Welcome! Register for a free account (or login) > How does it work?
|
|
![]() ![]() |
Nov 7 2009, 09:49 AM
Post
#31
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
DaonolFix (15.04.09) by jpshortstuff Log created at 20:44 on 07/11/2009 by Saamia Hasan Running from C:\Documents and Settings\Saamia Hasan\Desktop\DaonolFix.exe =====Find Daonol===== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32] "midi"="wdmaud.drv" "midimapper"="midimap.dll" "mixer"="wdmaud.drv" "MSACM.CTRXAUD"="ctrxaud.acm" "msacm.iac2"="C:\WINDOWS\system32\iac25_32.ax" "msacm.imaadpcm"="imaadp32.acm" "msacm.l3acm"="C:\WINDOWS\system32\l3codeca.acm" "msacm.msadpcm"="msadp32.acm" "msacm.msaudio1"="msaud32.acm" "msacm.msg711"="msg711.acm" "msacm.msg723"="msg723.acm" "msacm.msgsm610"="msgsm32.acm" "msacm.siren"="sirenacm.dll" "msacm.sl_anet"="sl_anet.acm" "msacm.trspch"="tssoft32.acm" "MSVideo8"="VfWWDM32.dll" "VIDC.CTRX"="ctrxvid.drv" "vidc.cvid"="iccvid.dll" "VIDC.I420"="msh263.drv" "vidc.iv31"="ir32_32.dll" "vidc.iv32"="ir32_32.dll" "vidc.iv41"="ir41_32.ax" "vidc.iv50"="ir50_32.dll" "VIDC.IYUV"="iyuv_32.dll" "vidc.M261"="msh261.drv" "vidc.M263"="msh263.drv" "vidc.mrle"="msrle32.dll" "vidc.msvc"="msvidc32.dll" "VIDC.UYVY"="msyuv.dll" "VIDC.YUY2"="msyuv.dll" "VIDC.YVU9"="tsbyuv.dll" "VIDC.YVYU"="msyuv.dll" "wave"="wdmaud.drv" "wavemapper"="msacm32.drv" -=Daonol Files=- (none found) -=End Of File=- |
|
|
|
Nov 7 2009, 09:58 AM
Post
#32
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Looks good
I would say you are clean of malware now. Lets clean you up from the tools we used. You could try a defrag to see is that assists with the running of your computer. Any other issues will probably be related to hardware or the dust issue. You probably need a good clean out. Try Canned Air http://www.wisegeek.com/what-is-canned-air.htm If you are very careful using it, it can clean out a great deal of dust and other debris: Please do the following: Follow these steps to uninstall Combofix
![]() NEXT Now to remove the rest of the tools that we have used in fixing your machine:
NOTE: If there are any other tools/logs remaining > right click and delete them. NEXT Download and run Auslogics Disc Defragmenter NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Nov 7 2009, 11:06 AM
Post
#33
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
Ok cool. Thanks. So koobface, kryptic and freddy are all gone now?
|
|
|
|
Nov 7 2009, 11:09 AM
Post
#34
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Yes they are
|
|
|
|
Nov 7 2009, 11:10 AM
Post
#35
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
Thank you so so so much!!! All the best!!!
|
|
|
|
Nov 7 2009, 11:13 AM
Post
#36
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
You are welcome
stay safe ~CB |
|
|
|
Nov 11 2009, 09:06 AM
Post
#37
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
Hi,
I think the comp is still infected with koobface. And I did not click on any weird links and stuff so I'm pretty sure it didn't come back. |
|
|
|
Nov 11 2009, 09:15 AM
Post
#38
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Please run this scan
Download OTS to your Desktop
Please attach the log in your next post. To attach a file, do the following:
|
|
|
|
Nov 11 2009, 09:23 AM
Post
#39
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
|
|
|
|
Nov 11 2009, 10:04 AM
Post
#40
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
There is no indication of anything obvious in that log. What symptoms are you experiencing?
Please run your malwarebytes antimalware program and post the log first do this before running MBAM: Download TFC to your desktop
It's normal after running TFC cleaner that the PC will be slower to boot the first time. NEXT Clear your browser cache Once your browser is open, press ALT on keyboard,click the Tools menu. Click on Delete Browsing History... Select "Temporary Internet Files". Click on "Delete". Once the files have been deleted, you can dismiss the "Internet Options" dialogue by clicking the "Okay" button. |
|
|
|
Nov 11 2009, 10:47 AM
Post
#41
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
My friends on facebook are receiving weird messages from my account so I thought it might be koobface again.
Here is the log: Malwarebytes' Anti-Malware 1.41 Database version: 3147 Windows 5.1.2600 Service Pack 3 11/11/2009 21:44:16 mbam-log-2009-11-11 (21-44-06).txt Scan type: Quick Scan Objects scanned: 102954 Time elapsed: 9 minute(s), 57 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\un_UrduPlugin.exe (Backdoor.Bot) -> No action taken. |
|
|
|
Nov 11 2009, 10:53 AM
Post
#42
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Can you explain what the messages are as there does not appear to be any malware on your machine.
Clean up OTS
|
|
|
|
Nov 11 2009, 11:06 AM
Post
#43
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 23 Joined: 28-October 09 Member No.: 88,573 Operating System: Windows XP |
After my last reboot, an icon by the name of thumbs.db has appeared on my desktop.
All sorts of weird messages are being send through my facebook account. Some of them are: http://twitter.com/CharlenoPappi/status/5613623600 Read this news article and lmk if u know how they are earning so much $$$ working from home.. Seems like this is very possible http://twitter.com/CharlenoPappi/status/5613623600 WOw $5,000 a month? sign me up ! lol http://twitter.com/CharlenoPappi/status/5613623600 Prety motivational news article http://twitter.com/CharlenoPappi/status/5613623600 |
|
|
|
Nov 11 2009, 11:11 AM
Post
#44
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
we need to set your hidden files and folders back to default... please do the following:
I will need to look into the messages a little further. |
|
|
|
Nov 17 2009, 01:29 PM
Post
#45
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,652 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Due to inactivity this topic will be closed.
If you need help please start a new thread. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
0 | MT11 | 9 | Yesterday, 08:04 PM Last post by: MT11 |
|||
![]() |
7 | Helpless Oldie | 159 | Yesterday, 03:09 AM Last post by: CatByte |
|||
![]() |
25 | DocItsBad | 349 | 18th March 2010 - 02:38 PM Last post by: LDTate |
|||
![]() |
7 | mollzzfirstsn | 184 | 18th March 2010 - 10:54 AM Last post by: CatByte |
|||
|
Time is now: 20th March 2010 - 07:51 AM |