
[Resolved] A really tough problem!
#16
Posted 17 February 2010 - 08:46 PM
Register to Remove
#17
Posted 17 February 2010 - 08:59 PM
Edited by quirmche, 17 February 2010 - 08:59 PM.
#18
Posted 18 February 2010 - 04:07 AM

#19
Posted 18 February 2010 - 06:32 AM
Good enough. One more scan (this one won't take long) then please run DDS and post the fresh log for me, (DDS.txt only, I don't need the Attach.txt this time). Is your computer running better?

- Then doubleclick it to start the tool
- A Notepad file containing the report will open, also found at %systemdrive%\Rooter.txt. Post that here
- Rooter log
- DDS log
- Any outstanding issues or symptoms with your PC
ASAP & UNITE Member - Proud Graduate of the WTT Classroom
The help you receive here is free. If you wish to show your appreciation, then you may [url="https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=RPMcMurphy%40whatthetech%2ecom&lc=US&item_name=RPMcMurphy¤cy_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted""]

#20
Posted 18 February 2010 - 11:06 AM
#21
Posted 18 February 2010 - 03:44 PM
The sounds your PC is making when adding or removing USB devices are normal assuming they are working correctly when inserted. My machine does the same thing. That ESET threat will be removed later when we clean up.

1. Open Notepad.
2. Copy and paste the contents of the below codebox into Notepad.
3. Save the file to your desktop as "fix.reg" (WITH the quotation marks).
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{2318C2B1-4965-11D4-9B18-009027A5CD4F}"=- "{A057A204-BACC-4D26-9990-79A187E2698E}"=- "{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}"=- [-HKEY_CLASSES_ROOT\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}] [-HKEY_CLASSES_ROOT\TYPELIB\{2318C2B1-4965-11D4-9B18-009027A5CD4F}] [-HKEY_CLASSES_ROOT\CLSID\{A057A204-BACC-4D26-9990-79A187E2698E}] [-HKEY_CLASSES_ROOT\TYPELIB\{A057A204-BACC-4D26-9990-79A187E2698E}] [-HKEY_CLASSES_ROOT\CLSID\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}] [-HKEY_CLASSES_ROOT\TYPELIB\{4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C}]4. Double click the fix.reg file on your desktop and confirm the prompts that you wish to make the changes.
5. Reboot.
When you finish that please run DDS again and post the DDS.txt log.
ASAP & UNITE Member - Proud Graduate of the WTT Classroom
The help you receive here is free. If you wish to show your appreciation, then you may [url="https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=RPMcMurphy%40whatthetech%2ecom&lc=US&item_name=RPMcMurphy¤cy_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted""]

#22
Posted 18 February 2010 - 08:07 PM
#23
Posted 19 February 2010 - 05:40 AM
Your logs look clean - Good job! Now we have some important cleanup and housekeeping to do though. These steps will also remove that other threat ESET found and hopefully get your USB issue resolved (if it doesn't, let me know). Are you able to see your iPhone in "My Computer" when you plug it in?

Please follow these steps to remove older version Java components and update.
- Download the latest version of Java Runtime Environment (JRE) 6 and save it to your desktop.
- Scroll down to where it says "Java SE Runtime Environment (JRE) 6 Update 18. The Java SE Runtime Environment (JRE) allows end-users to run Java applications."
- Click the "Download" button to the right.
- Select the Windows platform from the dropdown menu.
- Read the License Agreement and then check the box that says: " I agree to the Java SE Runtime Environment 6 with JavaFX License Agreement". Click on Continue.The page will refresh.
- Click on the link to download Windows Offline Installation and save the file to your desktop.
- Close any programs you may have running - especially your web browser.
- Now go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
- Check (highlight) any item with Java Runtime Environment (JRE or J2SE or Java 6) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove each Java version.
- Reboot your computer once all Java components are removed.
- Then from your desktop double-click on jre-6u18-windows-i586-p.exe to install the newest version.
- After the install is complete, go into the Control Panel (using Classic View) and double-click the Java Icon. (looks like a coffee cup)
- On the General tab, under Temporary Internet Files, click the Settings button.
- Next, click on the Delete Files button
- There are two options in the window to clear the cache - Leave BOTH Checked[list]
Applications and AppletsTrace and Log Files
- Click OK on Delete Temporary Files Window
Note: This deletes ALL the Downloaded Applications and Applets from the CACHE. - Click OK to leave the Temporary Files Window
- Click OK to leave the Java Control Panel.

- Press the Windows key + R on your keyboard or click Start -> Run. Copy and past the following text into the run box that opens:
Combofix /Uninstall


- The application window will appear
- Click the Re-enable button to re-enable your CD Emulation drivers
- Click Yes to continue
- A 'Finished!' message will appear
- Click OK
- DeFogger will now ask to reboot the machine - click OK
Your Emulation drivers are now re-enabled.

- Make sure you have an Internet Connection.
- Download OTC to your desktop and run it
- A list of tool components used in the cleanup of malware will be downloaded.
- If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
- Click Yes to begin the cleanup process and remove these components, including this application.
- You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.
- Manually delete any remaining logs or tools from our fixes

- Restart any anti-malware programs that we disabled while we were cleaning your machine.
- Keep your antivirus application current and updated. Also, hang on to MBAM. Scan with them at least weekly.
- Avoid using P2P programs, cracks and keygens! Refer back to my earlier post for more information.
- Consider running in a limited user account. See this post for more information.
- Please carefully review the information in our Security - Best Practices and Prevention forum located HERE
Edited by RPMcMurphy, 19 February 2010 - 05:45 AM.
ASAP & UNITE Member - Proud Graduate of the WTT Classroom
The help you receive here is free. If you wish to show your appreciation, then you may [url="https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=RPMcMurphy%40whatthetech%2ecom&lc=US&item_name=RPMcMurphy¤cy_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted""]

#24
Posted 19 February 2010 - 10:08 PM
I want to thank you very much for your help! My computer works very well at this point!
Two issues remain:
- iphone is still not recognized
- Computer start up is still very slow and seems to get stuck
#25
Posted 20 February 2010 - 05:22 AM
iTunes and QuickTime were both infected. I cleaned them with ComboFix, but it is possible they were damaged or corrupted in the process. Please uninstall iTunes and QuickTime via Control Panel > Add / Remove programs, then download a fresh copy from HERE and reinstall them.
Let me know if that helps. Also let me know if your iPhone is recoginzed by Windows in "My Computer"
ASAP & UNITE Member - Proud Graduate of the WTT Classroom
The help you receive here is free. If you wish to show your appreciation, then you may [url="https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=RPMcMurphy%40whatthetech%2ecom&lc=US&item_name=RPMcMurphy¤cy_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted""]

Register to Remove
#26
Posted 20 February 2010 - 05:55 AM

#27
Posted 20 February 2010 - 05:56 AM

ASAP & UNITE Member - Proud Graduate of the WTT Classroom
The help you receive here is free. If you wish to show your appreciation, then you may [url="https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=RPMcMurphy%40whatthetech%2ecom&lc=US&item_name=RPMcMurphy¤cy_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted""]

#28
Posted 20 February 2010 - 11:08 AM
#29
Posted 20 February 2010 - 02:36 PM
OK, don't run anymore tools right now.
First, thy this:
- Click Start > Run or Press the Windows Key + R and enter the following into the run box that opens:
services.msc - Find "Apple Mobile Device".
- In the "status" column it will tell you if the process is started or not, and the "startup type" column will tell you if the process will start automatically when windows starts. Set the status to "started" and the startup type to "automatic".
- To do this right click on this process, and then click on "Properties"
- In the "general" tab find the "startup type" drop-down arrow menu and make sure "automatic" is selected. Select it if it is not.
- Also in the general tab check the "service status". If it does not say "started" then click the start button.
- At the bottom of the properties window click "apply"
- Do you have any other USB devices that are working properly?
- Have you tried different USB ports with the iPhone?
- Open Device Manager - Click Start > Run or Press the Windows Key + R and enter the following into the run box that opens:
mmc devmgmt.msc
Are there any question marks or exclamation points next to any of the devices listed?
ASAP & UNITE Member - Proud Graduate of the WTT Classroom
The help you receive here is free. If you wish to show your appreciation, then you may [url="https://www.paypal.com/cgi-bin/webscr?cmd=_donations&business=RPMcMurphy%40whatthetech%2ecom&lc=US&item_name=RPMcMurphy¤cy_code=USD&bn=PP%2dDonationsBF%3abtn_donate_SM%2egif%3aNonHosted""]

#30
Posted 21 February 2010 - 11:41 AM
Do you have any other USB devices that are working properly?
Yes, my mouse is wireless with a usb key, I also have two data usb keys cruzer micro, and PNY and both are recognized in My Computer. However, my iphone and my creative nomad mp3 player are not recognized and they have that strange three beep sound that I'll call the "not recognized sound" when plugged in.
I had the same thing occur a few years back with my Palm Treo 650 not being recognized and it didn't work until I got a new one after my original broke.
Have you tried different USB ports with the iPhone?
Yes
Open Device Manager - Click Start > Run or Press the Windows Key + R and enter the following into the run box that opens:
mmc devmgmt.msc
Are there any question marks or exclamation points next to any of the devices listed?
See pics!
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users