Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Constant Virus Probs + Crashes


  • Please log in to reply

#1
LSEactuary

LSEactuary

    Member

  • Member
  • PipPip
  • 79 posts
Hi,

This week - yet again - my computer got a new virus - Windows Security Alert. I have managed to delete it with the help of the tech experts on the live help (thanks sooooo much!!!!) but I want to avoid all these virus problems in the future. Each new virus seems to be worse then the previous one and my computer goes to a blue screen with white writing sometimes. I dont use utorrent or any other torrent applications and hence do not understand where these viruses crop up from. I have MSE installed and make sure i scan the computer regularly - yet every weekend (for the past 5 weeks) i end up repairing the computer.

I have kept track of websites used by others on this computer and every site is 'legal' - ie hotmail, messenger websites, games, and normal google searches. I have not used combofix or any other software other then mbam (and the other bits and pieces on the maleware removing thread) so im not sure why it went to the blue screen and this morning suddenly worked again...?

I have posted the logs below after deleting the current virus. please suggest what I can do to avoid further problems.

Thanks in advance! :)

Attached Files

  • Attached File  OTL.Txt   113.53KB   56 downloads
  • Attached File  ark.txt   2.93KB   58 downloads

  • 0

Advertisements


#2
LSEactuary

LSEactuary

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts
i dont think its fully healed.

the computer frezes after about 1 hour especially the internet and google chrome

its a bit slower then usual too.
  • 0

#3
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hello,

My name is SweetTech. I would be glad to take a look at your log and help you with solving any malware problems.

If you have already received help elsewhere please inform me so that this topic can be closed.

If you have not, please adhere to the guidelines below and then follow instructions as outlined further below:

  • Logs from malware removal programs (OTL is one of them) can take some time to analyze. I need you to be patient while I analyze any logs you post.
  • Please make sure to carefully read any instruction that I give you.
    Reading too lightly will cause you to miss important steps, which could have destructive effects.
  • If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • These instructions have been specifically tailored to your computer and the issues you are experiencing with your computer. It's important to note that these instructions are not suitable for any other computer, even if the issues are fairly similar.
  • Do not do things I do not ask for, such as running a spyware scan on your computer. The one thing that you should always do, is to make sure sure that your anti-virus definitions are up-to-date!
  • If I instruct you to download a specific tool in which you already have, please delete the copy that you have and re-download the tool. The reason I ask you to do this is because these tools are updated fairly regularly.
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • I am going to stick with you until ALL malware is gone from your system. I would appreciate it if you would do the same. From this point, we're in this together :)
    Because of this, you must reply within three days
    failure to reply will result in the topic being closed!
  • Please do not PM me directly for help. If you have any questions, post them in this topic. The only time you can and should PM me is when I have not been replying to you for several days (usually around 3 days) and you need an explanation. If that's the case, just send me a message to me on here. :)
  • Lastly, I am no magician. I will try very hard to fix your issues, but no promises can be made. Also be aware that some infections are so severe that you might need to resort to reformatting and reinstalling your operating system.
    Don't worry, this only happens in severe cases, but it sadly does happen. Be prepared to back up your data. Have means of backing up your data available.
____________________________________________________

I'm reviewing your logs now, and will be back with instructions shortly.
  • 0

#4
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Hello again,


OTL Fix

We need to run an OTL Fix
  • Please reopen Posted Image on your desktop.
  • Copy and Paste the following code into the Posted Image textbox. Do not include the word "Code"

    :Services
    :OTL
    DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:6092
    O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No CLSID value found.
    O9 - Extra Button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
    O9 - Extra 'Tools' menuitem : PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe File not found
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2010/09/02 19:54:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\raekircxo
    [2010/09/02 19:54:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\tmikiapga
    [2010/08/29 20:04:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\{3DF7E812-BE07-4FF6-8556-2054F51FAE99}
    [2010/08/16 07:17:45 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\MSKITGRRJS
    [2010/08/16 07:17:32 | 000,000,000 | -HSD | C] -- C:\Documents and Settings\All Users\Application Data\d33f0d2
    [2010/08/15 15:31:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\rbbiqhuvi
    [2010/07/11 11:55:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Anxyom
    [2010/07/07 17:14:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Ziekok
    [2010/06/28 05:07:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Miyniw
    [2010/09/02 19:54:11 | 000,000,005 | ---- | M] () -- C:\zrpt.xml
    [2010/09/02 07:41:19 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Scoto.bin
    [2010/09/01 17:04:17 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Fnumalo.dat
    [2010/08/02 16:23:06 | 000,002,155 | ---- | M] () -- C:\rapport.txt
    [2010/08/20 19:16:04 | 000,000,444 | ---- | M] () -- C:\rkill.log
    @Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    :Commands
    [purity]
    [resethosts]
    [CreateRestorePoint]
    [emptytemp]
    [EMPTYFLASH]
    
  • Push Posted Image
  • OTL may ask to reboot the machine. Please do so if asked.
  • Click Posted Image.
  • A report will open. Copy and Paste that report in your next reply.
  • If the machine reboots, the log will be located at C:\_OTL\MovedFiles\mmddyyyy_hhmmss.log, where mmddyyyy_hhmmss is the date of the tool run.


NEXT:



Running ComboFix
Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your Anti-Virus and Anti-Spyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

Posted Image

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

Posted Image

  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the ComboFix log in your next reply as well as describe how your computer is running now
  • 0

#5
LSEactuary

LSEactuary

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts
sorry for the delay... i work mon-fri.

here are the logs.
  • 0

#6
LSEactuary

LSEactuary

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts
All processes killed
Error: Unable to interpret <[resethosts]> in the current context!
Error: Unable to interpret <[CreateRestorePoint]> in the current context!
Error: Unable to interpret <[emptytemp]> in the current context!
Error: Unable to interpret <[EMPTYFLASH]> in the current context!

OTL by OldTimer - Version 3.2.11.0 log created on 09052010_194429

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...
  • 0

#7
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
It doesn't seem like the OTL fix worked properly. Could you please try to run it again following the instructions very carefully in my previous post.
  • 0

#8
LSEactuary

LSEactuary

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts
Hre are the OTL Logs when i ran it again:

All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Service catchme stopped successfully!
Service catchme deleted successfully!
File C:\ComboFix\catchme.sys File not found not found.
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1FD79A59-37B1-459B-9097-09F9FAB8A523}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1FD79A59-37B1-459B-9097-09F9FAB8A523}\ not found.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{4B3803EA-5230-4DC3-A7FC-33638F3D3542} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4B3803EA-5230-4DC3-A7FC-33638F3D3542}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B7FE5D70-9AA2-40F1-9C6B-12A255F085E1}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Folder C:\Documents and Settings\user\Local Settings\Application Data\raekircxo\ not found.
Folder C:\Documents and Settings\user\Local Settings\Application Data\tmikiapga\ not found.
Folder C:\Documents and Settings\user\Local Settings\Application Data\{3DF7E812-BE07-4FF6-8556-2054F51FAE99}\ not found.
Folder C:\Documents and Settings\All Users\Application Data\MSKITGRRJS\ not found.
Folder C:\Documents and Settings\All Users\Application Data\d33f0d2\ not found.
Folder C:\Documents and Settings\user\Application Data\rbbiqhuvi\ not found.
Folder C:\Documents and Settings\user\Application Data\Anxyom\ not found.
Folder C:\Documents and Settings\user\Application Data\Ziekok\ not found.
Folder C:\Documents and Settings\user\Application Data\Miyniw\ not found.
File C:\zrpt.xml not found.
File C:\WINDOWS\Scoto.bin not found.
File C:\WINDOWS\Fnumalo.dat not found.
File C:\rapport.txt not found.
File C:\rkill.log not found.
Unable to delete ADS C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 .
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\user\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\user\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
Restore point Set: OTL Restore Point (0)

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 7628384 bytes
->Java cache emptied: 38557 bytes
->Flash cache emptied: 1245 bytes

User: NetworkService
->Temp folder emptied: 107968 bytes
->Temporary Internet Files folder emptied: 29872624 bytes
->Java cache emptied: 16125 bytes
->Flash cache emptied: 3315 bytes

User: user
->Temp folder emptied: 15539829 bytes
->Temporary Internet Files folder emptied: 117704330 bytes
->Java cache emptied: 49998 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 61628775 bytes
->Flash cache emptied: 22429 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10613161 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 232.00 mb


[EMPTYFLASH]

User: Administrator
->Flash cache emptied: 0 bytes

User: All Users

User: Default User
->Flash cache emptied: 0 bytes

User: LocalService
->Flash cache emptied: 0 bytes

User: NetworkService
->Flash cache emptied: 0 bytes

User: user
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


OTL by OldTimer - Version 3.2.12.1 log created on 09192010_140633

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...



Your instructions say not to re-run Combofix so I havent... should I?
  • 0

#9
SweetTech

SweetTech

    Sir SpamAlot

  • Retired Staff
  • 7,671 posts
Have you already ran ComboFix? If so, please locate the log and post it for me, instructions will follow on how to locate the log. IF you didn't run ComboFix, then please go ahead and run it now.

Locating ComboFix Log
  • Right click on START on the left end of your Windows toolbar (lower left corner of your screen)
  • Click on Explore
  • Click on Local Disk (C:) in the left-hand window pane
  • Look for ComboFix.txt in the right-hand window pane and right click on it
  • Put your cursor (arrow) on Open With
  • Move your cursor to the new menu that opens and click on Choose Program...
  • Click on Notepad

When file opens, Copy/Paste text here.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP