What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
Closed TopicStart new topic
> [Resolved] Bad Image Error after virus removal
Comcrap
post Sep 24 2009, 08:46 PM
Post #1


Authentic Member
**

Group: Authentic Member
Posts: 22
Joined: 24-September 09
Member No.: 88,070
Operating System: Windows XP Professional, Windows Vista



I recently noticed my browser acting funny (redirecting me while I tried to browse google.)

I did a Malwarebyte's AntiMalware quick scan, and it found 9 infected objects (rootkits, some Dlls with randomly generated letters for names)

It deleted all but 3, located in the system32 folder and told me it'd have to delete them on restart, so I hesitantly restarted.

Sure enough it started giving me weird stuff.

Now every time a process starts, it gives me an error message saying

notepad.exe - Bad Image
The application or DLL Globalroot\systemroot\system32\gasfkybqqpkrod.dll is not a valid windows Image. Please check this against your installation diskette.

how do I fix this?

Right now, I'm running windows Xp professional on a Desktop system.

This post has been edited by Comcrap: Sep 24 2009, 08:46 PM
Go to the top of the page
 
+Quote Post
 
Start new topic
Replies
Comcrap
post Sep 25 2009, 03:47 AM
Post #2


Authentic Member
**

Group: Authentic Member
Posts: 22
Joined: 24-September 09
Member No.: 88,070
Operating System: Windows XP Professional, Windows Vista



FOR GMER

GMER 1.0.15.15087 - http://www.gmer.net
Rootkit scan 2009-09-25 01:59:11
Windows 5.1.2600 Service Pack 2
Running: gmer.exe; Driver: C:\DOCUME~1\beta\LOCALS~1\Temp\ffrcrfow.sys


---- System - GMER 1.0.15 ----

INT 0x62 ? 898ABBF8
INT 0x63 ? 89640BF8
INT 0x63 ? 89640BF8
INT 0x63 ? 89640BF8
INT 0x63 ? 89640BF8
INT 0x63 ? 89640BF8
INT 0x63 ? 89640BF8
INT 0x82 ? 898ABBF8
INT 0x83 ? 8991ABF8

Code 8920BB10 ZwEnumerateKey
Code 89205E68 ZwFlushInstructionCache
Code 8928CCCE ZwSaveKey
Code 8928787E ZwSaveKeyEx
Code 89287CCE IofCallDriver
Code 892882BE IofCompleteRequest

---- Kernel code sections - GMER 1.0.15 ----

.text ntoskrnl.exe!IofCallDriver 804E37C5 5 Bytes JMP 89287CD3
.text ntoskrnl.exe!IofCompleteRequest 804E3BF6 5 Bytes JMP 892882C3
PAGE ntoskrnl.exe!ZwEnumerateKey 8056EF30 5 Bytes JMP 8920BB14
PAGE ntoskrnl.exe!ZwFlushInstructionCache 80576A6A 5 Bytes JMP 89205E6C
PAGE ntoskrnl.exe!ZwSaveKey 8064C1EF 5 Bytes JMP 8928CCD2
PAGE ntoskrnl.exe!ZwSaveKeyEx 8064C287 5 Bytes JMP 89287882
? spoh.sys The system cannot find the file specified. !
.text USBPORT.SYS!DllUnload BA55C62C 5 Bytes JMP 896401D8

---- Kernel IAT/EAT - GMER 1.0.15 ----

IAT \WINDOWS\System32\Drivers\SCSIPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 8991A2D8
IAT pci.sys[ntoskrnl.exe!IoDetachDevice] [F7507C4C] spoh.sys
IAT pci.sys[ntoskrnl.exe!IoAttachDeviceToDeviceStack] [F7507CA0] spoh.sys
IAT atapi.sys[HAL.dll!READ_PORT_UCHAR] [F74D7042] spoh.sys
IAT atapi.sys[HAL.dll!READ_PORT_BUFFER_USHORT] [F74D713E] spoh.sys
IAT atapi.sys[HAL.dll!READ_PORT_USHORT] [F74D70C0] spoh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_BUFFER_USHORT] [F74D7800] spoh.sys
IAT atapi.sys[HAL.dll!WRITE_PORT_UCHAR] [F74D76D6] spoh.sys
IAT \SystemRoot\system32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!DbgBreakPoint] 896402D8
IAT \SystemRoot\system32\DRIVERS\i8042prt.sys[HAL.dll!READ_PORT_UCHAR] [F74E6E9C] spoh.sys

---- Devices - GMER 1.0.15 ----

Device \FileSystem\Ntfs \Ntfs 899161F8
Device \FileSystem\Fastfat \FatCdrom 896681F8
Device \Driver\usbuhci \Device\USBPDO-0 8963F1F8
Device \Driver\usbuhci \Device\USBPDO-1 8963F1F8
Device \Driver\dmio \Device\DmControl\DmIoDaemon 899181F8
Device \Driver\dmio \Device\DmControl\DmConfig 899181F8
Device \Driver\dmio \Device\DmControl\DmPnP 899181F8
Device \Driver\dmio \Device\DmControl\DmInfo 899181F8
Device \Driver\usbuhci \Device\USBPDO-2 8963F1F8
Device \Driver\usbuhci \Device\USBPDO-3 8963F1F8
Device \Driver\usbehci \Device\USBPDO-4 896121F8
Device \Driver\Ftdisk \Device\HarddiskVolume1 898AC1F8
Device \Driver\usbstor \Device\00000064 891B7500
Device \Driver\Ftdisk \Device\HarddiskVolume2 898AC1F8
Device \Driver\Cdrom \Device\CdRom0 896411F8
Device \Driver\atapi \Device\Ide\IdePort0 898AB1F8
Device \Driver\atapi \Device\Ide\IdePort1 898AB1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 898AB1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 898AB1F8
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 898AB1F8
Device \Driver\Cdrom \Device\CdRom1 896411F8
Device \Driver\usbstor \Device\00000068 891B7500
Device \Driver\PCI_PNP8060 \Device\0000003d spoh.sys
Device \Driver\PCI_PNP8060 \Device\0000003d spoh.sys
Device \Driver\NetBT \Device\NetBt_Wins_Export 894E21F8
Device \Driver\NetBT \Device\NetbiosSmb 894E21F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{4B6535BD-24A5-4CF9-8AE3-61810A429ACA} 894E21F8
Device \Driver\usbuhci \Device\USBFDO-0 8963F1F8
Device \Driver\usbuhci \Device\USBFDO-1 8963F1F8
Device \FileSystem\MRxSmb \Device\LanmanDatagramReceiver 890CE1F8
Device \Driver\usbuhci \Device\USBFDO-2 8963F1F8
Device \Driver\sptd \Device\621396810 spoh.sys
Device \FileSystem\MRxSmb \Device\LanmanRedirector 890CE1F8
Device \Driver\usbuhci \Device\USBFDO-3 8963F1F8
Device \Driver\usbehci \Device\USBFDO-4 896121F8
Device \Driver\Ftdisk \Device\FtControl 898AC1F8
Device \Driver\viasraid \Device\Scsi\viasraid1 899171F8
Device \Driver\aszspgts \Device\Scsi\aszspgts1 895A71F8
Device \Driver\aszspgts \Device\Scsi\aszspgts1Port3Path0Target0Lun0 895A71F8
Device \FileSystem\Fastfat \Fat 896681F8
Device \FileSystem\Cdfs \Cdfs 896661F8

---- Services - GMER 1.0.15 ----

Service C:\WINDOWS\system32\drivers\gasfkypxllgqqk.sys (*** hidden *** ) [SYSTEM] gasfkyuoyxgroa <-- ROOTKIT !!!

---- Registry - GMER 1.0.15 ----

Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa@start 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa@type 1
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa@group file system
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa@imagepath \systemroot\system32\drivers\gasfkypxllgqqk.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main@aid 10096
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main@sid 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main@cmddelay 14400
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main\connections
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main\delete
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main\injector
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main\injector@* gasfkywsp8y.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\main\tasks
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkypxllgqqk.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules@gasfkycmd.dll \systemroot\system32\gasfkymxoddrjj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules@gasfkylog.dat \systemroot\system32\gasfkyehrlntrp.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules@gasfkywsp.dll \systemroot\system32\gasfkysaejecuj.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules@gasfky.dat \systemroot\system32\gasfkyndwrqkxx.dat
Reg HKLM\SYSTEM\CurrentControlSet\Services\gasfkyuoyxgroa\modules@gasfkywsp8y.dll \systemroot\system32\gasfkybqqpkrod.dll
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC1 0xDD 0x58 0x66 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA3 0x0F 0xB5 0x62 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x89 0x79 0xD2 0x61 ...
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa@start 1
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa@type 1
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa@group file system
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa@imagepath \systemroot\system32\drivers\gasfkypxllgqqk.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main@aid 10096
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main@sid 0
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main@cmddelay 14400
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main\connections (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main\delete (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main\injector (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main\injector@* gasfkywsp8y.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\main\tasks (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules@gasfkyrk.sys \systemroot\system32\drivers\gasfkypxllgqqk.sys
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules@gasfkycmd.dll \systemroot\system32\gasfkymxoddrjj.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules@gasfkylog.dat \systemroot\system32\gasfkyehrlntrp.dat
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules@gasfkywsp.dll \systemroot\system32\gasfkysaejecuj.dll
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules@gasfky.dat \systemroot\system32\gasfkyndwrqkxx.dat
Reg HKLM\SYSTEM\ControlSet002\Services\gasfkyuoyxgroa\modules@gasfkywsp8y.dll \systemroot\system32\gasfkybqqpkrod.dll
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xC1 0xDD 0x58 0x66 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA3 0x0F 0xB5 0x62 ...
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x89 0x79 0xD2 0x61 ...

---- Files - GMER 1.0.15 ----

File C:\Program Files\Adobe\Acrobat 8.0\Acrobat\plug_ins3d\3difr.x3d (size mismatch) 538112/262144 bytes executable
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\FrameWork.log 58756 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\mofcomp.log 14617 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\replog.log 405 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\setup.log 4961 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\wbemcore.log 143 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\wbemess.log 52759 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\wbemess.lo_ 65611 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\wbemprox.log 152 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\wmiadap.log 4839 bytes
File C:\Program Files\Adobe\Adobe InDesign CS3\Adobe_epic\Personalization\Cs_CZ\wmiprov.log 31187 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\AppEvent.Evt 524288 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\default.LOG 1024 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\default.sav 94208 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\SAM 262144 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\SAM.LOG 1024 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\SecEvent.Evt 65536 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\SECURITY 262144 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\SECURITY.LOG 1024 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\software 23855104 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\software.LOG 1024 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\software.sav 659456 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\SysEvent.Evt 524288 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\system 4718592 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\system.LOG 1024 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\system.sav 892928 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\systemprofile 0 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\TempKey.LOG 1024 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\userdiff 262144 bytes
File C:\Program Files\AIM6\services\imApp\ver6_9_15_1\resources\en-US\userdiff.LOG 1024 bytes

---- EOF - GMER 1.0.15 ----


FOR MBAM

Malwarebytes' Anti-Malware 1.41
Database version: 2857
Windows 5.1.2600 Service Pack 2

9/24/2009 7:21:20 PM
mbam-log-2009-09-24 (19-21-20).txt

Scan type: Quick Scan
Objects scanned: 98014
Time elapsed: 15 minute(s), 14 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{28abc5c0-4fcb-11cf-aax5-81cx1c635612} (Generic.Bot.H) -> Delete on reboot.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013 (Trojan.Agent) -> Delete on reboot.

Files Infected:
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\win32.exe (Generic.Bot.H) -> Delete on reboot.
C:\WINDOWS\system32\gasfkybqqpkrod.dll (Rootkit.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\gasfkymxoddrjj.dll (Rootkit.TDSS) -> Delete on reboot.
C:\WINDOWS\system32\gasfkysaejecuj.dll (Rootkit.TDSS) -> Delete on reboot.
C:\WINDOWS\Temp\gasfkyksvmtvsirb.tmp (Rootkit.TDSS) -> Delete on reboot.
C:\Documents and Settings\beta\Local Settings\Temporary Internet Files\Content.IE5\SX6FSL6V\load[1].php (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully.


Still getting these error messages every time I open a program (or it does any kind of process.)
Go to the top of the page
 
+Quote Post

Posts in this topic
- Comcrap   [Resolved] Bad Image Error after virus removal   Sep 24 2009, 08:46 PM
- - oldman960   Hi Comcrap, welcome to the forum. To make cleanin...   Sep 24 2009, 11:49 PM
- - Comcrap   FOR GMER GMER 1.0.15.15087 - http://www.gmer.net ...   Sep 25 2009, 03:47 AM
- - oldman960   Hi Comcrap, QUOTE Still getting these error messa...   Sep 25 2009, 07:42 PM
- - Comcrap   I cannot run combofix. It seems everytime somethi...   Sep 26 2009, 12:06 AM
- - oldman960   Hi Comcrap, Please download exeHelper to your de...   Sep 26 2009, 01:36 AM
- - Comcrap   first exeHelper by Raktor - 09 Build 20090925 Run ...   Sep 26 2009, 01:45 AM
- - oldman960   Hi Comcrap, When you tried to run combofix, were ...   Sep 26 2009, 08:28 AM
- - Comcrap   The same thing that happened with ComboFix happene...   Sep 26 2009, 02:12 PM
- - oldman960   Hi Comcrap, Try running combofix in safe mode. T...   Sep 27 2009, 03:20 AM
- - Comcrap   Does the exact same thing in safe mode. Every pro...   Sep 27 2009, 01:07 PM
- - oldman960   Hi Something is really messing with combofix. Let...   Sep 27 2009, 01:26 PM
- - Comcrap   files attached   Sep 27 2009, 02:08 PM
- - oldman960   Hi Comcrap, Click Ok to any Windows errors you ma...   Sep 27 2009, 02:15 PM
- - Comcrap   Well it deleted two viruses, but didn't do muc...   Sep 28 2009, 02:40 AM
- - oldman960   Hi Compcrap, Let's see if we can kill some of...   Sep 28 2009, 05:59 PM
- - Comcrap   well those irritating error messages have stopped,...   Sep 28 2009, 10:15 PM
- - oldman960   Hi Comcrap, Well neither am I. We look deeper. L...   Sep 28 2009, 10:51 PM
- - Comcrap   here's the log. I have a laptop too. Should ...   Sep 30 2009, 02:09 AM
- - Comcrap   Just checking in.   Oct 2 2009, 03:32 PM
- - oldman960   Hi Comcrap, My apologies, I didn't recieve no...   Oct 2 2009, 05:59 PM
- - oldman960   Hi Comcrap, Are you still with us? Thanks   Oct 5 2009, 06:21 AM
- - Comcrap   Yes, I've just been busy. I scanned my PC with...   Oct 5 2009, 03:12 PM
- - oldman960   Hi Compcrap, Sorry, it seems we tried to use DDs ...   Oct 5 2009, 06:55 PM
- - oldman960   Hi Comcrap, Are you having problems? Thanks   Oct 8 2009, 11:34 PM
- - Comcrap   sorry been a bit busy as of late. you'll see t...   Oct 8 2009, 11:36 PM
- - oldman960   Hi Comcrap, Thanks for the update.   Oct 8 2009, 11:38 PM
- - Comcrap   here you go   Oct 10 2009, 03:46 PM
- - oldman960   Hi Compcrap, Please post the MBAM and Kaspersky l...   Oct 11 2009, 01:17 AM
- - Comcrap   Sorry about that   Oct 13 2009, 10:41 PM
- - oldman960   Hi Compcrap, Logs look good. We can have a look a...   Oct 14 2009, 06:57 AM
- - oldman960   Hi Compcrap, Still here? Thanks   Oct 18 2009, 12:02 AM
- - Comcrap   Still here   Oct 18 2009, 02:04 AM
- - Comcrap   I am concerned. my flashdrives are fine, since I f...   Oct 21 2009, 03:19 AM
- - oldman960   Hi Compcrap, QUOTE The utility may ask you to ins...   Oct 21 2009, 06:46 AM
- - Comcrap   Very well. You might be right about that. I'll...   Oct 21 2009, 10:34 PM
- - oldman960   Hi Compcrap, QUOTE Will the flash drive scanner w...   Oct 21 2009, 11:11 PM
- - oldman960   Hi Compcrap, You still with us?   Oct 25 2009, 03:57 PM
- - Comcrap   still here   Oct 25 2009, 08:48 PM
- - oldman960   Hi Compcrap, How are you making out? Thanks   Oct 25 2009, 08:52 PM
- - Comcrap   ran the disinfector on my drives and they're a...   Oct 29 2009, 02:26 AM
- - oldman960   Hi Compcrap, Have installed an antivirus program?...   Oct 29 2009, 01:05 PM
- - Comcrap   working on it. Sorry, my laptop recently failed, s...   Nov 2 2009, 10:57 PM
- - oldman960   Hi Compcrap, Sorry about your laptop. Thanks for ...   Nov 3 2009, 12:47 AM
- - oldman960   Since this issue appears to be resolved ... this T...   Nov 8 2009, 01:42 AM


Closed TopicStart new topic

 


RSS Time is now: 19th March 2010 - 08:42 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy