.dll c:\windows\system32\_003531_.tmp.dll c:\windows\system32\_003532_.tmp.dll c:\windows\system32\_003534_.tmp.dll c:\windows\system32\_003535_.tmp.dll c:\windows\system32\_003537_.tmp.dll c:\windows\system32\_003538_.tmp.dll c:\windows\system32\_003540_.tmp.dll c:\windows\system32\_003541_.tmp.dll c:\windows\system32\_003545_.tmp.dll c:\windows\system32\_003546_.tmp.dll c:\windows\system32\_003548_.tmp.dll c:\windows\system32\_003551_.tmp.dll c:\windows\system32\_003553_.tmp.dll c:\windows\system32\_003554_.tmp.dll c:\windows\system32\_003555_.tmp.dll c:\windows\system32\_003556_.tmp.dll c:\windows\system32\_003559_.tmp.dll c:\windows\system32\_003560_.tmp.dll c:\windows\system32\_003561_.tmp.dll c:\windows\system32\_003562_.tmp.dll c:\windows\system32\_003563_.tmp.dll c:\windows\system32\_003568_.tmp.dll c:\windows\system32\_003570_.tmp.dll c:\windows\system32\_003571_.tmp.dll Infected copy of c:\windows\system32\drivers\atapi.sys was found and disinfected Kitty ate it . ((((((((((((((((((((((((( Files Created from 2009-09-07 to 2009-10-07 ))))))))))))))))))))))))))))))) . 2009-10-07 03:12 . 2009-10-07 03:13 -------- d-----w- c:\program files\SUPERAntiSpyware 2009-10-07 03:12 . 2009-10-07 03:12 -------- d-----w- c:\documents and settings\owner\Application Data\SUPERAntiSpyware.com 2009-10-07 03:12 . 2009-10-07 03:12 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard 2009-10-07 00:44 . 2009-10-07 00:45 -------- d-----w- c:\program files\ERUNT 2009-10-06 21:01 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-10-06 21:01 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-10-06 21:01 . 2009-10-06 21:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2009-10-03 22:11 . 2009-10-03 22:11 -------- d-----w- c:\program files\Common Files\xing shared 2009-10-02 16:02 . 2009-10-01 17:29 195440 ------w- c:\windows\system32\MpSigStub.exe 2009-10-01 04:28 . 2009-10-01 04:28 -------- d-----w- c:\documents and settings\All Users\Application Data\IObit 2009-09-14 18:54 . 2009-06-21 21:44 153088 -c----w- c:\windows\system32\dllcache\triedit.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-10-07 19:04 . 2006-08-25 02:45 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec 2009-10-07 18:08 . 2008-03-30 18:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy 2009-10-07 18:04 . 2008-09-21 03:08 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP 2009-10-06 20:28 . 2009-01-02 17:45 -------- d-----w- c:\program files\Spyware Doctor 2009-10-03 22:12 . 2006-02-16 09:56 -------- d-----w- c:\program files\Common Files\Real 2009-10-03 22:11 . 2006-02-16 09:56 -------- d-----w- c:\program files\Real 2009-10-01 04:28 . 2009-08-15 06:13 -------- d-----w- c:\program files\IObit 2009-09-14 23:29 . 2009-02-17 04:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-09-14 22:13 . 2009-08-06 04:35 -------- d-----w- c:\documents and settings\owner\Application Data\Logs 2009-09-14 22:13 . 2009-02-17 04:36 -------- d-----w- c:\documents and settings\owner\Application Data\OfficeUpdate12 2009-09-14 22:13 . 2006-02-17 09:57 -------- d-----w- c:\program files\DIGStream 2009-09-14 22:13 . 2006-02-17 09:57 -------- d-----w- c:\program files\ESPNMotion 2009-09-14 22:13 . 2006-02-16 09:55 -------- d-----w- c:\program files\America Online 9.0 2009-09-05 06:23 . 2009-08-15 06:13 -------- d-----w- c:\documents and settings\owner\Application Data\IObit 2009-08-11 05:59 . 2008-09-21 03:07 -------- d-----w- c:\program files\SpywareBlaster 2009-08-11 05:22 . 2009-08-11 05:22 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{EF63305C-BAD7-4144-9208-D65528260864} 2009-08-11 02:06 . 2008-03-30 18:56 -------- d-----w- c:\program files\Spybot - Search & Destroy 2009-08-08 12:33 . 2009-06-09 00:30 55656 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-08-07 02:24 . 2006-02-15 15:36 327896 ----a-w- c:\windows\system32\wucltui.dll 2009-08-07 02:24 . 2006-02-15 15:36 209632 ----a-w- c:\windows\system32\wuweb.dll 2009-08-07 02:24 . 2006-08-24 18:00 44768 ----a-w- c:\windows\system32\wups2.dll 2009-08-07 02:24 . 2006-02-15 15:36 35552 ----a-w- c:\windows\system32\wups.dll 2009-08-07 02:24 . 2006-02-15 15:36 53472 ----a-w- c:\windows\system32\wuauclt.exe 2009-08-07 02:24 . 2006-02-15 14:02 96480 ----a-w- c:\windows\system32\cdm.dll 2009-08-07 02:23 . 2006-02-15 15:36 575704 ----a-w- c:\windows\system32\wuapi.dll 2009-08-07 02:23 . 2009-03-07 23:26 215920 ----a-w- c:\windows\system32\muweb.dll 2009-08-07 02:23 . 2009-03-07 23:26 274288 ----a-w- c:\windows\system32\mucltui.dll 2009-08-07 02:23 . 2006-02-15 15:36 1929952 ----a-w- c:\windows\system32\wuaueng.dll 2009-08-05 09:01 . 2006-02-15 14:03 204800 ----a-w- c:\windows\system32\mswebdvd.dll 2009-07-17 19:01 . 2006-02-15 14:02 58880 ----a-w- c:\windows\system32\atl.dll 2009-07-14 06:43 . 2006-02-15 14:05 286208 ----a-w- c:\windows\system32\wmpdxm.dll 2006-10-11 08:04 . 2007-05-23 01:03 61036 ----a-w- c:\program files\mozilla firefox\components\jar50.dll 2006-10-11 08:04 . 2007-05-23 01:03 48742 ----a-w- c:\program files\mozilla firefox\components\jsd3250.dll 2006-10-11 08:05 . 2007-05-23 01:03 29313 ----a-w- c:\program files\mozilla firefox\components\myspell.dll 2006-10-11 08:05 . 2007-05-23 01:03 41082 ----a-w- c:\program files\mozilla firefox\components\spellchk.dll 2006-10-11 08:04 . 2007-05-23 01:03 166510 ----a-w- c:\program files\mozilla firefox\components\xpinstal.dll 2009-05-01 21:02 . 2009-05-01 21:02 1044480 ----a-w- c:\program files\mozilla firefox\plugins\libdivx.dll 2009-05-01 21:02 . 2009-05-01 21:02 200704 ----a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2009-09-15 1998576] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-10-03 198160] "IObit Security 360"="c:\program files\IObit\IObit Security 360\IS360tray.exe" [2009-09-29 1241872] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2008-11-04 435096] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon] 2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service] @="Service" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^RAMASST.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\RAMASST.lnk backup=c:\windows\pss\RAMASST.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "DefWatch"=2 (0x2) "ccSetMgr"=2 (0x2) "ccEvtMgr"=2 (0x2) "Symantec AntiVirus"=2 (0x2) "SNDSrvc"=3 (0x3) "Symantec Core LC"=3 (0x3) [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [1/28/2009 7:51 PM 64160] R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [5/30/2009 10:21 PM 130936] R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [1/2/2009 10:45 AM 160792] R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [9/15/2009 11:42 AM 9968] R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [9/15/2009 11:42 AM 74480] R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [6/8/2009 5:30 PM 108289] R2 IS360service;IS360service;c:\program files\IObit\IObit Security 360\is360srv.exe [9/30/2009 9:28 PM 309008] R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [11/3/2006 7:19 PM 13592] R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [9/15/2009 11:42 AM 7408] S2 gupdate1c9b4f01ad1c2b8;Google Update Service (gupdate1c9b4f01ad1c2b8);c:\program files\Google\Update\GoogleUpdate.exe [4/3/2009 11:39 PM 133104] S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/3/2009 7:49 AM 1029456] S3 samhid;samhid;c:\windows\system32\drivers\Samhid.sys [5/6/2007 7:55 PM 7548] S3 SavRoam;SAVRoam;"c:\program files\Symantec AntiVirus\SavRoam.exe" --> c:\program files\Symantec AntiVirus\SavRoam.exe [?] S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [1/2/2009 10:45 AM 348752] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP . Contents of the 'Scheduled Tasks' folder 2009-10-07 c:\windows\Tasks\Ad-Aware Update (Weekly).job - c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:49] 2009-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-04 06:39] 2009-10-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-04-04 06:39] 2009-10-07 c:\windows\Tasks\MP Scheduled Scan.job - c:\program files\Windows Defender\MpCmdRun.exe [2006-11-04 02:20] . . ------- Supplementary Scan ------- . uStart Page = hxxp://www.google.com uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 mStart Page = hxxp://www.google.com uInternet Connection Wizard,ShellNext = hxxp://www.toshibadirect.com/dpdstart uSearchURL,(Default) = hxxp://www.google.com/search?q=%s IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 FF - ProfilePath - c:\documents and settings\owner\Application Data\Mozilla\Firefox\Profiles\nk4pu3ra.default\ FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q= FF - component: c:\program files\Mozilla Firefox\components\xpinstal.dll FF - component: c:\program files\Mozilla Firefox\extensions\talkback@mozilla.org\components\qfaservices.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ . - - - - ORPHANS REMOVED - - - - Toolbar-Locked - (no file) Toolbar-ITBar7Layout - (no file) ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-10-07 12:32 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . --------------------- DLLs Loaded Under Running Processes --------------------- - - - - - - - > 'winlogon.exe'(944) c:\program files\SUPERAntiSpyware\SASWINLO.dll c:\windows\system32\WININET.dll - - - - - - - > 'explorer.exe'(2280) c:\windows\system32\WININET.dll c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.3053_x-ww_b80fa8ca\MSVCR80.dll c:\windows\system32\webcheck.dll c:\windows\system32\IEFRAME.dll c:\windows\system32\WPDShServiceObj.dll c:\program files\Common Files\aolshare\aolshcpy.dll c:\windows\system32\PortableDeviceTypes.dll c:\windows\system32\PortableDeviceApi.dll . ------------------------ Other Running Processes ------------------------ . c:\program files\Intel\Wireless\Bin\EvtEng.exe c:\program files\Intel\Wireless\Bin\S24EvMon.exe c:\program files\Avira\AntiVir Desktop\avguard.exe c:\program files\Common Files\AOL\ACS\AOLacsd.exe c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe c:\program files\TOSHIBA\ConfigFree\CFSvcs.exe c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe c:\windows\system32\DVDRAMSV.exe c:\windows\ehome\ehrecvr.exe c:\windows\ehome\ehSched.exe c:\program files\Intel\Wireless\Bin\RegSrvc.exe c:\windows\ehome\mcrdsvc.exe c:\windows\system32\dllhost.exe c:\program files\IObit\IObit Security 360\is360.exe . ************************************************************************** . Completion time: 2009-10-07 12:41 - machine was rebooted ComboFix-quarantined-files.txt 2009-10-07 19:41 Pre-Run: 80,948,461,568 bytes free Post-Run: 80,825,110,528 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect 350 --- E O F --- 2009-10-05 16:40 |
|
|
Oct 7 2009, 02:03 PM
Post
#4
|
|
![]() GeekU Teacher Posts: 42,897 From: Dublin OS: XP |
hi
Download TFC to your desktop
Please download Malwarebytes' Anti-Malware from Here Double Click mbam-setup.exe to install the application.
Extra Note: If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly. Go to Kaspersky website and perform an online antivirus scan.
|
|
|
Oct 8 2009, 05:27 PM
Post
#5
|
|
|
Member ![]() ![]() Posts: 14 OS: windows XP |
Malwarebytes' Anti-Malware 1.41
Database version: 2916 Windows 5.1.2600 Service Pack 3 10/8/2009 3:49:13 PM mbam-log-2009-10-08 (15-49-13).txt Scan type: Quick Scan Objects scanned: 118178 Time elapsed: 10 minute(s), 7 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, October 7, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, October 07, 2009 23:18:54 Records in database: 2931287 -------------------------------------------------------------------------------- Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Objects scanned: 69529 Threats found: 0 Infected objects found: 0 Suspicious objects found: 0 Scan duration: 02:15:00 No threats found. Scanned area is clean. Selected area has been scanned. |
|
|
Oct 9 2009, 06:39 AM
Post
#6
|
|
![]() GeekU Teacher Posts: 42,897 From: Dublin OS: XP |
hi
CLICK HERE to download the HijackThis Installer:
|
|
|
Oct 13 2009, 10:12 AM
Post
#7
|
|
![]() GeekU Teacher Posts: 42,897 From: Dublin OS: XP |
Due to lack of feedback, this topic has been closed.
If you need this topic reopened, please contact a staff member. This applies only to the original topic starter. Everyone else please begin a New Topic. |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
8 / 771 | 30th April 2009 - 09:24 AM 94SupraTT started - last by Rorschach112 |
|||||
![]() |
7 / 475 | 15th July 2009 - 04:45 PM rikaard started - last by Rorschach112 |
|||||
![]() |
16 / 1,203 | 9th August 2009 - 08:18 AM mountaineer26070 started - last by Essexboy |
|||||
![]() |
10 / 278 | 16th November 2009 - 12:07 PM Kenglert started - last by Rorschach112 |
|||||
|
Time is now: 11th March 2010 - 06:48 PM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising