This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Freezing & Black Screen - 2 Trojans found - Please help!

60 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

I hope you had a nice weekend!

Thanks, I hope you had a nice weekend too. Happy Valentines by the way :thumbup:


When ComboFix opened it started to scan and this time it went thru the whole scan……. I couldn't believe it.

Funnily enough, I'm not sure why it went thru all the way this time, but I think I may have missed one real time protection which probably is the root of not being able to run the tools provided though this does not happen all the time, but it's worth the try.

Right now, I need you to disable TeaTimer then try running GMER again.
Disabling TeaTimer

  • Run Spybot-S&D in Advanced Mode.
  • If it is not already set to do this Go to the Mode menu select "Advanced Mode"
  • On the left hand side, Click on Tools
  • Then click on the Resident Icon in the List
  • Uncheck "Resident TeaTimer" and click OK any prompts.
  • Restart your computer.


For both the GenericFF-1 & Fakesec-310 – 3 of those 5 boxes are colored in red.

I need the infected directory for this, can you post the spyware terminator log if possible or perhaps a screenshot for me? Can you do that?


Thanks so much again for all your help, I really do appreciate it!!! And, I'm really sorry my computer had been so stubborn.

You're welcome :)

No worries about the trouble, that's what we are here for. It's quite a challenge for me, so if you're willing to go through everything until we get this sorted out, I would certainly appreciate it. :thumbup:
Thanks so much and Happy Valentines Day to you, too! Thanks for reminding me that today was Valentines Day, I almost forgot…… oops! No biggie tho, no bf, but I usually do get something little for my son. Any way, I was going to send you a copy of the Spyware Terminator Log/Report but I couldn't figure out how. It has a button that says "Copy to Clipboard" and I clicked that but I can't find where the clipboard is, I looked everywhere. I also tried highlighting everything in the report to copy and paste it but it won't let me do that, the only options there when I highlight, then right click is to "Select" or "Deselect" the items. That's why I wrote some of the files they were in, in earlier posts and tried best as I could to explain everything. But I know it has to be hard for you not to see what I am talking about. As far as doing a screenshot, I never did that before, but if you would be so kind as to explain how to do that, I would be willing to try! I haven't disabled TeaTimer yet, I am going to do that now and will try Gmer again. Thanks again and will be back in touch soon!
Clipboard is actually in your computer's memory, so when you select copy to clipboard, all you have to do is to press CTRL-V to paste the log and I believe the log should appear.
I went to disable the Tea Timer but as I was going to click on Spybot, my Spyware Terminator scan started. I have it scheduled to run every night. I figured I'd let it run and try what you said about copying it to the clipboard and pressing CTRL-V. I didn't know about the CTRL-V part, I guess thats why nothing happened when I clicked on the "Copy to Clipboard"….lol. Its running the scan now but it seems to have found something else now…… Heuristics.Broken.Executable : g:\Config.Msi\357eee4.rbf , as well as the others from before, the GenericFF-1 & Fakesec-310. Btw, do you happen to know what these viruses are or what they do? Have you ever heard of them? The reason I'm asking is because I had to pay a couple bills today online and when I went to go into my bank account just a little bit ago to check something, it seemed a little weird. It was asking me a different security question then the one's it usually asks. I ended up just closing out of it and not entering anything….. well I entered an answer to see what it would do and it accepted my answer then took me to the next page that asked me for my password. Thats when I closed it out and didn't enter anything else. Do you think they could have gotten my information from when I went on earlier today to pay some bills? If you happen to know or have an idea of any of these, Id really appreciate it but if not thats ok, too. Thanks again!
What I'm trying to do now is to get a better picture of your computer which explains why I asked you to post up the spyware terminator log just to see what is the location of the file. However, I don't see anything that is suspicious based on CF and DDS logs I have. And your freezing and black screen is what puzzles me.

The 357eee4.rbf is a file for windows installer rollback process and basically what it does is save the current configuration during installation to serve as backup in case anything happens. I believe that is likely to be false positive.

You did right on not entering your financial information when it is unnecessary. I think for now, the best thing we could do before I get my colleagues advice is to get ESET scan and a fresh DDS.

ESET Online Scanner
I'd like us to scan your machine with ESET OnlineScan

Note: If you are using Windows Vista/7, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the [external image: Posted Image] button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on [external image: Posted Image] to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the [external image: Posted Image] icon on your desktop.
  • Check [external image: Posted Image]
  • Click the [external image: Posted Image] button.
  • Accept any security warnings from your browser.
  • Check [external image: Posted Image]
  • Make sure that the option "Remove found threats" is Unchecked
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin
    scanning your computer. Please be patient as this can take some time.
  • Look for report in C:\Program Files\ESET\ESET Online Scanner\log.txt. Include the contents of this report in your next reply.
  • Select Uninstall application on close check box and push [external image: Posted Image]
===================================================

Please run DDS again and post it on your next reply.

===================================================

On your next reply please post :
ESET report
Fresh DDS log


Let me know if you have any problems in performing with the steps above or any questions you may have.

Good Day!
Ok, I let the Spyware Terminator Virus protection scan finish and I was able to "Copy to Clipboard" (you were right, I had to open Word and use CTRL-V to paste it there). Only 1 problem, I was going to paste it here but its about 13 pages long. I was just going to copy and send the trojan/virus part but thats about 10 pages itself. Do you happen to have an email address there where I could send it or should I go ahead and post the 13 pages on here? I went into Spybot and disabled Tea Timer (I followed the directions & restarted my computer) then tried the Gmer program again, actually a few times, but the same thing is still happening. I click on the Gmer icon, a small box appears and I click run. The Gmer program opens and starts scanning for a couple seconds. I try to uncheck the boxes in the directions but the scan stops & freezes. Then the "Not Responding" comes up. Then I can't close it. I try the "End Program" and that doesn't close it either. I try to shut my computer down by going into the Start menu and clicking on shut down or restart but it just sits there and doesn't shut down or restart. I have to hold the button down on the cpu itself for it to turn off. I wait a min. and turn it back on. Luckily, lately I haven't had the black screen but I am still having things freeze on me. I also I ran DDS again, and again it froze on me. I did the same as before, I tried closing DDS but it wouldn't close. It wasn't doing anything and the only thing I could do was to minimize it so would minimize down to my lower toolbar so I could see my desktop, I did that, then I clicked on DDS again, it opened and did the scan but again it only gave me 1 report which is posted below. I also did the ESET scan (I followed the directions) it did the scan (it took a few hours to do) but it didn't find anything, therefore it did not give me a report. That's really weird how some programs will scan and others won't (they start and then freeze). I made sure I had the virus protection and that Tea Timer disabled. Here is the DDS report……………. DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 7:15:33.43 on Mon 02/14/2011 Internet Explorer: 7.0.5730.13 BrowserJavaVersion: 1.6.0_23 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.460 [GMT -5:00] ============== Running Processes =============== G:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe G:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe G:\WINDOWS\system32\spoolsv.exe G:\WINDOWS\Explorer.EXE G:\WINDOWS\system32\igfxtray.exe G:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe G:\Program Files\System Protect\SysProtect_Tray.exe G:\Program Files\Lexmark 5400 Series\lxctmon.exe G:\Program Files\Common Files\Java\Java Update\jusched.exe G:\Program Files\Lexmark 5400 Series\ezprint.exe G:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe G:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe G:\WINDOWS\system32\ctfmon.exe G:\Program Files\Messenger\msmsgs.exe G:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe G:\Program Files\Windows Desktop Search\WindowsSearch.exe G:\Program Files\OpenOffice.org 3\program\soffice.exe G:\Program Files\OpenOffice.org 3\program\soffice.bin svchost.exe G:\WINDOWS\system32\inetsrv\inetinfo.exe G:\Program Files\Java\jre6\bin\jqs.exe G:\WINDOWS\system32\lxctcoms.exe G:\Program Files\CDBurnerXP\NMSAccessU.exe G:\Program Files\Macrium\Reflect\ReflectService.exe G:\WINDOWS\System32\snmp.exe G:\Program Files\Spyware Terminator\sp_rsser.exe G:\Program Files\System Protect\SysProtect_srv.exe G:\WINDOWS\system32\svchost.exe -k imgsvc G:\WINDOWS\system32\SearchIndexer.exe G:\WINDOWS\system32\wscntfy.exe G:\Program Files\Outlook Express\msimn.exe G:\Program Files\Mozilla Firefox\firefox.exe G:\PROGRA~1\Crawler\Toolbar\CToolbar.exe G:\WINDOWS\system32\SearchProtocolHost.exe G:\Documents and Settings\Administrator\Desktop\Gmer.exe G:\Documents and Settings\Administrator\Local Settings\temp\1C.tmp\MBR.DAT G:\Documents and Settings\Administrator\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.crawler.com/?tbid=60347 uURLSearchHooks: N/A: {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - g:\progra~1\crawler\toolbar\ctbr.dll BHO: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - g:\program files\lexmark toolbar\toolband.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - g:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: : {1cb20bf0-bbae-40a7-93f4-6435ff3d0411} - g:\progra~1\crawler\toolbar\ctbr.dll BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - g:\progra~1\spybot - search & destroy\SDHelper.dll BHO: RoboForm: {724d43a9-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\roboform.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - g:\progra~1\microsoft office\office14\URLREDIR.DLL BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - g:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - g:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll TB: &Crawler Toolbar: {4b3803ea-5230-4dc3-a7fc-33638f3d3542} - g:\progra~1\crawler\toolbar\ctbr.dll TB: &RoboForm: {724d43a0-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\roboform.dll TB: Lexmark Toolbar: {1017a80c-6f09-4548-a84d-edd6ac9525f0} - g:\program files\lexmark toolbar\toolband.dll uRun: [SpywareTerminatorUpdate] "g:\program files\spyware terminator\SpywareTerminatorUpdate.exe" uRun: [OnlineVault] "g:\program files\online vault\OnlineVault.exe" /startup uRun: [RoboForm] "g:\program files\siber systems\ai roboform\RoboTaskBarIcon.exe" uRun: [ctfmon.exe] g:\windows\system32\ctfmon.exe uRun: [MSMSGS] "g:\program files\messenger\msmsgs.exe" /background mRun: [IgfxTray] g:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] g:\windows\system32\hkcmd.exe mRun: [SpywareTerminator] "g:\program files\spyware terminator\SpywareTerminatorShield.exe" mRun: [SystemProtect] g:\program files\system protect\SysProtect_Tray.exe mRun: [lxctmon.exe] "g:\program files\lexmark 5400 series\lxctmon.exe" mRun: [Lexmark 5400 Series Fax Server] "g:\program files\lexmark 5400 series\fm3032.exe" /s mRun: [LXCTCATS] rundll32 g:\windows\system32\spool\drivers\w32x86\3\LXCTtime.dll,_RunDLLEntry@16 mRun: [SunJavaUpdateSched] "g:\program files\common files\java\java update\jusched.exe" mRun: [EzPrint] "g:\program files\lexmark 5400 series\ezprint.exe" mRun: [Adobe Reader Speed Launcher] "g:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "g:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [QuickTime Task] "g:\program files\quicktime\QTTask.exe" -atboottime StartupFolder: g:\docume~1\admini~1\startm~1\programs\startup\openof~1.lnk - g:\program files\openoffice.org 3\program\quickstart.exe StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\microsoft works calendar reminders.lnk - g:\program files\common files\microsoft shared\works shared\wkcalrem.exe StartupFolder: g:\docume~1\alluse~1\startm~1\programs\startup\windows search.lnk - g:\program files\windows desktop search\WindowsSearch.exe mPolicies-explorer: NoResolveTrack = 1 (0x1) mPolicies-explorer: NoFileAssociate = 0 (0x0) IE: Crawler Search - tbr:iemenu IE: Customize Menu - file://g:\program files\siber systems\ai roboform\RoboFormComCustomizeIEMenu.html IE: E&xport to Microsoft Excel - g:\progra~1\microsoft office\office14\EXCEL.EXE/3000 IE: Fill Forms - file://g:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: RoboForm Toolbar - file://g:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: Save Forms - file://g:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: Se&nd to OneNote - g:\progra~1\microsoft office\office14\ONBttnIE.dll/105 IE: {320AF880-6646-11D3-ABEE-C5DBF3571F46} - g:\program files\siber systems\ai roboform\RoboFormComFillForms.html IE: {320AF880-6646-11D3-ABEE-C5DBF3571F49} - g:\program files\siber systems\ai roboform\RoboFormComSavePass.html IE: {724d43aa-0d85-11d4-9908-00400523e39a} - g:\program files\siber systems\ai roboform\RoboFormComShowToolbar.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FA32182A-EA44-4583-803B-AA827F0D4E06} - g:\progra~1\online~2\ONLINE~1.EXE IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - g:\program files\messenger\msmsgs.exe IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - g:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - g:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - g:\progra~1\spybot - search & destroy\SDHelper.dll DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1275797429265 DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_22-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - g:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - g:\progra~1\crawler\toolbar\ctbr.dll Notify: igfxcui - igfxsrvc.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - g:\windows\system32\WPDShServiceObj.dll SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - g:\program files\windows desktop search\MSNLNamespaceMgr.dll ================= FIREFOX =================== FF - ProfilePath - g:\docume~1\admini~1\applic~1\mozilla\firefox\profiles\avpujchl.default\ FF - component: g:\documents and settings\administrator\application data\mozilla\firefox\profiles\avpujchl.default\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}\components\FFExternalAlert.dll FF - component: g:\documents and settings\administrator\application data\mozilla\firefox\profiles\avpujchl.default\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3}\components\RadioWMPCore.dll FF - component: g:\progra~1\crawler\firefox\components\xcomm.dll FF - component: g:\progra~1\crawler\firefox\components\xshared.dll FF - component: g:\progra~1\crawler\firefox\components\xsupport.dll FF - component: g:\program files\siber systems\ai roboform\firefox\components\rfproxy_31.dll FF - plugin: g:\documents and settings\administrator\local settings\application data\yahoo!\browserplus\2.9.8\plugins\npybrowserplus_2.9.8.dll FF - plugin: g:\progra~1\microsoft office\office14\NPAUTHZ.DLL FF - plugin: g:\progra~1\microsoft office\office14\NPSPWRAP.DLL FF - plugin: g:\program files\divx\divx plus web player\npdivx32.dll FF - plugin: g:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: g:\program files\mozilla firefox\plugins\npCouponPrinter.dll FF - plugin: g:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - g:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - g:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} FF - Ext: Crawler Toolbar: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - g:\progra~1\crawler\toolbar\firefox FF - Ext: Java Quick Starter: [removed] - g:\program files\java\jre6\lib\deploy\jqs\ff FF - Ext: AI Roboform Toolbar for Firefox: {22119944-ED35-4ab1-910B-E619EA06A115} - g:\program files\siber systems\ai roboform\Firefox FF - Ext: Yahoo! Toolbar: {635abd67-4fe9-1b23-4f01-e679fa7484c1} - %profile%\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} FF - Ext: PriceBlink: [removed] - %profile%\extensions\[removed] FF - Ext: United States English Spellchecker: [removed] - %profile%\extensions\[removed] FF - Ext: Free TV Bar c3 Toolbar: {3ee8d0be-f450-4ef2-97b9-ac2222d14db3} - %profile%\extensions\{3ee8d0be-f450-4ef2-97b9-ac2222d14db3} FF - Ext: Amazon Wish List: [removed] - %profile%\extensions\[removed] FF - Ext: Christmas Boom: [removed] - %profile%\extensions\[removed] FF - Ext: Surf Canyon - Search Engine Assistant: {75623d5d-4683-402a-b610-ac4bab767c86} - %profile%\extensions\{75623d5d-4683-402a-b610-ac4bab767c86} —- FIREFOX POLICIES —- FF - user.js: yahoo.homepage.dontask - true FF - user.js: browser.blink_allowed - true FF - user.js: network.prefetch-next - true FF - user.js: nglayout.initialpaint.delay - 250 FF - user.js: layout.spellcheckDefault - 1 FF - user.js: browser.urlbar.autoFill - false FF - user.js: browser.search.openintab - false FF - user.js: browser.tabs.closeButtons - 1 FF - user.js: browser.tabs.opentabfor.middleclick - true FF - user.js: browser.tabs.tabMinWidth - 100 FF - user.js: browser.urlbar.hideGoButton - false ============= SERVICES / DRIVERS =============== R0 pssnap;Paramount Software Snapshot Filter;g:\windows\system32\drivers\pssnap.sys [2010-9-28 15328] R1 sp_rsdrv2;Spyware Terminator Driver 2;g:\windows\system32\drivers\sp_rsdrv2.sys [2010-6-5 142592] R2 ReflectService;Macrium Reflect Image Mounting Service;g:\program files\macrium\reflect\ReflectService.exe [2010-9-28 220128] R2 SP_Service;System Protect Deletion Prevention Service;g:\program files\system protect\SysProtect_srv.exe [2010-6-5 598528] R3 sp_prot;System Protect Filter Driver;g:\windows\system32\drivers\sp_prot.sys [2010-6-5 12288] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;g:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 cpudrv;cpudrv;g:\program files\systemrequirementslab\cpudrv.sys [2009-12-18 11336] S3 DfSdkS;Defragmentation-Service;g:\program files\ashampoo\ashampoo winoptimizer 2010 advanced\DfSdkS.exe [2010-6-20 406016] S3 osppsvc;Office Software Protection Platform;g:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 PSMounter;Macrium Reflect Image Explorer Service;g:\windows\system32\drivers\psmounter.sys [2010-9-28 44512] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;g:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] =============== Created Last 30 ================ 2011-02-14 08:45:01 ——– d—–w- g:\program files\Abbyy FineReader 6.0 Sprint 2011-02-14 08:11:51 ——– d—–w- g:\docume~1\admini~1\applic~1\Windows Search 2011-02-14 06:45:32 ——– d—–w- g:\documents and settings\all users\Microsoft 2011-02-14 06:40:58 ——– d—–w- g:\program files\Microsoft Analysis Services 2011-02-14 06:40:51 ——– d—–w- g:\windows\SHELLNEW 2011-02-14 03:43:30 ——– d—–w- g:\program files\SFS Download Manager 2011-02-13 15:11:27 ——– d—–w- G:\conspirecf3672c 2011-02-13 08:02:04 98816 —-a-w- g:\windows\sed.exe 2011-02-13 08:02:04 89088 —-a-w- g:\windows\MBR.exe 2011-02-13 08:02:04 256512 —-a-w- g:\windows\PEV.exe 2011-02-13 08:02:04 161792 —-a-w- g:\windows\SWREG.exe 2011-02-13 08:01:58 ——– d—–w- G:\conspirecf 2011-02-07 16:47:54 ——– d—–w- g:\docume~1\admini~1\locals~1\applic~1\Apple 2011-02-07 16:47:19 ——– d—–w- g:\docume~1\admini~1\locals~1\applic~1\Apple Computer 2011-01-30 19:57:00 103864 —-a-w- g:\program files\mozilla firefox\plugins\nppdf32.dll 2011-01-30 19:57:00 103864 —-a-w- g:\program files\internet explorer\plugins\nppdf32.dll ==================== Find3M ==================== 2010-11-29 22:38:30 94208 —-a-w- g:\windows\system32\QuickTimeVR.qtx 2010-11-29 22:38:30 69632 —-a-w- g:\windows\system32\QuickTime.qts 2010-11-18 18:12:44 81920 —-a-w- g:\windows\system32\isign32.dll ============= FINISH: 7:15:58.89 =============== Oh, again, please let me know what to do about the 13 page Spyware Terminator Report, if I should go ahead and post it here or if there is somewhere else I should send it to and I will send or post right away. Thanks again!
Yes, some programs do act funnily with certain computers.

Send it through Megaupload.com, upload the file and you will be given a link for download. Copy that and paste it here.

Please uninstall the following Programs using the Add/Remove Programs utility if they exist.
Crawler Toolbar

Detailed steps below :-
On the Windows XP taskbar:
Click Start > Control Panel.
In the Control Panel window, double-click Add or Remove Programs.

===================================================

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

===================================================
Ok, I uploaded the Spyware Terminator Logfile/Report 2-14 to MegaUpload and the link it gave me is – http://www.megaupload.com/?d=OIWMVWWB
I hope I did that right. I never did that before. I am going to uninstall that Crawler Toolbar and ATF Cleaner now. You had said something at the end of your last post, "to keep saved passwords, click "no" at prompt for the ATF Cleaner, does that have anything to do with the Roboform and saved passwords there?

Thanks so much again!
Good news for you, I just went through the log, and apparently those infected files are located in System Restore. This means that you don't have to worry about it because the most important thing now is your system files are all intact and clean. All we have to do now is to clear the system restore points.

Now Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
Yeeeeaaahhhh! I'm glad I did that right. Ok, I uninstalled that Crawler Toolbar, along with it was some web defender or something like that (that was part of it), I never used that Toolbar any way, but its now gone. I also, downloaded the ATF Cleaner and did as instructed. That seems similar to another program I have called CCleaner. I like that program, I use it at the end of the day after I've been on the internet all day and it keeps my computer running fast, usually, unless I get a bug. However, I only use the Cleaner part on it and I don't mess with anything else like the registry cleaner or other tools, so it just cleans up my browser, recycle bin, etc. Ok, I just seen you posted another post. I guess that maybe explains why a lot of those programs didn't find anything. Well, I'm glad its nothing to serious. Ok, I created a new System Restore point, I labeled it today's date and then I noticed after I clicked ok, it said that today's date will be marked on that point………… lol…….. ooops! Oh well, I didn't know what to call it so i just said restore point 2-15. And I did the Cleanmgr as asked. So, should I try and do another Spyware Terminator scan now then? Thank you very very much!!!
CCleaner is a good program that I personally use it myself, just make sure you keep it updated and run it regularly. :) Well the ESET didn't find anything so you should be good to go for now, if you just want to make sure, go ahead and do another round of scan. I believe we are ready to do some cleanup routines after that.
Good Evening Conspire,

I did another Spyware Terminator scan and the Fakesec-310 in all those restore files is gone but that GenericFF-1 is still in one of the restore files and another called vcomp90.dll and then there is that Heuristic.Broken.Executable one that's saying it's part of a virus in a file called ConfigMsi\357eee4.rbf. I was going to paste the report here but its still 4 pages so I uploaded it to megaupload.com again and the link is …….. http://www.megaupload.com/?d=72PLNIT8 … if you would like to take a look. But, we're gettin closer!

Thanks again so much!!!!!!
Let's upload this to file scanner shall we? :)

Go to My Computer-> Tools-> Folder Options-> View tab:
  • Under the Hidden files and folders heading:
  • Select - Show hidden files and folders.
  • Uncheck- Hide protected operating system files (recommended) option.
  • Also, make sure there is no checkmark beside Hide file extensions for known file types.
  • Click OK. (Remember to Hide files and folders once done)

Please go to one of the below sites to scan the following files:
Virus Total (Recommended)
jotti.org
VirScan


click on Browse, and upload the following file for analysis:
G:\WINDOWS\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_f0ccd4aa\vcomp90.dll
G:\Config.Msi\357eee4.rbf


Then click Submit. Allow the file to be scanned, and then please copy and paste the results here for me to see.
If it says already scanned – click "reanalyze now"
Please post the results in your next reply.
Ok, I did as you asked but I could only do the 2 files seperately. Here is the first scan for the first one……….

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
vcomp90.dll
Submission date:
2011-02-17 07:20:39 (UTC)
Current status:
queued (#2) queued (#2) analysing finished
Result:
0/ 43 (0.0%)

VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.02.14.02 2011.02.14 -
AntiVir 7.11.3.121 2011.02.16 -
Antiy-AVL 2.0.3.7 2011.02.17 -
Avast 4.8.1351.0 2011.02.16 -
Avast5 5.0.677.0 2011.02.16 -
AVG 10.0.0.1190 2011.02.17 -
BitDefender 7.2 2011.02.17 -
CAT-QuickHeal 11.00 2011.02.17 -
ClamAV 0.96.4.0 2011.02.17 -
Commtouch 5.2.11.5 2011.02.17 -
Comodo 7715 2011.02.17 -
DrWeb 5.0.2.03300 2011.02.17 -
Emsisoft 5.1.0.2 2011.02.17 -
eSafe 7.0.17.0 2011.02.16 -
eTrust-Vet 36.1.8164 2011.02.17 -
F-Prot 4.6.2.117 2011.02.16 -
F-Secure 9.0.16160.0 2011.02.17 -
Fortinet 4.2.254.0 2011.02.17 -
GData 21 2011.02.17 -
Ikarus T3.1.1.97.0 2011.02.17 -
Jiangmin 13.0.900 2011.02.17 -
K7AntiVirus 9.85.3869 2011.02.16 -
Kaspersky 7.0.0.125 2011.02.17 -
McAfee 5.400.0.1158 2011.02.17 -
McAfee-GW-Edition 2010.1C 2011.02.17 -
Microsoft 1.6502 2011.02.17 -
NOD32 5881 2011.02.16 -
Norman 6.07.03 2011.02.16 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.02.16 -
PCTools 7.0.3.5 2011.02.17 -
Prevx 3.0 2011.02.17 -
Rising 23.45.02.06 2011.02.16 -
Sophos 4.61.0 2011.02.17 -
SUPERAntiSpyware 4.40.0.1006 2011.02.17 -
Symantec 20101.3.0.103 2011.02.17 -
TheHacker 6.7.0.1.132 2011.02.17 -
TrendMicro 9.200.0.1012 2011.02.17 -
TrendMicro-HouseCall 9.200.0.1012 2011.02.15 -
VBA32 3.12.14.3 2011.02.16 -
VIPRE 8448 2011.02.17 -
ViRobot 2011.2.17.4314 2011.02.17 -
VirusBuster 13.6.204.0 2011.02.16 -
Additional information
Show all
MD5 : 401f8901dbaac9b3033e42a0698a0676
SHA1 : 8769d3c0980c5efe8b05f27ddb62b4a5f6fb6b33
SHA256: fa473512b462d89b1829f3222362ac02757538f252967d16fda485ffa92ccf74
ssdeep: 768:8PSXLA354st0Ha5FvLgUz/g0f47TsvyVkpSL2jmPGEKy/zYaz4Z/ja:8q7Aca5F1vOlLSaX
/CZ/2
File size : 51008 bytes
First seen: 2009-07-29 04:08:35
Last seen : 2011-02-17 07:20:39
TrID:
Win32 Executable MS Visual C++ (generic) (65.2%)
Win32 Executable Generic (14.7%)
Win32 Dynamic Link Library (generic) (13.1%)
Generic Win/DOS Executable (3.4%)
DOS Executable Generic (3.4%)
sigcheck:
publisher….: Microsoft Corporation
copyright….: © Microsoft Corporation. All rights reserved.
product……: Microsoft_ Visual Studio_ 2008
description..: Microsoft_ C/C__ OpenMP Runtime
original name: VCOMP90.DLL
internal name: VCOMP90.DLL
file version.: 9.00.30729.4148 built by: QFE
comments…..: n/a
signers……: Microsoft Corporation
Microsoft Code Signing PCA
Microsoft Root Authority
signing date.: 8:05 AM 7/12/2009
verified…..: -
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x5A72
timedatestamp….: 0x4A596D77 (Sun Jul 12 04:58:31 2009)
machinetype……: 0x14c (I386)

[[ 4 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.text, 0x1000, 0x918B, 0x9200, 6.65, cb1d8d4beca8a90eca8132d8bf8c7ae3
.data, 0xB000, 0x3C0, 0x200, 0.41, 6181d1743d0374117637b2386415311f
.rsrc, 0xC000, 0xFB8, 0x1000, 3.31, b80cbfbf8964f3abdb9c59e116a5ac37
.reloc, 0xD000, 0x65C, 0x800, 4.52, bcb902f3f9439d3bed89c05996bcca85

[[ 2 import(s) ]]
KERNEL32.dll: TlsGetValue, FormatMessageW, OutputDebugStringW, GetConsoleWindow, GetConsoleScreenBufferInfo, WriteConsoleW, WideCharToMultiByte, WriteFile, GetLastError, LocalFree, GetStdHandle, ExitProcess, HeapFree, GetProcessHeap, TlsSetValue, Sleep, UnhandledExceptionFilter, GetTickCount, HeapAlloc, CreateEventW, CloseHandle, WaitForSingleObject, SetEvent, InitializeCriticalSectionAndSpinCount, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, CreateSemaphoreW, ReleaseSemaphore, GetCurrentThreadId, TryEnterCriticalSection, QueryPerformanceCounter, TlsAlloc, TlsFree, GetSystemInfo, QueryPerformanceFrequency, GetSystemTimeAdjustment, GetEnvironmentVariableW, lstrlenW, lstrcmpiW, GetStringTypeExW, SleepEx, SwitchToThread, QueueUserAPC, CreateThread, QueueUserWorkItem, GetFileAttributesW, GetUserDefaultUILanguage, FindFirstFileW, FindNextFileW, FindClose, LoadLibraryExW, GetModuleFileNameW, GetModuleHandleW, FindResourceW, LoadResource, IsDebuggerPresent, SetUnhandledExceptionFilter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, RtlUnwind
USER32.dll: MessageBoxW

[[ 112 export(s) ]]
_vcomp_atomic_add_i1, _vcomp_atomic_add_i2, _vcomp_atomic_add_i4, _vcomp_atomic_add_i8, _vcomp_atomic_add_r4, _vcomp_atomic_add_r8, _vcomp_atomic_and_i1, _vcomp_atomic_and_i2, _vcomp_atomic_and_i4, _vcomp_atomic_and_i8, _vcomp_atomic_div_i1, _vcomp_atomic_div_i2, _vcomp_atomic_div_i4, _vcomp_atomic_div_i8, _vcomp_atomic_div_r4, _vcomp_atomic_div_r8, _vcomp_atomic_div_ui1, _vcomp_atomic_div_ui2, _vcomp_atomic_div_ui4, _vcomp_atomic_div_ui8, _vcomp_atomic_mul_i1, _vcomp_atomic_mul_i2, _vcomp_atomic_mul_i4, _vcomp_atomic_mul_i8, _vcomp_atomic_mul_r4, _vcomp_atomic_mul_r8, _vcomp_atomic_or_i1, _vcomp_atomic_or_i2, _vcomp_atomic_or_i4, _vcomp_atomic_or_i8, _vcomp_atomic_shl_i1, _vcomp_atomic_shl_i2, _vcomp_atomic_shl_i4, _vcomp_atomic_shl_i8, _vcomp_atomic_shr_i1, _vcomp_atomic_shr_i2, _vcomp_atomic_shr_i4, _vcomp_atomic_shr_i8, _vcomp_atomic_shr_ui1, _vcomp_atomic_shr_ui2, _vcomp_atomic_shr_ui4, _vcomp_atomic_shr_ui8, _vcomp_atomic_sub_i1, _vcomp_atomic_sub_i2, _vcomp_atomic_sub_i4, _vcomp_atomic_sub_i8, _vcomp_atomic_sub_r4, _vcomp_atomic_sub_r8, _vcomp_atomic_xor_i1, _vcomp_atomic_xor_i2, _vcomp_atomic_xor_i4, _vcomp_atomic_xor_i8, _vcomp_barrier, _vcomp_copyprivate_broadcast, _vcomp_copyprivate_receive, _vcomp_enter_critsect, _vcomp_flush, _vcomp_for_dynamic_init, _vcomp_for_dynamic_init_i8, _vcomp_for_dynamic_next, _vcomp_for_dynamic_next_i8, _vcomp_for_static_end, _vcomp_for_static_init, _vcomp_for_static_init_i8, _vcomp_for_static_simple_init, _vcomp_for_static_simple_init_i8, _vcomp_fork, _vcomp_get_thread_num, _vcomp_leave_critsect, _vcomp_master_barrier, _vcomp_master_begin, _vcomp_master_end, _vcomp_ordered_begin, _vcomp_ordered_end, _vcomp_ordered_loop_end, _vcomp_reduction_i1, _vcomp_reduction_i2, _vcomp_reduction_i4, _vcomp_reduction_i8, _vcomp_reduction_r4, _vcomp_reduction_r8, _vcomp_reduction_u1, _vcomp_reduction_u2, _vcomp_reduction_u4, _vcomp_reduction_u8, _vcomp_sections_init, _vcomp_sections_next, _vcomp_set_num_threads, _vcomp_single_begin, _vcomp_single_end, omp_destroy_lock, omp_destroy_nest_lock, omp_get_dynamic, omp_get_max_threads, omp_get_nested, omp_get_num_procs, omp_get_num_threads, omp_get_thread_num, omp_get_wtick, omp_get_wtime, omp_in_parallel, omp_init_lock, omp_init_nest_lock, omp_set_dynamic, omp_set_lock, omp_set_nest_lock, omp_set_nested, omp_set_num_threads, omp_test_lock, omp_test_nest_lock, omp_unset_lock, omp_unset_nest_lock
ExifTool:
file metadata
CharacterSet: Unicode
CodeSize: 37376
CompanyName: Microsoft Corporation
EntryPoint: 0x5a72
FileDescription: Microsoft C/C++ OpenMP Runtime
FileFlagsMask: 0x003f
FileOS: Windows NT 32-bit
FileSize: 50 kB
FileSubtype: 0
FileType: Win32 DLL
FileVersion: 9.00.30729.4148 built by: QFE
FileVersionNumber: 9.0.30729.4148
ImageVersion: 9.0
InitializedDataSize: 7168
InternalName: VCOMP90.DLL
LanguageCode: English (U.S.)
LegalCopyright: Microsoft Corporation. All rights reserved.
LinkerVersion: 9.0
MIMEType: application/octet-stream
MachineType: Intel 386 or later, and compatibles
OSVersion: 5.0
ObjectFileType: Dynamic link library
OriginalFilename: VCOMP90.DLL
PEType: PE32
ProductName: Microsoft Visual Studio 2008
ProductVersion: 9.00.30729.4148
ProductVersionNumber: 9.0.30729.4148
Subsystem: Windows GUI
SubsystemVersion: 5.0
TimeStamp: 2009:07:12 06:58:31+02:00
UninitializedDataSize: 0

VT Community

0

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

VirusTotal Team
Add your comment… Remember that when you write comments as an anonymous user they receive the lowest possible reputation. So if you have not signed in yet don't forget to do so. How to markup your comments?
You can add basic styles to your comments using the following accepted bbcode tags:

text – bold
text – italics
text – underline
text – strikethrough
text
– preformatted text

You can also address comments to particular users using the "@" twitter-like mode. By prepending a "#" symbol to a word you can add custom tags to your comment, tags that can then be searched for.

*** And here is the second one………

0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware.
File name:
357eee4.rbf
Submission date:
2011-02-17 07:28:40 (UTC)
Current status:
queued queued analysing finished
Result:
0/ 43 (0.0%)

VT Community

not reviewed
Safety score: -
Compact
Print results
Antivirus Version Last Update Result
AhnLab-V3 2011.02.14.02 2011.02.14 -
AntiVir 7.11.3.118 2011.02.16 -
Antiy-AVL 2.0.3.7 2011.02.16 -
Avast 4.8.1351.0 2011.02.16 -
Avast5 5.0.677.0 2011.02.16 -
AVG 10.0.0.1190 2011.02.16 -
BitDefender 7.2 2011.02.16 -
CAT-QuickHeal 11.00 2011.02.16 -
ClamAV 0.96.4.0 2011.02.16 -
Commtouch 5.2.11.5 2011.02.16 -
Comodo 7711 2011.02.16 -
DrWeb 5.0.2.03300 2011.02.16 -
Emsisoft 5.1.0.2 2011.02.16 -
eSafe 7.0.17.0 2011.02.16 -
eTrust-Vet 36.1.8162 2011.02.16 -
F-Prot 4.6.2.117 2011.02.15 -
F-Secure 9.0.16160.0 2011.02.16 -
Fortinet 4.2.254.0 2011.02.16 -
GData 21 2011.02.16 -
Ikarus T3.1.1.97.0 2011.02.16 -
Jiangmin 13.0.900 2011.02.16 -
K7AntiVirus 9.85.3869 2011.02.16 -
Kaspersky 7.0.0.125 2011.02.16 -
McAfee 5.400.0.1158 2011.02.16 -
McAfee-GW-Edition 2010.1C 2011.02.16 -
Microsoft 1.6502 2011.02.16 -
NOD32 5880 2011.02.16 -
Norman 6.07.03 2011.02.15 -
nProtect 2011-02-10.01 2011.02.15 -
Panda 10.0.3.5 2011.02.16 -
PCTools 7.0.3.5 2011.02.16 -
Prevx 3.0 2011.02.17 -
Rising 23.45.02.06 2011.02.16 -
Sophos 4.61.0 2011.02.16 -
SUPERAntiSpyware 4.40.0.1006 2011.02.16 -
Symantec 20101.3.0.103 2011.02.16 -
TheHacker 6.7.0.1.131 2011.02.15 -
TrendMicro 9.200.0.1012 2011.02.16 -
TrendMicro-HouseCall 9.200.0.1012 2011.02.15 -
VBA32 3.12.14.3 2011.02.16 -
VIPRE 8440 2011.02.16 -
ViRobot 2011.2.16.4313 2011.02.16 -
VirusBuster 13.6.203.0 2011.02.16 -
Additional information
Show all
MD5 : e1f4527f67caac50cc2eacd5d96d7e1a
SHA1 : b7b03de6dc2608211e4d3e4cdcd851f2d1bbc8d2
SHA256: be39c846263d6d4d758c5c946976ca4e0cc0f8a61168fec1d8ad17e86237cb8b
ssdeep: 384:BUJ8888888888888888888888888888888888888888888888888888888888864:BYZnr8
cNeKqUpt2elklGeUWFgGYE
File size : 27886 bytes
First seen: 2007-07-24 15:46:21
Last seen : 2011-02-17 07:28:40
TrID:
Microsoft compiled help format 2.0 (34.5%)
Generic Win/DOS Executable (32.1%)
DOS Executable Generic (32.1%)
VXD Driver (0.4%)
Sybase iAnywhere database files (0.3%)
sigcheck:
publisher….: n/a
copyright….:
product……: n/a
description..: Compiled Microsoft Help 2.0 Title
original name: n/a
internal name: n/a
file version.: 2.5.0.0
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned
PEInfo: PE structure information

[[ basic data ]]
entrypointaddress: 0x0
timedatestamp….: 0x0 (Thu Jan 01 00:00:00 1970)
machinetype……: 0x14c (I386)

[[ 2 section(s) ]]
name, viradd, virsiz, rawdsiz, ntropy, md5
.rsrc, 0x188, 0x37C, 0x400, 3.07, 9037c2bcfe1d8c4b5f4a65fb5a2b0120
.its, 0x564, 0x18, 0x200, 2.79, 825d4724aee720376657a4ea8931325c

VT Community

0

This file has never been reviewed by any VT Community member. Be the first one to comment on it!

VirusTotal Team

I'm sure glad you know what all that stuff is in these reports cuz I don't have a clue. So, do you think it would be alright for me to go into my bank account to pay a couple bills? Do you think those viruses remaining are anything to worry about to do that?

Thanks so much again for all your help!!!!!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI