Welcome! Register for a free account (or login) > How does it work?
|
|


Jun 26 2009, 06:53 PM
Post
#1
|
|||||
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 193 Joined: 22-August 07 From: U.S.A. Member No.: 72,355 Operating System: Windows XP |
Note: I cannot log on to my email nor WTT using my PC, now. I am using a friend's PC at this moment. HELP!
Hello, Tech Team! ![]() I could not log into my e-mail account today. I got this: I ended up installing IE 8. My Symantec will not enable. I get this: and on Windows Security Center I get this: These screens are not really responding to me. I did a quick scan with mbam after updating and I have an HJT log but when I tried to run Kaspersky online, I got this: Here's my mbam log: Malwarebytes' Anti-Malware 1.38 Database version: 2340 Windows 5.1.2600 Service Pack 3 6/26/2125 7:33:18 PM mbam-log-2125-06-26 (19-33-18).txt Scan type: Quick Scan Objects scanned: 93555 Time elapsed: 15 minute(s), 16 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) and here's my HJT log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:48:03 PM, on 6/26/2125 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\McAfee\SiteAdvisor\McSACore.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Java\jre6\bin\java.exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\system32\mspaint.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.juno.com/s/sp R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=69157 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.8.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1237127157128 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1237127143308 O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cab O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Symantec Management Client (SmcService) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe O23 - Service: Symantec Network Access Control (SNAC) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE O23 - Service: Symantec Endpoint Protection (Symantec AntiVirus) - Symantec Corporation - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe -- End of file - 7827 bytes I appreciate your help, thank you! Kathy
This post has been edited by Kathy: Jun 27 2009, 01:50 PM |
||||
|
|
|||||
![]() |
Jul 1 2009, 10:29 PM
Post
#2
|
|
![]() Forum God / Classroom Admin Assistant Group: Classroom Teacher Posts: 12,327 Joined: 27-December 07 From: Sisters, OR Member No.: 75,503 Operating System: xp |
Kathy,
Yep. That sounds pretty hinky. Let's bring in the big gun. Download ComboFix from one of these locations: Link 1 Link 2 Link 3 * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply. Notes: 1. Do not mouse-click Combofix's window while it is running. That may cause it to stall. 2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions. 3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser. 4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper. 5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. |
|
|
|
Kathy [Resolved] My PC is going wacky. Jun 26 2009, 06:53 PM
Tomk Welcome back Kathy,
You have have to transfer the... Jun 29 2009, 11:39 AM
Kathy Hello, Tomk!!
It's so good to t... Jun 30 2009, 04:43 PM
Tomk Kathy,
The biggest thing I see is that your Syman... Jun 30 2009, 04:53 PM
Kathy Hi, Tomk!
I've lost control. I cannot e... Jun 30 2009, 05:06 PM
Tomk Kathy,
Maybe but I'm not seeing it.
Can you ... Jun 30 2009, 05:16 PM
Kathy Hi, Tomk!
My Windows firewall is already on. ... Jun 30 2009, 05:24 PM
Tomk Kathy,
Not positive, but you apparently did at so... Jun 30 2009, 05:30 PM
Kathy Okey-dokey! I'll get right to it as soon a... Jun 30 2009, 05:34 PM
Tomk Kathy,
Not a problem. That's why we're h... Jun 30 2009, 05:47 PM
Kathy Hello, Tomk!
ZoneAlarm does not show in my uni... Jun 30 2009, 08:09 PM
Tomk Kathy,
Well, all I'm finding is the wonky dri... Jun 30 2009, 09:48 PM
Kathy Hello, Tomk!
Here's the OTM log:
All proc... Jul 1 2009, 05:52 PM
Tomk Kathy,
Well that was a fairly uneventful. Do you... Jul 1 2009, 06:04 PM
Kathy Hello, Tomk!
I am now able to log on to WTT (Y... Jul 1 2009, 06:43 PM
Tomk Kathy,
I've heard of people having trouble wi... Jul 1 2009, 07:15 PM
Kathy Hello, Tomk!
I followed links through that ... Jul 1 2009, 10:19 PM
Kathy Hello, Tomk!
When ComboFix finished, I found ... Jul 1 2009, 11:23 PM
Tomk Kathy,
Not sure. Appears to be a registry issue ... Jul 1 2009, 11:39 PM
Kathy Hello, Tomk!
Here's the new ComboFix log:
... Jul 2 2009, 04:56 AM
Tomk Kathy,
I don't know about Kaspersky.
Let... Jul 2 2009, 07:03 AM
Kathy Hello, Tomk!
My PC won't boot. I'd g... Jul 2 2009, 03:30 PM
Tomk Kathy,
Restart your computer.
When the machine fi... Jul 2 2009, 05:07 PM
Kathy Hello, Tomk!
I couldn't get it to boot. It... Jul 2 2009, 09:09 PM
Tomk Kathy,
Do you have your Windows CD? Jul 2 2009, 09:34 PM
Kathy Hello, Tomk!
No, it came preinstalled from my ... Jul 2 2009, 10:42 PM
Tomk Kathy,
I don't know anything about, and there... Jul 2 2009, 11:01 PM
Kathy Hello, Tonk!
Yes, I could not boot into safe m... Jul 2 2009, 11:04 PM
Tomk Kathy,
OK then. I suggest that you post in the W... Jul 2 2009, 11:10 PM
Kathy Okay, Tomk!
I have to leave right now, but I... Jul 2 2009, 11:18 PM
Tomk RE: [Resolved] My PC is going wacky. Jul 2 2009, 11:27 PM
Kathy Hello, Tomk!
I posted a new topic, I cannot b... Jul 3 2009, 04:38 AM
Tomk RE: [Resolved] My PC is going wacky. Jul 3 2009, 09:35 AM
Tomk Kathy,
Are you out there somewhere? Jul 9 2009, 05:28 PM
Tomk Kathy,
Where are we at with this little beasty? Jul 15 2009, 11:35 AM
Kathy Hello, Tomk!
I hope that you are having a G... Jul 18 2009, 11:39 AM
Tomk Kathy,
I'll wait to hear what your computer g... Jul 19 2009, 08:31 PM
Kathy Okay, Tom! Jul 19 2009, 11:44 PM
Tomk Kathy,
Good Luck. Jul 20 2009, 08:30 AM
Tomk Since this issue appears to be resolved ... this T... Jul 26 2009, 08:21 AM![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
8 | 3streamMusic | 199 | Today, 06:18 PM Last post by: LDTate |
|||
![]() |
16 | jester421 | 334 | Today, 09:18 AM Last post by: CatByte |
|||
![]() |
6 | ROOFIE(MTL) | 103 | Today, 06:42 AM Last post by: CatByte |
|||
![]() |
15 | Amebeo | 260 | Today, 06:38 AM Last post by: CatByte |
|||
|
Time is now: 20th March 2010 - 09:50 PM |