

Sep 25 2009, 11:26 AM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
|
|
|
|
![]() |
Sep 26 2009, 11:03 PM
Post
#2
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
you may need to download these programs to another computer and transfer them to the infected PC via USB Please do the following: Please download exeHelper to your desktop.
Note If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file). NEXT Please save this file to your desktop.
|
|
|
|
Sep 30 2009, 04:31 PM
Post
#3
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
I can't do anything really in normal mode so all this was done in safe mode. When I boot up in normal mode many many command prompts open and close. It won't let me open any programs at all.
exeHelper by Raktor - 09 Build 20090925 Run at 15:23:59 on 09/30/09 Now searching... Checking for numerical processes... Checking for bad processes... Checking for bad files... Deleting file C:\WINDOWS\system32\desot.exe Deleting file C:\WINDOWS\ppp3.dat Deleting file C:\WINDOWS\ppp4.dat Deleting file C:\WINDOWS\system32\sysnet.dat Deleting file C:\WINDOWS\system32\sonhelp.htm Checking for bad registry entries... Removing HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{77dc0b63-1535-4ba9-8be8-d59eb676fa02} Resetting filetype association for .exe Resetting filetype association for .com Resetting userinit and shell values... Resetting policies... --Finished-- Running from: C:\Documents and Settings\Administrator\desktop\win32kdiag.exe Log file at : C:\Documents and Settings\Administrator\Desktop\Win32kDiag.txt Removing all found mount points. Attempting to reset file permissions. WARNING: Could not get backup privileges! Searching 'C:\WINDOWS'... Finished! I was able to download (very surprisingly) these programs to my infected computer instead of having to transfer them. |
|
|
|
Sep 30 2009, 05:30 PM
Post
#4
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: Please download DDS from either of these links LINK 1 LINK 2 and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. NEXT ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries |
|
|
|
Oct 2 2009, 08:09 PM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
here are the logs you asked for. the first time i tried to run the scan the comp froze and had to be manually turned off.
Attached File(s)
DDS.txt ( 11.93K )
Number of downloads: 25
Attach.txt ( 19.74K )
Number of downloads: 5
gmer.txt ( 11.59K )
Number of downloads: 27 |
|
|
|
Oct 2 2009, 09:54 PM
Post
#6
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: Download Combofix from either of the links below. You must rename it to combafix.exe before saving it. Save it to your desktop. **Note: In the event you already have Combofix, delete it, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
Link 1 Link 2 -----------------------------------------------------------
----------------------------------------------------------- |
|
|
|
Oct 3 2009, 01:54 PM
Post
#7
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
|
|
|
|
Oct 3 2009, 02:09 PM
Post
#8
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: Please download Malwarebytes' Anti-Malware
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
Oct 3 2009, 08:37 PM
Post
#9
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
Malwarebytes' Anti-Malware 1.41
Database version: 2900 Windows 5.1.2600 Service Pack 2 10/3/2009 1:42:47 PM mbam-log-2009-10-03 (13-42-47).txt Scan type: Quick Scan Objects scanned: 124617 Time elapsed: 15 minute(s), 59 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 1 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{77dc0b63-1535-4ba9-8be8-d59eb676fa02} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{afd4ad01-58c1-47db-a404-fbe00a6c5486} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Windows Police Pro (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Windows Police Pro (Rogue.WindowsPolicePro) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Attached File(s)
|
|
|
|
Oct 3 2009, 08:45 PM
Post
#10
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Delete your temporary Internet files. The rest of the items found by Kaspersky are in Quarantine, which we will be cleaning up shortly.
NEXT Please post a fresh DDS and Attach.txt and describe how the computer is running now and if there are any outstanding issues. |
|
|
|
Oct 4 2009, 12:12 PM
Post
#11
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
I havent been using the computer much but the programs are opening now. I'm not getting any weird popups and the sercurity program seems to be working better. Do you know if there is any particular webpages (i.e. facebook, aim, etc.) that would make the computer more suseptible to getting these viruses or is it just being on the internet in general? Another computer in the house is now having the same problems but my laptop isn't and I was just wondering if that could be a difference in usage or just a coincidence. (I don't use networking sites or instant messaging on my laptop).
Overall this computer seems to be running much better.
Attached File(s)
|
|
|
|
Oct 4 2009, 03:58 PM
Post
#12
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
You are clean, Please do the following: Visit ADOBEand download the latest version of Acrobat Reader (version 9.1) Having the latest updates ensures there are no security vulnerabilities in your system. NEXT Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
NEXT Follow these steps to uninstall Combofix
![]() NEXT Now to remove the rest of the tools that we have used in fixing your machine:
If any logs/tools remain after using this program > right click and delete them. NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Oct 4 2009, 08:30 PM
Post
#13
|
|
|
New Member ![]() Group: Authentic Member Posts: 8 Joined: 25-September 09 Member No.: 88,078 Operating System: Windows XP |
alright thank you very much. im surprised the comp was recoverable.
|
|
|
|
Oct 4 2009, 08:49 PM
Post
#14
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Glad I could help you out.
stay safe ~CB |
|
|
|
Oct 10 2009, 08:41 AM
Post
#15
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,927 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
1 | wfa09 | 22 | Yesterday, 06:44 PM Last post by: jephree |
|||
![]() |
20 | Wakenaam | 361 | Yesterday, 09:54 AM Last post by: Tomk |
|||
![]() |
16 | mesa215 | 281 | Yesterday, 12:05 AM Last post by: Raktor |
|||
![]() |
17 | stjohn | 353 | 19th November 2009 - 06:17 PM Last post by: CatByte |
|||
|
Time is now: 21st November 2009 - 06:29 AM |