Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Exploit trojans?


  • Please log in to reply

#16
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts
I have had quite a few friends have that surgery, and they all healed amazingly quickly, and felt 100% better after. Hope you Mom has the same experiences too. No problem - post when time allows.
  • 0

Advertisements


#17
dantemic1

dantemic1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Here is the log you asked for. However when it comes to that file when I looked it up it didn't find it.


C:\Qoobox\Quarantine\C\ProgramData\XP\EBLib.dll.vir -> C:\ProgramData\XP\EBLib.dll ( 32768 bytes )
C:\Qoobox\Quarantine\C\ProgramData\XP\TPwSav.sys.vir -> C:\ProgramData\XP\TPwSav.sys ( 11264 bytes )
  • 0

#18
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts
How's your Mom doing? Looks like ComboFix put the files back. No malware being picked up, so on that familiar note, how's you computer doing as well - any problems?
  • 0

#19
dantemic1

dantemic1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
She is doing better thanks. My friends dad also just had surgery like that and he came out pretty good. They were just worried about my mom because she had a lung removed 9 years ago due lung cancer she got from a job she worked at. So she is more apt to experience problems with any kind of surgery.

As for the computer it runs a little slow but I think I need to start removing programs I do not use anymore. Thanks for the help!! I just wanted to make sure that I removed the stuff that was partially removed when I first posted. :)
  • 0

#20
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts
Very good news your Mom is doing well. Some changes to make still, and then we really do need to still check what all is installed there, before we wrap things up.


REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main]
"Start Page"="http://www.yahoo.com/"
Go to Start Search, type notepad.exe in the Start Search box. Notepad.exe will appear at the top of the Menu. Rightclick on it and choose "Run as administrator"., and copy the text inside the box above and paste it into the open Notepad textbox.

Save this to your desktop as "fixer.reg"

Be sure to include the "" quotes in the name.

Then right click fixer.reg, select Merge, and allow it to merge the new information with the Registry.

---------------

In Firefox, type the following into the address bar:

about:config

In the Filter box at the top of that display, type in each of the following, one at a time, and make the changes I suggest below each please:

browser.search.defaulturl

Modify it to this (inside the Code box):

http://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=


keyword.URL

To this:

http://www.google.com/search?ie=UTF-8&oe=UTF-8&sourceid=navclient&gfns=1&q=


This:

browser.search.selectedEngine

Modify it to this:

Google


Those changes will be completed once Firefox is closed and re-opened.

-----------

Please download HijackThis from Here. Then click on the downloaded file, and install HijackThis.

Click Config - Misc Tools - Open Uninstall Manager.

Click on Save List, then save that to a location you can locate again (such as the desktop). Copy/paste the contents of that back here please.
  • 0

#21
dantemic1

dantemic1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Here is the uninstall list that you asked for and I also completed everything else. :thumbsup:

Update for Microsoft Office 2007 (KB2508958)
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.5
ALPS Touch Pad Driver
Atheros Driver Installation Program
Atheros Wi-Fi Protected Setup Library
Belkin Setup and Router Monitor
BlackBerry Desktop Software 6.0
BlackBerry Desktop Software 6.0
BlackBerry Device Software Updater
Bluetooth Stack for Windows by Toshiba
CA Yahoo! Anti-Spy (remove only)
CD/DVD Drive Acoustic Silencer
Compatibility Pack for the 2007 Office system
D3DX10
DVD MovieFactory for TOSHIBA
eMusic Download Manager 4.1.4
ESET Online Scanner v3
FrostWire 4.21.3
FrostWire 5.1.5
GearDrvs
Google Desktop
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Update Helper
HijackThis 2.0.2
  • 0

#22
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts
I kinda think, alphabetically-wise, that list is a tad shy of an entire list (ends at "H"). Could you check that please.
  • 0

#23
dantemic1

dantemic1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Oops sorry about that one lol. Here is the whole list....seems to be a lot of things.


Update for Microsoft Office 2007 (KB2508958)
Activation Assistant for the 2007 Microsoft Office suites
Adobe AIR
Adobe AIR
Adobe Flash Player 10 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.1)
Adobe Shockwave Player 11.5
ALPS Touch Pad Driver
Atheros Driver Installation Program
Atheros Wi-Fi Protected Setup Library
Belkin Setup and Router Monitor
BlackBerry Desktop Software 6.0
BlackBerry Desktop Software 6.0
BlackBerry Device Software Updater
Bluetooth Stack for Windows by Toshiba
CA Yahoo! Anti-Spy (remove only)
CD/DVD Drive Acoustic Silencer
Compatibility Pack for the 2007 Office system
D3DX10
DVD MovieFactory for TOSHIBA
eMusic Download Manager 4.1.4
ESET Online Scanner v3
FrostWire 4.21.3
FrostWire 5.1.5
GearDrvs
Google Desktop
Google Toolbar for Internet Explorer
Google Toolbar for Internet Explorer
Google Update Helper
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
HTC BMP USB Driver
HTC Driver Installer
HTC Sync
Intel® Graphics Media Accelerator Driver
Java™ 6 Update 29
Junk Mail filter update
LiveUpdate (Symantec Corporation)
LiveUpdate (Symantec Corporation)
LiveUpdate 3.2 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
Malwarebytes' Anti-Malware version 1.51.2.1300
McAfee Internet Security
McAfee Online Backup
McAfee Online Backup
McAfee Security Scan Plus
McAfee Virtual Technician
Media Converter for Philips
Memeo AutoBackup
Mesh Runtime
Messenger Companion
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft .NET Framework 4 Client Profile
Microsoft Easy Assist v2
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office 2007 Service Pack 2 (SP2)
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office File Validation Add-In
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.5
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Works
Mozilla Firefox 4.0.1 (x86 en-US)
MSVCRT
MSXML 4.0 SP2 (KB941833)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 4.0 SP2 Parser and SDK
MSXML 4.0 SP3 Parser
MSXML 4.0 SP3 Parser (KB973685)
OGA Notifier 2.0.0048.0
Opera 11.52
Paint Shop Pro 7
Payroll Accounting 2010
QuickTime
Realtek 8169 PCI, 8168 and 8101E PCIe Ethernet Network Card Driver for Windows Vista
Realtek High Definition Audio Driver
SAMSUNG Mobile Modem Driver Set
Samsung Mobile phone USB driver Software
SAMSUNG Mobile USB Modem 1.0 Software
SAMSUNG Mobile USB Modem Software
Security Update for 2007 Microsoft Office System (KB2288621)
Security Update for 2007 Microsoft Office System (KB2288931)
Security Update for 2007 Microsoft Office System (KB2345043)
Security Update for 2007 Microsoft Office System (KB2553074)
Security Update for 2007 Microsoft Office System (KB2553089)
Security Update for 2007 Microsoft Office System (KB2553090)
Security Update for 2007 Microsoft Office System (KB2584063)
Security Update for 2007 Microsoft Office System (KB969559)
Security Update for 2007 Microsoft Office System (KB976321)
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Access 2007 (KB979440)
Security Update for Microsoft Office Excel 2007 (KB2553073)
Security Update for Microsoft Office Groove 2007 (KB2552997)
Security Update for Microsoft Office InfoPath 2007 (KB2510061)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office InfoPath 2007 (KB979441)
Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
Security Update for Microsoft Office Publisher 2007 (KB2284697)
Security Update for Microsoft Office system 2007 (972581)
Security Update for Microsoft Office system 2007 (KB974234)
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
Security Update for Microsoft Office Word 2007 (KB2344993)
Security Update for Windows Media Encoder (KB2447961)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Encoder (KB979332)
Segoe UI
SupportSoft Assisted Service
SweetIM for Messenger 3.0
Synaptics Pointing Device Driver
Texas Instruments PCIxx21/x515/xx12 drivers.
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Disc Creator
TOSHIBA DVD PLAYER
TOSHIBA Extended Tiles for Windows Mobility Center
TOSHIBA Flash Cards Support Utility
TOSHIBA Games
TOSHIBA Hardware Setup
Toshiba Registration
TOSHIBA SD Memory Utilities
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
TOSHIBA Value Added Package
Ulead GIF Animator 5
Update for 2007 Microsoft Office System (KB967642)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523)
Update for Microsoft Office 2007 Help for Common Features (KB963673)
Update for Microsoft Office 2007 System (KB2539530)
Update for Microsoft Office Access 2007 Help (KB963663)
Update for Microsoft Office Excel 2007 Help (KB963678)
Update for Microsoft Office Infopath 2007 Help (KB963662)
Update for Microsoft Office OneNote 2007 (KB980729)
Update for Microsoft Office OneNote 2007 Help (KB963670)
Update for Microsoft Office Outlook 2007 (KB2583910)
Update for Microsoft Office Outlook 2007 Help (KB963677)
Update for Microsoft Office Powerpoint 2007 Help (KB963669)
Update for Microsoft Office Publisher 2007 Help (KB963667)
Update for Microsoft Office Script Editor Help (KB963671)
Update for Microsoft Office Word 2007 Help (KB963665)
Update for Outlook 2007 Junk Email Filter (KB2596560)
Visual C++ 8.0 ATL (x86) WinSXS MSM
Visual C++ 8.0 CRT (x86) WinSXS MSM
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Family Safety
Windows Live Family Safety
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Mail
Windows Live Mail
Windows Live Mesh
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live Messenger
Windows Live Messenger Companion Core
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Movie Maker
Windows Live OneCare safety scanner
Windows Live Photo Common
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Sync
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer
Windows Live Writer
Windows Live Writer Resources
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Player Firefox Plugin
Word Riot Deluxe
Xobni
Xobni Core
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar


By the way I hope that you have a great Thanksgiving!!
  • 0

#24
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts
Looks clean, and the only malware are items ComboFix already removed to it's Qoobox quarantine folder, so harmless.

For this:

C:\Users\cliff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Advanced Registry Optimizer.lnk

Assuming you made sure you have an accurate view of files there, make sure you can View Hidden Files.

Click Start - right click Computer, click Explore (or Open if no Explore option). Navigate to that C:\Users\cliff\AppData, click on AppData, then look in the right side column for Roaming. Follow that method to arrive at Start Menu\Programs\Startup, where that link should be.

No malware - you did well. Before we consider some final cleaning up steps here, post back how things are running please.
  • 0

#25
dantemic1

dantemic1

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
I found this .... C:\Program Files\Advanced Registry Optimizer. Should I delete that one cause that is the only thing I see there besides some configuration settings.
  • 0

Advertisements


#26
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts

By the way I hope that you have a great Thanksgiving!!


Sorry, I missed that. I am in the US, and yes, I truly did, thanks, and also hope your's was enjoyable.

I reckon I am misreading the log info, but do go ahead and delete that Advanced Registry Optimizer folder.


Some review of installed softwares you may want to consider removing.

FrostWire 4.21.3 and
FrostWire 5.1.5 - Torrent software is how systems get some of the most serious infection. Picture everyone in your town placing food on a very large table, and you come along, without knowing where any of it came from, and start eating. Malware vendors most definitely provide torrent "food"
CA Yahoo! Anti-Spy (remove only) - Not known to be effective for malware protection, and can interfere with programs that are.
SweetIM for Messenger 3.0 - Some of this vendors methods are not considered to be in the user's best interest.

If you do not regularly use any of these, they bog down your browser, can bog down your bandwidth with their unseen traffic back to their motherships, and in the case of any Google software, that so-called "Updater" is always installed. Runs at startup, and immediately attempts to access it's servers, regardless if there is Internet access established yet. Slows things down in many ways:

Google Desktop - Major resource user.
Google Toolbar for Internet Explorer
Google Update Helper
Yahoo! Browser Services
Yahoo! Install Manager
Yahoo! Internet Mail
Yahoo! Messenger
Yahoo! Software Update
Yahoo! Toolbar


Make any changes necessary, then before we consider some cleaning up of what our work added there, post back how everything is running please.
  • 0

#27
Jintan

Jintan

    Trusted Helper

  • Malware Removal
  • 904 posts
Oops - just glanced at my notes, and missed one item. The logs show some past Norton install left behind it's Live Update components. In addition to what I have already suggested, please go here and download the Norton Removal Tool that is appropriate for your version. Then close all open windows and disable all protective software, and click the downloaded file to completely remove Norton from your system. If the removal does not cause a reboot reboot after the tool has completed the removal.

If you do not recall the version that is okay - the same tool is used for most versions, and in this case should do the job.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP