Welcome to your place for tech questions! ( Log In or Join today ) Get answers from experts today. (it's 100% free) Virus removal forum
![]() ![]() |
Feb 27 2012, 09:31 PM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 6 Joined: 27-February 12 Member No.: 99,665 Operating System: windows xp |
|
|
|
|
Feb 28 2012, 05:48 PM
Post
#2
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
Hi, and welcome to our malware removal forum!
My name is Richard and I'll be happy to help you with your computer problems. Please be advised that I am currently in training, so my responses will need to be approved by one of our experts before I post them. This is only to ensure you are receiving accurate instructions. It may cause a delay in my replies. Please note the following:
I will return as soon as possible with more instructions. Regards, Richard |
|
|
|
Mar 1 2012, 07:21 AM
Post
#3
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
ComboFix is a very powerful tool. It is not recommended to run ComboFix without expert supervision. If a ComboFix log was produced, please post that. ComboFix logs are located at c:\ComboFix.txt, while older logs are at c:\Qoobox\ComboFix2.txt, c:\Qoobox\ComboFix3.txt, etc. Next Download DDS by sUBs to your desktop. Disable any script blocker/antivirus software temporarily.
Next GMER Rootkit Scanner --------------- Download GMER Rootkit Scanner from here to to your Desktop. It will be a randomly named executable.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries In your next reply, please provide the following:
Regards, Richard |
|
|
|
Mar 1 2012, 11:17 PM
Post
#4
|
|
|
New Member ![]() Group: Authentic Member Posts: 6 Joined: 27-February 12 Member No.: 99,665 Operating System: windows xp |
DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 7.0.5730.11 Run by User at 22:10:04 on 2012-03-03 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.511.63 [GMT -7:00] . . ============== Running Processes =============== . C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Brother\ControlCenter2\brctrcen.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe svchost.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Internet Explorer\iexplore.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://isearch.avg.com/?cid={B5C77A59-F93B-4C12-86D6-D82DF8D44C65}&mid=a4b1663a544647d19591d15b79cf6381-6757d02be948c45dd48c31d239cb241dce73470c&lang=en&ds=ins12&pr=sa&d=2012-02-28 11:38:59&v=10.0.0.7&sap=hp uURLSearchHooks: H - No File BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll {e7df6bff-55a5-4eb7-a673-4ed3e9456d39} uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background uRun: [AdobeUpdater] "c:\program files\common files\adobe\updater5\AdobeUpdater.exe" mRun: [SetDefPrt] c:\program files\brother\brmfl04g\BrStDvPt.exe mRun: [ControlCenter2.0] c:\program files\brother\controlcenter2\brctrcen.exe /autorun mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [niEJngRwieOhYh.exe] c:\documents and settings\all users\application data\niEJngRwieOhYh.exe StartupFolder: c:\docume~1\user\startm~1\programs\startup\automa~1.lnk - c:\troopmaster software\automailer\AutoMailer.exe uPolicies-explorer: NoDesktop = 1 (0x1) mPolicies-system: DisableTaskMgr = 1 (0x1) IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe TCP: DhcpNameServer = 66.182.71.3 66.182.72.3 TCP: Interfaces\{74C7BEB2-9987-49DD-A53D-4D418AF6E349} : DhcpNameServer = 66.182.71.3 66.182.72.3 SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll . ============= SERVICES / DRIVERS =============== . R0 d347bus;d347bus;c:\windows\system32\drivers\d347bus.sys [2007-4-24 155136] R0 d347prt;d347prt;c:\windows\system32\drivers\d347prt.sys [2007-4-24 5248] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2011-2-2 136176] S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2011-2-2 136176] . =============== Created Last 30 ================ . 2012-03-01 02:16:55 -------- d-----w- C:\annicka2 2012-02-29 06:14:17 355328 ----a-w- c:\documents and settings\all users\application data\C5NkBr6W5RPgxh.exe 2012-02-29 05:28:47 448000 ----a-w- c:\documents and settings\all users\application data\niEJngRwieOhYh.exe 2012-02-28 18:38:48 -------- d--h--w- c:\program files\AVG Secure Search 2012-02-28 18:38:42 -------- d-----w- c:\documents and settings\all users\application data\Common Files 2012-02-28 18:35:47 -------- d--h--w- c:\program files\Moozy . ==================== Find3M ==================== . 2012-01-29 12:10:42 237072 ---h--w- c:\windows\system32\MpSigStub.exe . ============= FINISH: 22:10:51.71 =============== |
|
|
|
Mar 1 2012, 11:34 PM
Post
#5
|
|
|
New Member ![]() Group: Authentic Member Posts: 6 Joined: 27-February 12 Member No.: 99,665 Operating System: windows xp |
Dude this is dude, I ran a search for the combo fix log, can't find it on my computer. I posted the DDS 1st report and attached the second. Thanks.
Attached File(s)
|
|
|
|
Mar 2 2012, 10:49 AM
Post
#6
|
|
|
New Member ![]() Group: Authentic Member Posts: 6 Joined: 27-February 12 Member No.: 99,665 Operating System: windows xp |
Heres the Gmer, again I did a file search for the combofix and nothing, I know it did something because it unhid my files, however I don't think I downloaded the program to my computer, I don't know if that matters or not.
Attached File(s)
|
|
|
|
Mar 2 2012, 12:00 PM
Post
#7
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
Thanks for the GMER log.
Please download DeFogger to your Desktop.
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop. Do not re-enable these drivers until otherwise instructed. Regards, Richard |
|
|
|
Mar 2 2012, 06:06 PM
Post
#8
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
Please delete your copy of ComboFix.exe and then download a fresh copy of ComboFix: COMBOFIX --------------- Please download ComboFix from one of the following locations:
Please note: If the Microsoft Windows Recovery Console is already installed, or if you are running Vista, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see a Congratulations!!! message. Click on Yes, to continue scanning for malware. When finished, it shall produce a log for you. Please include the C:\Sheriff.txt in your next reply. WARNING: ComboFix will disconnect your machine from the Internet as soon as it starts.
In your next reply, please provide the following:
Regards, Richard |
|
|
|
Mar 7 2012, 08:05 AM
Post
#9
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
It has been two days or more since my last post. Do you still need help or more time?
Regards, Richard |
|
|
|
Mar 7 2012, 11:50 PM
Post
#10
|
|
|
New Member ![]() Group: Authentic Member Posts: 6 Joined: 27-February 12 Member No.: 99,665 Operating System: windows xp |
Sorry for the delay, busy work week. I had to hire a new employee due to retirement of another.
Attached File(s)
|
|
|
|
Mar 9 2012, 08:17 AM
Post
#11
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
Please do not update the computer at this time, but could you let me know why it has not been updated to Service Pack 3?
I recommend keeping internet use to a minimum while we work together to reduce the risk of further infection which can worsen the state of the computer. Next Please download SystemLook from one of the links below and save it to your Desktop. Download Mirror #1 Download Mirror #2
Note: The log can also be found on your Desktop entitled SystemLook.txt In your next reply, please provide the following:
Regards, Richard |
|
|
|
Mar 9 2012, 08:59 PM
Post
#12
|
|
|
New Member ![]() Group: Authentic Member Posts: 6 Joined: 27-February 12 Member No.: 99,665 Operating System: windows xp |
PC is running, all the programs came back a little slow on the net. Am I suppose to have the service pack 3? I try really hard not to download anything when updates say they need updated, seems I get too much junk with it. Let me know if I need to get the service pack. Thanks
Attached File(s)
|
|
|
|
Mar 10 2012, 09:35 AM
Post
#13
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
Thanks for the information
Please do not update the computer at this time. I will tell you when it is safe to update. It is very important that you install all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and IE up to date will help make you less susceptible to future malware infections. Before we start: The following steps involve modifying the registry. Modifying the registry can be dangerous (and can render your system unbootable) so it's advisable that you make a backup of the registry before proceeding. First, please backup your Registry with ERUNT.
Run Erunt.exe to backup your registry to the folder of your choice. Note: To restore your registry, go to the folder and start ERDNT.exe Next Please download OTM by OldTimer.
CODE :Processes explorer.exe :Reg [-HKEY_CURRENT_USER\Software\ambuhelper1] [-HKEY_USERS\S-1-5-21-1606980848-1708537768-725345543-1003\Software\ambuhelper1] :Files c:\program files\Moozy :Commands [purity] [emptytemp] [start explorer] [Reboot]
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. Next Please post a fresh DDS log so I can review it. In your next reply, please provide the following:
Regards, Richard |
|
|
|
Mar 16 2012, 08:59 AM
Post
#14
|
|
![]() Advanced Member Group: Senior Class Posts: 769 Joined: 23-March 11 Member No.: 96,306 Operating System: Windows 98 |
It has been two days or more since my last post. Do you still need help or more time?
Regards, Richard |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
21 | billed | 3,292 | 20th March 2010 - 06:15 AM Last post by: schrauber |
|||
![]() |
13 | BillyJB | 983 | 10th August 2010 - 11:16 AM Last post by: JonTom |
|||
![]() |
4 | Divinre | 4,273 | 23rd October 2010 - 11:25 AM Last post by: ken545 |
|||
|
Time is now: 22nd May 2013 - 05:31 PM |