This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Infection...

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi

Try this first

  • Please download this tool from Microsoft.
  • Double click on MGADiag.exe to run it.
  • Click Continue.
  • The program will run. It takes a while to finish the diagnosis, please be patient.
  • Once done, click on Copy.
  • Open Notepad and paste the contents in. Save this file and post it in your next reply.
Diagnostic Report (1.7.0069.0): —————————————– WGA Data–> Validation Status: Genuine Validation Code: 0 Online Validation Code: N/A Cached Validation Code: N/A Windows Product Key: *****-*****-BRVBB-38MQ9-3PMFT Windows Product Key Hash: 2V2VyxlfhiaCt/JkDzYQfiNOHMA= Windows Product ID: 55277-OEM-2111907-00106 Windows Product ID Type: 2 Windows License Type: OEM SLP Windows OS version: 5.1.2600.2.00010300.1.0.hom CSVLK Server: N/A CSVLK PID: N/A ID: {D41FD210-77E9-4602-8F61-8627863184A7}(3) Is Admin: Yes TestCab: 0x0 WGA Version: Registered, 1.7.59.1 Signed By: Microsoft Product Name: N/A Architecture: N/A Build lab: N/A TTS Error: N/A Validation Diagnostic: 025D1FF3-171-1 Resolution Status: N/A WgaER Data–> ThreatID(s): N/A Version: N/A Notifications Data–> Cached Result: N/A File Exists: No Version: N/A, hr = 0x80070002 WgaTray.exe Signed By: N/A, hr = 0x80070002 WgaLogon.dll Signed By: N/A, hr = 0x80070002 OGA Data–> Office Status: 109 N/A OGA Version: N/A, 0x80070002 Signed By: N/A, hr = 0x80070002 Office Diagnostics: FCEE394C-2920-80070002_B4D0AA8B-470-80070002_025D1FF3-171-1 Browser Data–> Proxy settings: N/A User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Win32) Default Browser: C:\Program Files\Internet Explorer\IEXPLORE.exe Download signed ActiveX controls: Prompt Download unsigned ActiveX controls: Disabled Run ActiveX controls and plug-ins: Allowed Initialize and script ActiveX controls not marked as safe: Disabled Allow scripting of Internet Explorer Webbrowser control: Active scripting: Script ActiveX controls marked as safe for scripting: File Scan Data–> Other data–> Office Details: {D41FD210-77E9-4602-8F61-8627863184A7}1.7.0069.05.1.2600.2.00010300.1.0.homx32*****-*****-*****-*****-3PMFT55277-OEM-2111907-001062S-1-5-21-1759380079-317732263-1746573024Compaq Presario 061DQ077A-ABU S5100UK GB340American Megatrends Inc.3.16 20031015******.******+***HP PAVILION579D3C570184A05B08090409GMT Standard Time(GMT+00:00)02CompaqPresario 109
Hi

Vist this site and download Dial-A-Fix

Extract the contents of the zip file and double click the Dial-A-Fix.exe file. Select all options that arent greyed out. Then try installing Sp2 again.

Let me know how that goes.
Hi again

I missed this.

Remember to disconnect from the Internet before carrying out the next instruction, and to save the following script before you do.


Open Notepad - it must be Notepad, not Wordpad.
Copy the text below in the code box by highlighting all the text with your mouse and pressing Ctrl+C

KillAll::
 
File::
C:\WINDOWS\System32\adsldpl.exe
C:\WINDOWS\System32\adsldpp.exe

Driver::
ScheduleShellHWDetection
MSIServerwinmgmt

Go to the Notepad window and click Edit > Paste
Then click File > Save
Name the file "CFScript.txt" (including the quotes)
Save the file to your Desktop

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe



Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):

O15 - Trusted Zone: *.imageservr.com
O15 - Trusted Zone: *.imageservr.com (HKLM)
O23 - Service: Task Scheduler ScheduleShellHWDetection (ScheduleShellHWDetection) - Unknown owner - C:\WINDOWS\System32\adsldpl.exe (file missing)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked exit HijackThis, and reboot.


Please do an online scan with Kaspersky Online Scanner. You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:

      + Extended(If available otherwise Standard)
    • Scan Options:

      + Scan Archives
      + Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button
  • Save the file to your desktop.
  • Copy and paste that information in your next post.

With the exception of Internet Explorer, which is needed for the Kaspersky Scan, keep ALL programs closed until the scan is complete. This includes your anti-virus. Once you have installed the Scanner, and the updated definitions, you can disconnect from the Internet.Re-enable the anti-virus before reconnecting to the Internet.


In your next reply post:
Kaspersky report
ComboFix.txt
New HJT log taken after the above scan has run

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI