Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93124 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Infection: "system-check.com" [Solved]


  • This topic is locked This topic is locked
133 replies to this topic

#121 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 07 January 2012 - 04:22 AM

Dean,

The greater majority of what ESET found was in Qoobox which are just back ups of what Combofix removed, there harmless where there and will deal with that when where done.


This should remove the rest of it

Open OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :processes
    killallprocesses
    
    :OTL
    C:\Documents and Settings\All Users\Documents\19792079
    
    
    :Services
    
    :Reg
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top. <--Not run Scan
  • Let the program run unhindered, reboot when it is done
  • Then post the results of the log it produces.


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

    Advertisements

Register to Remove


#122 Dean N

Dean N

    Authentic Member

  • Authentic Member
  • PipPip
  • 152 posts

Posted 07 January 2012 - 08:34 AM

All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\Dean Nicholson\Desktop\cmd.bat deleted successfully.
C:\Documents and Settings\Dean Nicholson\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 615 bytes

User: All Users

User: Dean Nicholson
->Temp folder emptied: 16384 bytes
->Temporary Internet Files folder emptied: 4717669 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 470 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 32902 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 819334 bytes
->Flash cache emptied: 1346 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 439 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 518644540 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 500.00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 01072012_092838

Files\Folders moved on Reboot...
C:\Documents and Settings\Dean Nicholson\Local Settings\Temporary Internet Files\Content.IE5\JTJIRD5J\ads[3].htm moved successfully.
C:\Documents and Settings\Dean Nicholson\Local Settings\Temporary Internet Files\Content.IE5\CC442NPK\ads[7].htm moved successfully.
C:\Documents and Settings\Dean Nicholson\Local Settings\Temporary Internet Files\Content.IE5\CC442NPK\index[3].htm moved successfully.
C:\Documents and Settings\Dean Nicholson\Local Settings\Temporary Internet Files\Content.IE5\9ZVNU042\ads[4].htm moved successfully.
C:\Documents and Settings\Dean Nicholson\Local Settings\Temporary Internet Files\Content.IE5\9ZVNU042\iframe[1].htm moved successfully.

Registry entries deleted on Reboot...

#123 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 07 January 2012 - 08:41 AM

:thumbup: How is everything ?

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#124 Dean N

Dean N

    Authentic Member

  • Authentic Member
  • PipPip
  • 152 posts

Posted 07 January 2012 - 10:33 AM

Everything seems to be good! :clap:

#125 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 07 January 2012 - 10:44 AM

Thats great Dean :thumbup:

This is what I would suggest , you have Malwarebytes installed, you can upgrade to the Pro version, the cost is minimal, I believe around $20 or so, its not a yearly fee, you get a keycode and the program is yours, the pro version offers a protection module, what this will do is if you ever wander into a bad site by accident, you will get a page not found error and a pop up from Malwarebytes saying they prevented a potential malicious site from opening, I have this on all my computers , but the choice is totally up to you.


Take care my friend :)

  • Click START then RUN
  • Now type Combofix /uninstall in the runbox and click OK. Note the space between the X and the /, it needs to be there.


    Posted Image




Open OTL and click on Clean Up and it will remove programs we used to clean your system along with there backups, any programs that where not removed you can just drag to the trash.

Malwarebytes is the free version and yours to keep and will not be removed




Safe Surfn
Ken

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#126 Dean N

Dean N

    Authentic Member

  • Authentic Member
  • PipPip
  • 152 posts

Posted 07 January 2012 - 12:34 PM

Final request: Start -> All Programs ...the list of programs is there, but they all show as (empty). Can you advise on how to re-populate this list? THANK YOU again for all your help!

#127 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 07 January 2012 - 07:49 PM

Dean, as you use different programs they will populate on that list, you can right click on the start menu and look around for an option to change the amount of programs to add, is this what you mean ?

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#128 Dean N

Dean N

    Authentic Member

  • Authentic Member
  • PipPip
  • 152 posts

Posted 07 January 2012 - 09:27 PM

No, if I click on start, then hover over All Programs, the programs list opens; then, when I hover over most of the actual programs (including Accessories, Games. iTunes, Thinkvantage, and Windows Live) they open further and just say "(empty)". I think some setting just needs reset, but for the life of me I can't find it. Also now, it appears I have no sound. I ran through all the settings, the volume levels are all up, no mute buttons are checked, and when on a site, say, YouTube, the volume level is all the way up, and so is the speaker output on my laptop. No sound at all! Any clue? EDIT: I uploaded a pic of the empty slot because I'm having a hard time describing what's going on. EDIT part deux: Skype audio and video works, but sound is not working on any website.

Attached Thumbnails

  • 2012_01_07_22_28_30_Start_Menu.jpg

Edited by Dean N, 07 January 2012 - 09:51 PM.


#129 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 08 January 2012 - 09:22 AM

Dean,

Right click on My Computer and then click on Properties > Then Device Manager and look under sound, does it look ok or is there a yellow splat or red x ?



Try this unhide utility, dont know if it will help in this case but it cant hurt anything.

http://download.blee...nler/unhide.exe

Once the program has been downloaded, double-click on the Unhide.exe icon on your desktop and allow the program to run. This program will remove the +H, or hidden, attribute from all the files on your hard drives. If there are any files that were purposely hidden by you, you will need to hide them again after this tool is run.

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#130 Dean N

Dean N

    Authentic Member

  • Authentic Member
  • PipPip
  • 152 posts

Posted 08 January 2012 - 10:11 AM

I ran Unhide earlier, right after I noticed the empty spots. I downloaded it again and tried again. Didn't fix it. Everything looks ok under device manager, no yellow splat or red x:

Attached Thumbnails

  • 2012_01_08_10_54_33_Infection___system_check.jpg

Edited by Dean N, 08 January 2012 - 10:49 AM.

    Advertisements

Register to Remove


#131 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 08 January 2012 - 12:03 PM

You may want to post here at our windows forum, they can help you with that as we just do malware removal on this one
http://forums.whatth...p?showforum=119


The malware you had was some of the worst that has come along in quite awhile, it may have done some damage to your system along the way. Doing a System Repair may be a good option, doing it before while you where still infected most likely would have left the malware intact, but doing it now may be a good move, post to the above link, link them to this thread so they can see what we have done and left them guide you through the process.

Good luck,

Ken :)

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#132 Dean N

Dean N

    Authentic Member

  • Authentic Member
  • PipPip
  • 152 posts

Posted 08 January 2012 - 03:29 PM

Thanks Ken, again, thanks VERY MUCH. Looks like we're done here!

:notworthy:



(Link to further repair at Windows Forum)

#133 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 08 January 2012 - 04:43 PM

:thumbup: Take care Ken :)

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#134 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 13 January 2012 - 01:53 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatth...ed_t106388.html
and start a New Topic.

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users