Welcome! Register for a free account (or login) > How does it work?
|
|
![]() ![]() |
Jul 15 2009, 08:21 AM
Post
#1
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
I've just run ComboFix, and my log is below. --------------------- ComboFix 09-07-14.08 - Amanda Bell 15/07/2009 10:08.1.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1014.374 [GMT -4:00] Running from: c:\documents and settings\Amanda Bell\Desktop\ComboFix.exe AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\Installer\2e2a7.msi c:\windows\system32\muzapp.exe c:\windows\system32\pac.txt . ((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 ))))))))))))))))))))))))))))))) . 2009-07-03 15:55 . 2009-07-03 15:55 -------- d-----w- c:\program files\Tudou 2009-07-02 17:33 . 2009-07-02 17:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2009-07-02 16:36 . 2009-07-02 16:36 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2009-07-02 16:33 . 2009-04-24 02:55 176235 ----a-w- c:\windows\system32\Primomonnt.dll 2009-07-02 16:33 . 2009-07-02 16:33 -------- d-----w- c:\program files\Nitro PDF 2009-07-02 16:24 . 2009-07-02 16:24 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-07-02 16:23 . 2009-07-02 16:23 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\program files\NOS 2009-06-27 04:28 . 2009-06-27 04:28 -------- d-----w- c:\program files\Convert VOB to AVI 2009-06-26 14:57 . 2009-06-26 14:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-15 13:48 . 2008-08-30 20:53 -------- d-----w- c:\program files\Symantec AntiVirus 2009-07-15 13:48 . 2008-05-11 12:52 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\uTorrent 2009-07-15 13:39 . 2007-10-20 13:26 -------- d-----w- c:\program files\ApexDC++ 2009-07-02 16:28 . 2006-02-21 15:35 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-27 04:14 . 2008-10-06 21:35 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\dvdcss 2009-06-24 21:28 . 2009-02-12 00:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-06-24 21:28 . 2008-06-19 21:36 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 21:28 . 2007-02-15 11:51 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-06-20 02:17 . 2006-09-11 21:06 -------- d-----w- c:\program files\Google 2009-06-09 22:38 . 2007-02-26 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-08 18:48 . 2006-09-03 20:49 108824 ----a-w- c:\documents and settings\Amanda Bell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-05-07 15:32 . 2006-02-21 08:37 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-06 17:22 . 2009-05-06 17:22 390664 ----a-w- c:\documents and settings\Amanda Bell\Application Data\Real\RealPlayer\Update\RealPlayer11.exe 2009-04-29 04:56 . 2006-02-21 08:37 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2006-02-21 08:37 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-04-17 12:26 . 2006-02-21 08:37 1847168 ----a-w- c:\windows\system32\win32k.sys 2009-02-19 19:52 . 2008-09-13 19:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2007-02-12 21:42 . 2007-01-13 05:15 88 --sh--r- c:\windows\system32\F88901A949.sys 2007-03-20 14:11 . 2006-09-11 11:37 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536] "CrawlerNotes"="c:\progra~1\crawler\notes\cnotes.exe" [2007-12-21 1010688] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728] "THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 761948] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-04-28 570664] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-14 88203] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264] "NDSTray.exe"="NDSTray.exe" [BU] "TFncKy"="TFncKy.exe" [BU] "TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728] "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\ _śEUIA1.lnk - c:\program files\Tudou\śEUTudou\TudouVa.exe [2009-5-18 1234328] c:\documents and settings\All Users\Start Menu\Programs\Startup\ RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-21 155648] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-06-24 21:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk] backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Amanda Bell^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Documents and Settings\\Amanda Bell\\Desktop\\DrJava.exe"= "c:\\Program Files\\Java\\jre1.5.0_14\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\java.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= "c:\\Program Files\\Tudou\\·ÉĖŁTudou\\TudouVa.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "17436:TCP"= 17436:TCP:BitComet 17436 TCP "17436:UDP"= 17436:UDP:BitComet 17436 UDP R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/06/2008 5:36 PM 327688] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [11/02/2009 8:06 PM 298776] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/02/2009 10:43 AM 101936] S2 gupdate1c9e7e4c75e015a;Google Update Service (gupdate1c9e7e4c75e015a);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 10:56 PM 133104] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 8:33 PM 116464] . Contents of the 'Scheduled Tasks' folder 2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] 2009-07-15 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] . - - - - ORPHANS REMOVED - - - - BHO-{43BEAFD9-E005-483D-A367-146BA6C8A32E} - c:\program files\Tudou\·ÉĖŁTudou\tudouDetector.dll . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta FF - ProfilePath - c:\documents and settings\Amanda Bell\Application Data\Mozilla\Firefox\Profiles\mono2lv9.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?referrer=ign#max56 FF - prefs.js: network.proxy.type - 2 FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\Google\Google Gears\Firefox\components\gears.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-15 10:13 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-07-15 10:16 ComboFix-quarantined-files.txt 2009-07-15 14:16 Pre-Run: 22,767,648,768 bytes free Post-Run: 22,740,340,736 bytes free WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect 187 --- E O F --- 2009-06-27 16:00 --------------------- Thank you! |
|
|
|
Jul 19 2009, 07:40 AM
Post
#2
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
QUOTE Why we don't ask you to run ComboFix from the onset As stated by the author of ComboFix: ComboFix is a very powerful tool which when improperly used may render your machine to a doorstop. We first need to verify if there's any rootkits present and how they could affect our tools. DDS & GMER are preliminary scans. We use their logs to map our strategy for attack. With these logs we can determine the infections present & decide whether to deploy ComboFix. NOTE:
STEP #1 Download DDS from either of these links LINK 1 LINK 2 and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. STEP #2 ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries |
|
|
|
Jul 19 2009, 10:20 PM
Post
#3
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
Thanks for your response.
I've had no problem with GMER, but could you be more specific about how to disable script blocking? I've tried to find help online, but no luck. Please find GMER.txt attached. This post has been edited by Darkraver: Jul 19 2009, 10:21 PM
Attached File(s)
|
|
|
|
Jul 20 2009, 02:44 AM
Post
#4
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
If you have script blocking it will likely be included with your antivirus, just disable that for the scan - should be OK
|
|
|
|
Jul 21 2009, 11:02 AM
Post
#5
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
Hi there,
Please find DDS.txt and Attach.txt attached to this post. Thank you!
Attached File(s)
|
|
|
|
Jul 21 2009, 11:28 AM
Post
#6
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following:
Copy/paste the text inside the Codebox below into notepad: Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') CODE DirLook:: c:\docume~1\amanda~1\startm~1\programs\startup Folder:: c:\program files\Tudou Registry:: [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "c:\\Program Files\\Tudou\\·ÉĖŁTudou\\TudouVa.exe"=- Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste') Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. |
|
|
|
Jul 22 2009, 06:21 PM
Post
#7
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
Hey,
Here is the log from the ComboFix scan. ----- ComboFix 09-07-14.08 - Amanda Bell 22/07/2009 20:07.2.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.3.1252.2.1033.18.1014.235 [GMT -4:00] Running from: c:\documents and settings\Amanda Bell\Desktop\ComboFix.exe Command switches used :: c:\documents and settings\Amanda Bell\Desktop\CFScript.txt AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated) {FB06448E-52B8-493A-90F3-E43226D3305C} * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\program files\Tudou c:\program files\Tudou\·ÉĖŁTudou\AppData.ini c:\program files\Tudou\·ÉĖŁTudou\clientconf.ini c:\program files\Tudou\·ÉĖŁTudou\skin.ini c:\program files\Tudou\·ÉĖŁTudou\sqlite3.dll c:\program files\Tudou\·ÉĖŁTudou\TudouVa.exe c:\program files\Tudou\·ÉĖŁTudou\tudouva.ini c:\program files\Tudou\·ÉĖŁTudou\update\newver.ini c:\program files\Tudou\·ÉĖŁTudou\update\setup.exe c:\program files\Tudou\·ÉĖŁTudou\update\updatetype.ini c:\program files\Tudou\·ÉĖŁTudou\upnpdll.dll . ((((((((((((((((((((((((( Files Created from 2009-06-23 to 2009-07-23 ))))))))))))))))))))))))))))))) . 2009-07-15 18:56 . 2009-07-18 03:56 -------- d-----w- c:\documents and settings\Amanda Bell\Local Settings\Application Data\Temp 2009-07-02 17:33 . 2009-07-02 17:37 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Adobe 2009-07-02 16:36 . 2009-07-02 16:36 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 2009-07-02 16:33 . 2009-04-24 02:55 176235 ----a-w- c:\windows\system32\Primomonnt.dll 2009-07-02 16:33 . 2009-07-02 16:33 -------- d-----w- c:\program files\Nitro PDF 2009-07-02 16:24 . 2009-07-02 16:24 -------- d-----w- c:\program files\Common Files\Adobe AIR 2009-07-02 16:23 . 2009-07-02 16:23 86016 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\arh.exe 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS 2009-07-02 16:22 . 2009-07-15 13:23 -------- d-----w- c:\program files\NOS 2009-06-27 04:28 . 2009-06-27 04:28 -------- d-----w- c:\program files\Convert VOB to AVI 2009-06-26 14:57 . 2009-06-26 14:57 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Google . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-19 15:23 . 2008-08-30 20:53 -------- d-----w- c:\program files\Symantec AntiVirus 2009-07-18 04:09 . 2006-09-11 21:06 -------- d-----w- c:\program files\Google 2009-07-15 19:10 . 2008-05-11 12:52 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\uTorrent 2009-07-15 13:39 . 2007-10-20 13:26 -------- d-----w- c:\program files\ApexDC++ 2009-07-02 16:28 . 2006-02-21 15:35 -------- d-----w- c:\program files\Common Files\Adobe 2009-06-27 04:14 . 2008-10-06 21:35 -------- d-----w- c:\documents and settings\Amanda Bell\Application Data\dvdcss 2009-06-24 21:28 . 2009-02-12 00:06 11952 ----a-w- c:\windows\system32\avgrsstx.dll 2009-06-24 21:28 . 2008-06-19 21:36 327688 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2009-06-24 21:28 . 2007-02-15 11:51 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2009-06-16 14:36 . 2006-02-21 08:37 119808 ----a-w- c:\windows\system32\t2embed.dll 2009-06-16 14:36 . 2006-02-21 08:37 81920 ----a-w- c:\windows\system32\fontsub.dll 2009-06-09 22:38 . 2007-02-26 00:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help 2009-06-08 18:48 . 2006-09-03 20:49 108824 ----a-w- c:\documents and settings\Amanda Bell\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-06-03 19:09 . 2006-02-21 08:37 1291264 ----a-w- c:\windows\system32\quartz.dll 2009-05-07 15:32 . 2006-02-21 08:37 345600 ----a-w- c:\windows\system32\localspl.dll 2009-05-06 17:22 . 2009-05-06 17:22 390664 ----a-w- c:\documents and settings\Amanda Bell\Application Data\Real\RealPlayer\Update\RealPlayer11.exe 2009-04-29 04:56 . 2006-02-21 08:37 827392 ----a-w- c:\windows\system32\wininet.dll 2009-04-29 04:55 . 2006-02-21 08:37 78336 ----a-w- c:\windows\system32\ieencode.dll 2009-02-19 19:52 . 2008-09-13 19:11 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll 2007-02-12 21:42 . 2007-01-13 05:15 88 --sh--r- c:\windows\system32\F88901A949.sys 2007-03-20 14:11 . 2006-09-11 11:37 3766 --sha-w- c:\windows\system32\KGyGaAvL.sys . (((((((((((((((((((((((((((((((((((((((((((( Look ))))))))))))))))))))))))))))))))))))))))))))))))))))))))) . ---- Directory of c:\docume~1\amanda~1\startm~1\programs\startup ---- 2009-07-03 15:55 . 2009-07-19 15:24 787 ----a-w- c:\docume~1\amanda~1\startm~1\programs\startup\Ęō¶Æ·ÉĖŁĶĮ¶¹.lnk 2006-09-03 20:48 . 2006-02-21 10:35 84 --sha-w- c:\docume~1\amanda~1\startm~1\programs\startup\desktop.ini ((((((((((((((((((((((((((((( SnapShot@2009-07-15_14.13.39 ))))))))))))))))))))))))))))))))))))))))) . + 2007-01-15 03:47 . 2008-07-08 13:02 17272 c:\windows\system32\spmsg.dll - 2007-01-15 03:47 . 2008-07-09 07:38 17272 c:\windows\system32\spmsg.dll + 2009-06-16 14:36 . 2009-06-16 14:36 81920 c:\windows\system32\dllcache\fontsub.dll + 2009-07-18 04:09 . 2009-07-18 04:09 47104 c:\windows\Installer\80d9a1c.msi + 2007-11-12 01:34 . 2009-07-16 07:05 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2007-11-12 01:34 . 2009-06-09 22:41 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe - 2007-11-12 01:34 . 2009-06-09 22:41 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe + 2007-11-12 01:34 . 2009-07-16 07:05 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe - 2007-11-12 01:34 . 2009-06-09 22:41 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe + 2007-11-12 01:34 . 2009-07-16 07:05 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2007-11-12 01:34 . 2009-07-16 07:05 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe + 2007-11-12 01:34 . 2009-07-16 07:05 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe + 2007-11-12 01:34 . 2009-07-16 07:05 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2007-11-12 01:34 . 2009-07-16 07:05 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe + 2009-06-16 14:36 . 2009-06-16 14:36 119808 c:\windows\system32\dllcache\t2embed.dll + 2007-11-12 01:34 . 2009-07-16 07:05 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe - 2007-11-12 01:34 . 2009-06-09 22:41 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe + 2007-11-12 01:34 . 2009-07-16 07:05 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe + 2007-11-12 01:34 . 2009-07-16 07:05 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe - 2007-11-12 01:34 . 2009-06-09 22:41 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe + 2007-11-12 01:34 . 2009-07-16 07:05 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe - 2007-11-12 01:34 . 2009-06-09 22:41 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe + 2007-11-12 01:34 . 2009-07-16 07:05 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe + 2007-11-12 01:34 . 2009-07-16 07:05 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe - 2007-11-12 01:34 . 2009-06-09 22:41 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe + 2008-05-07 05:12 . 2009-06-03 19:09 1291264 c:\windows\system32\dllcache\quartz.dll + 2009-06-30 15:30 . 2009-06-30 15:30 5520384 c:\windows\Installer\3cdd1cd.msp + 2006-09-04 19:19 . 2009-07-07 15:10 24539592 c:\windows\system32\MRT.exe . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2004-12-30 65536] "CrawlerNotes"="c:\progra~1\crawler\notes\cnotes.exe" [2007-12-21 1010688] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-02-28 1828136] "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Tvs"="c:\program files\Toshiba\Tvs\TvsTray.exe" [2005-11-30 73728] "THotkey"="c:\program files\Toshiba\Toshiba Applet\thotkey.exe" [2006-01-05 352256] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-02 761948] "OpwareSE2"="c:\program files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe" [2003-05-08 49152] "ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 249856] "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920] "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072] "TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2008-04-26 185896] "NBKeyScan"="c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-02-18 2221352] "AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-06-24 1948440] "ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896] "vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-09-28 125168] "Google IME Autoupdater"="c:\program files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2008-10-17 308720] "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696] "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-03-13 342312] "NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-04-28 570664] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696] "AGRSMMSG"="AGRSMMSG.exe" - c:\windows\agrsmmsg.exe [2005-10-14 88203] "RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2005-12-09 15691264] "NDSTray.exe"="NDSTray.exe" [BU] "TFncKy"="TFncKy.exe" [BU] "TDispVol"="TDispVol.exe" - c:\windows\system32\TDispVol.exe [2005-03-11 73728] "TPSMain"="TPSMain.exe" - c:\windows\system32\TPSMain.exe [2005-06-01 282624] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360] c:\documents and settings\All Users\Start Menu\Programs\Startup\ RAMASST.lnk - c:\windows\system32\RAMASST.exe [2006-2-21 155648] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter] 2009-06-24 21:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk] backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk] path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk backup=c:\windows\pss\Microsoft Office.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk] backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WinZip Quick Pick.lnk] backup=c:\windows\pss\WinZip Quick Pick.lnkCommon Startup [HKLM\~\startupfolder\C:^Documents and Settings^Amanda Bell^Start Menu^Programs^Startup^Adobe Gamma.lnk] path=c:\documents and settings\Amanda Bell\Start Menu\Programs\Startup\Adobe Gamma.lnk backup=c:\windows\pss\Adobe Gamma.lnkStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "c:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Documents and Settings\\Amanda Bell\\Desktop\\DrJava.exe"= "c:\\Program Files\\Java\\jre1.5.0_14\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_03\\bin\\javaw.exe"= "c:\\Program Files\\Java\\jre1.6.0_05\\bin\\javaw.exe"= "c:\\Program Files\\Real\\RealPlayer\\realplay.exe"= "c:\\Program Files\\uTorrent\\uTorrent.exe"= "c:\\Program Files\\Mozilla Firefox\\firefox.exe"= "c:\\Program Files\\Nero\\Nero8\\Nero Home\\NeroHome.exe"= "c:\\Program Files\\AVG\\AVG8\\avgupd.exe"= "c:\\Program Files\\MSN Messenger\\msnmsgr.exe"= "c:\\Program Files\\MSN Messenger\\livecall.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\java.exe"= "c:\\Program Files\\Maple 12\\jre\\bin\\maple.exe"= "c:\\Program Files\\Bonjour\\mDNSResponder.exe"= "c:\\Program Files\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "17436:TCP"= 17436:TCP:BitComet 17436 TCP "17436:UDP"= 17436:UDP:BitComet 17436 UDP R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [19/06/2008 5:36 PM 327688] R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [11/02/2009 8:06 PM 298776] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/02/2009 10:43 AM 101936] S2 gupdate1c9e7e4c75e015a;Google Update Service (gupdate1c9e7e4c75e015a);c:\program files\Google\Update\GoogleUpdate.exe [07/06/2009 10:56 PM 133104] S3 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [27/09/2006 8:33 PM 116464] --- Other Services/Drivers In Memory --- *NewlyCreated* - LAVCMAJI *Deregistered* - lavcmaji . Contents of the 'Scheduled Tasks' folder 2009-07-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] 2009-07-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2009-06-08 02:56] . . ------- Supplementary Scan ------- . uInternet Connection Wizard,ShellNext = iexplore uInternet Settings,ProxyOverride = local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta FF - ProfilePath - c:\documents and settings\Amanda Bell\Application Data\Mozilla\Firefox\Profiles\mono2lv9.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/ig?referrer=ign#max56 FF - prefs.js: network.proxy.type - 2 FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll FF - component: c:\program files\Google\Google Gears\Firefox\lib\ff30\gears.dll FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll FF - plugin: c:\program files\Mozilla Firefox\plugins\nppopcaploader.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-22 20:14 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-07-23 20:16 ComboFix-quarantined-files.txt 2009-07-23 00:16 ComboFix2.txt 2009-07-15 14:16 Pre-Run: 22,279,618,560 bytes free Post-Run: 22,287,540,224 bytes free 233 --- E O F --- 2009-07-16 07:05 |
|
|
|
Jul 22 2009, 06:30 PM
Post
#8
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
You appear to have two antivirus programs installed AVG and Symantec...More than one antivirus causes system instability, crashes and slowdowns, resulting in less security, not more, uninstall one of them. P2P - I see you have P2P software utorrent installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It likely contributed to your current situation. This page will give you further information. Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares. Please see this topic for more information: Perils of P2P File Sharing. I would strongly recommend that you uninstall this now. You can do so via Control Panel >> Add or Remove Programs. Next Please download Malwarebytes' Anti-Malware
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
Jul 23 2009, 09:28 PM
Post
#9
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
Hi there!
Below is the log from MBAM and the Kapersky Report is attached. The Kapersky didn't come up with anything, which I thought was odd, but I'm running it again just in case. Also, I uninstalled Symantec (though I need it to get wireless at school) and uTorrent. -- Malwarebytes' Anti-Malware 1.39 Database version: 2487 Windows 5.1.2600 Service Pack 3 23/07/2009 10:05:49 AM mbam-log-2009-07-23 (10-05-49).txt Scan type: Quick Scan Objects scanned: 92023 Time elapsed: 6 minute(s), 38 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: c:\WINDOWS\system32\mlcom.ax (Backdoor.Bot) -> Quarantined and deleted successfully. c:\WINDOWS\system32\MSINET.oca (Rogue.Trace) -> Quarantined and deleted successfully.
Attached File(s)
|
|
|
|
Jul 23 2009, 09:46 PM
Post
#10
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
One of the files found by malwarebytes was a backdoor bot, this type of infection has the ability to steal personal information from your computer. As a precaution, from a clean computer change all your passwords, also if you have used this computer for online banking or other financial transactions, notify your financial institutions that your personal information may have been compromised. Please post a fresh DDS log and advise how your computer is running now and if you have any outstanding issues. |
|
|
|
Jul 26 2009, 09:27 PM
Post
#11
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
Hi there,
Thanks for your help! The only outstanding issue is a prompt upon startup from Tudou about a missing file, but I can remove it from the registry myself. Here are the new DDS.txt and Attach.txt.
Attached File(s)
|
|
|
|
Jul 26 2009, 09:49 PM
Post
#12
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
that message will probably disappear when we clean up the tools. If you go to your startup folder - delete any reference to tudou from the start-up folder. C:\Documents and Settings\Amanda Bell\Start Menu\Programs\Startup Now please do the following: Please download JavaRa to your desktop and unzip it to its own folder.
NEXT Follow these steps to uninstall Combofix
![]() NEXT Now to remove the rest of the tools that we have used in fixing your machine:
NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Jul 27 2009, 10:57 AM
Post
#13
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
Thanks for all your help and recommendations.
Everything's looking brighter already. |
|
|
|
Jul 27 2009, 11:13 AM
Post
#14
|
|
|
Authentic Member ![]() ![]() Group: Authentic Member Posts: 67 Joined: 4-October 04 Member No.: 15,931 |
WAIT, DON'T SHUT IT DOWN YET!
Everything was going fine installing those protection programs, until I installed Spyware Guard. I've rebooted a few times, but I can no longer click on anything! The first thing that pops up when I boot up is a notice that DrWatson Postmortem Debugger has encountered an error and needs to shut down. Then I get an hourglass when hovering over the startbar, and cannot click on any icons. Please help! |
|
|
|
Jul 27 2009, 11:15 AM
Post
#15
|
|
![]() Classroom Administrator Group: Classroom Admin Posts: 9,481 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
uninstall spyware guard
do a system restore to yesterday tap into safe mode (tap F8 repeatedly on startup) choose last known good configuration |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
13 | Demos30 | 517 | Today, 09:24 AM Last post by: jpshortstuff |
|||
![]() |
22 | michael1071 | 456 | Today, 06:07 AM Last post by: Tomk |
|||
![]() |
14 | subsub | 160 | Yesterday, 02:07 PM Last post by: CatByte |
|||
![]() |
15 | JohnDJ | 275 | Yesterday, 07:50 AM Last post by: oldman960 |
|||
|
Time is now: 13th March 2010 - 05:30 PM |