I did select the Analyze This button but my IE didn't open I just got an error message that IE stopped working. I am using Firefox I don't know if that matters at all. Also I have Malwarebytes installed but I barely even open it. Anyway my Computer gets an error message saying that it can't search for updates and I also know that there may be other things wrong with this computer but this is the only one I can identify for now. I would appreciate any help with this and if I posted in the wrong section or just posted things wrong I am sorry.
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:55:47 AM, on 7/24/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18904) Boot mode: Normal
Welcome. Thank you for using Dell Community Forums.
I am reviewing your log. It appears that you have quite a bit of malware in there. It is surprising that McAfee did not see it. When you say that you barely open Malwarebytes is that because it will not run, or because you do not choose to use it?
While I arrange how to deal with this, you can help me by addressing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.
* During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.
* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
We need to see some additional information about what is happening in your machine.
Download DDS by sUBs from one of the following links. Save it to your desktop.
A small box will open, with an explanation about the tool.
Click Yes at the prompt for Optional Scan.
When done, DDS will open two (2) logs
1. DDS.txt 2. Attach.txt
Save both reports to your desktop.
Copy/paste both logs to your reply on the forum. Do not attach them.
Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.
Download Security Check by screen317 and save it to your Desktop: here or here
Run Security Check
Follow the onscreen instructions inside of the command window.
A Notepad document should open automatically called checkup.txt; close Notepad. We will need this log along with the two requested above, so remember where you've saved it!
If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
No Reply within 3 days will result in this topic being closed, and I will remove it from my subscriptions. If you require more time, please let me know.
Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.
Following that, please open Malwarebytes' Anti-Malware. Go to the Update Tab and update MBAM.
If an update is found, the program will automatically update itself.
Press the OK button to close that box and continue.
If you encounter any problems while downloading the updates,
manually download them fromhere and just double-click on mbam-rules.exe to install. Alternatively, you can update through MBAM's interface from a clean computer, copy the definitions (rules.ref) located in C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.
On the Scanner tab:
Make sure the "Perform Quick Scan" option is selected.
Then click on the Scan button.
If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
The scan will begin and "Scan in progress" will show at the top.
It may take some time to complete so please be patient.
When the scan is finished, a message box will say "The scan completed successfully.
Click 'Show Results' to display all objects found".
Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
Click on the Show Results button to see a list of any malware that was found.
Make sure that everything is checked, and click Remove Selected.
When removal is completed, a log report will open in Notepad.
The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the contents of that report along with any other requested logs into your next reply and exit MBAM.
Note:-- If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.
-- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes.
**If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from HERE
If your system has not rebooted after running MBAM, please do so.
Please run a scan with HijackThis and save your new log.
Go back to the HijackThis Main window and select "Open the misc tool section"
Click on the Config button.
Click the Misc. Tools button and select "Open uninstall manager". It will show you a list of your installed programs.
Click "Save list" and save it to your desktop. Copy and paste that list as a reply to this thread along with your log from MBAM and the output from the HijackThis scan.
Ok well I guess the closest thing to a cracked program would be my GBA emulator even if it is not, I deleted it. Malwarebytes has opened whenever I wanted it to but it is just that I never paid that much attention to it so I didn't check the things it did. About the System Restore I tried to go to System and to enable, but I just can't find the option to enable anything similar to that so as far as I know it is still off. This computer is mine though I lend it to other people what I do with it is up to me and I have not posted anything on other forums regarding help on any matter.
DDS (Ver_10-03-17.01) - NTFSx86 Run by IanP at 13:49:49.46 on Sat 07/24/2010 Internet Explorer: 8.0.6001.18904 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3545.2003 [GMT -4:00]
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_10-03-17.01)
Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 5/9/2009 2:23:49 AM System Uptime: 7/24/2010 10:48:27 AM (3 hours ago)
Motherboard: Dell Inc. | | 0G848F Processor: Pentium(R) Dual-Core CPU T4200 @ 2.00GHz | Microprocessor | 2000/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 283 GiB total, 161.889 GiB free. E: is FIXED (NTFS) - 15 GiB total, 7.351 GiB free. F: is CDROM ()
µTorrent Acrobat.com Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9 Antimalware Doctor Antivirus 2010 Apple Mobile Device Support Apple Software Update Banctec Service Agreement Bonjour BrightShadow Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibility Pack for the 2007 Office system Defense Center Dell-eBay Dell DataSafe Local Backup Dell DataSafe Local Backup - Support Software Dell DataSafe Online Dell Dock Dell Edoc Viewer Dell Getting Started Guide Dell Remote Access Dell Support Center (Support Software) Dell Touchpad Dell Wireless WLAN Card Utility Dungeons & Dragons Online - Eberron Unlimited™ EPSON NX100 Series Printer Uninstall GoToAssist 8.0.0.514 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® Matrix Storage Manager ITRWoW 3.2.2a iTunes Java(TM) 6 Update 11 Junk Mail filter update Malwarebytes' Anti-Malware McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 3.5 SP1 Microsoft Application Error Reporting Microsoft Choice Guard Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works Mozilla Firefox (3.6.6) MSVCRT OGA Notifier 2.0.0048.0 Pando Media Booster Playdom Toolbar Power Search Tool PowerDVD DX QuickSet QuickTime Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB978380) Security Update for Microsoft Office Excel 2007 (KB978382) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Skype web features Skype™ 4.1 SlingPlayer Street-Ads Browser Enhancer Turbine Download Manager Update for 2007 Microsoft Office System (KB967642) Update for 2007 Microsoft Office System (KB981715) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office InfoPath 2007 (KB976416) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 (KB974561) Update for Microsoft Office Word 2007 Help (KB963665) Verizon Broadband Toolbar (IE only) Verizon Servicepoint 3.5.10 Vz In Home Agent Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Family Safety Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer Wizard101 Yahoo! Messenger Yahoo! Search Protection Yahoo! Software Update Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
7/24/2010 9:30:57 AM, Error: Service Control Manager [7030] - The Follower service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly. 7/24/2010 6:51:07 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Remote Access Connection Manager service, but this action failed with the following error: An instance of the service is already running. 7/24/2010 6:48:07 AM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Server service, but this action failed with the following error: An instance of the service is already running. 7/24/2010 5:03:29 AM, Error: Service Control Manager [7034] - The Marvell Yukon Service service terminated unexpectedly. It has done this 1 time(s). 7/24/2010 12:33:24 PM, Error: netbt [4321] - The name "JOVAN :0" could not be registered on the interface with IP address 192.168.1.3. The computer with the IP address 192.168.1.4 did not allow the name to be claimed by this computer. 7/24/2010 12:11:07 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running. 7/24/2010 12:09:11 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service winmgmt with arguments "" in order to run the server: {8BC3F05E-D86B-11D0-A075-00C04FB68820} 7/24/2010 11:17:53 AM, Error: bowser [8003] - The master browser has received a server announcement from the computer JCLAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{F0929EDD-E08B-41EC-B5A9-6FBBD9EA2. The master browser is stopping or an election is being forced. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the User Profile Service service to connect. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Multimedia Class Scheduler service to connect. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7001] - The Windows Audio service depends on the Multimedia Class Scheduler service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7000] - The User Profile Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7000] - The Multimedia Class Scheduler service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7000] - The Intel(R) PRO/1000 PCI Express Network Connection Driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 7/24/2010 10:49:44 AM, Error: Service Control Manager [7000] - The Intel(R) PRO/1000 NDIS 6 Adapter Driver service failed to start due to the following error: The service cannot be started, either because it is disabled or because it has no enabled devices associated with it. 7/24/2010 10:48:58 AM, Error: EventLog [6008] - The previous system shutdown at 10:47:17 AM on 7/24/2010 was unexpected. 7/24/2010 10:47:17 AM, Error: EventLog [6008] - The previous system shutdown at 10:46:17 AM on 7/24/2010 was unexpected. 7/24/2010 10:25:47 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Themes service to connect. 7/24/2010 10:25:47 AM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the System Event Notification Service service to connect. 7/24/2010 10:25:47 AM, Error: Service Control Manager [7000] - The Themes service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/24/2010 10:25:47 AM, Error: Service Control Manager [7000] - The System Event Notification Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/24/2010 10:24:13 AM, Error: EventLog [6008] - The previous system shutdown at 10:22:36 AM on 7/24/2010 was unexpected. 7/24/2010 10:22:49 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 7/24/2010 10:22:48 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 7/24/2010 10:22:47 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service fdPHost with arguments "" in order to run the server: {145B4335-FE2A-4927-A040-7C35AD3180EF} 7/24/2010 10:22:44 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 7/24/2010 10:22:36 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 7/24/2010 10:22:01 AM, Error: EventLog [6008] - The previous system shutdown at 10:20:05 AM on 7/24/2010 was unexpected. 7/24/2010 10:20:05 AM, Error: EventLog [6008] - The previous system shutdown at 10:18:27 AM on 7/24/2010 was unexpected. 7/23/2010 12:50:27 AM, Error: BROWSER [8007] - The browser was unable to update the service status bits. The data is the error. 7/17/2010 9:24:48 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Shell Hardware Detection service to connect. 7/17/2010 9:24:48 PM, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Extensible Authentication Protocol service to connect. 7/17/2010 9:24:48 PM, Error: Service Control Manager [7001] - The WLAN AutoConfig service depends on the Extensible Authentication Protocol service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 7/17/2010 9:24:48 PM, Error: Service Control Manager [7001] - The Windows Image Acquisition (WIA) service depends on the Shell Hardware Detection service which failed to start because of the following error: The service did not respond to the start or control request in a timely fashion. 7/17/2010 9:24:48 PM, Error: Service Control Manager [7000] - The Extensible Authentication Protocol service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 7/17/2010 9:20:01 AM, Error: EventLog [6008] - The previous system shutdown at 9:18:10 AM on 7/17/2010 was unexpected.
==== End Of File ===========================
Results of screen317's Security Check version 0.99.4 Windows Vista Service Pack 2 (UAC is disabled!) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Disabled! Antivirus 2010 McAfee SecurityCenter WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware Java(TM) 6 Update 11 Out of date Java installed! Adobe Flash Player 10.1.53.64 Adobe Reader 9 Out of date Adobe Reader installed! Mozilla Firefox (3.6.6) ```````````````````````````````` Process Check: objlist.exe by Laurent McAfee VIRUSS~1 mcshield.exe ```````````````````````````````` DNS Vulnerability Check: Unknown. This method cannot test your vulnerability to DNS cache poisoning.
``````````End of Log````````````
....I believe that is everything thx again for the help ^^.
Well I ran into some problems, every time I do something related to malwarebytes my computer gets a blue screen. So I am really stuck and now this Antimalware Doctor program is bothering me I really don't know what to do next any suggestions?
A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
If not, delete the file, then download and use the one provided in Link 2.
If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
If the tool does not run from any of the links provided, please let me know.
A log pops up at the end of the run. This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Now.... See if your renamed MBAM (bozo) will run so that you can REMOVE SELECTED and post your log as requested above.
* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
Double click on ComboFix.exe & follow the prompts.
As part of its process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
Click on Yes, to continue scanning for malware.
When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a fresh HijackThis log for further review.
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you -- please tell your helper.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
* Additional information on A/V control HERE. * ComboFix is not intended for use with servers.
Memory Processes Infected: C:\Windows\System32\config\systemprofile\AppData\Roaming\9E3EDC761A3E9E2AB303E65361B59258\setupupdate70702.exe (Trojan.Agent.Gen) -> Unloaded process successfully.
Memory Modules Infected: C:\Windows\System32\iiijkk.dll (Trojan.Agent) -> Delete on reboot. C:\Windows\System32\config\systemprofile\AppData\Local\Nlmgtui.dll (Trojan.Hiloti) -> Delete on reboot.
Registry Keys Infected: HKEY_CLASSES_ROOT\AppID\{84c3c236-f588-4c93-84f4-147b2abbe67b} (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\AppID\{7b6a2552-e65b-4a9e-add4-c45577ffd8fd} (Adware.EZLife) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\JDK5SWFMZY (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\follower (Trojan.Dropper) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Antimalware Doctor Inc (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\Antimalware Doctor (Rogue.AntimalwareDoctor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Sysinternals Antivirus (Rogue.SysinternalsAntivirus) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Defense Center (Rogue.DefenseCenter) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Sky-Banners (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Street-Ads (Adware.Adrotator) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\AVSolution (Trojan.Agent) -> Quarantined and deleted successfully.
Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\setupupdate70702.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qronasevegu (Trojan.Hiloti) -> Delete on reboot. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\qronasevegu (Trojan.Hiloti) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sta (Trojan.Agent.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\jdk5swfmzy (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\netc (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lhyucoqa (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\tdaoxvuy (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yousonqo (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\awurqpsys (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\24d1ca9a-a864-4f7b-86fe-495eb56529d8 (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\7bde84a2-f58f-46ec-9eac-f1f90fead080 (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\uid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cbywwtsys (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\efdaxvsys (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\efdaxvsys (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected: (No malicious items detected)
Folders Infected: C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sysinternals Antivirus (Rogue.SysinternalsAntivirus) -> Quarantined and deleted successfully. C:\Windows\System32\lowsec (Stolen.data) -> Quarantined and deleted successfully. C:\Windows\$NtUninstallMTF1011$ (Adware.Adrotator) -> Quarantined and deleted successfully.
Files Infected: C:\Windows\System32\iiijkk.dll (Trojan.Agent) -> Delete on reboot. C:\Windows\System32\config\systemprofile\AppData\Roaming\9E3EDC761A3E9E2AB303E65361B59258\setupupdate70702.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Local\Nlmgtui.dll (Trojan.Hiloti) -> Delete on reboot. C:\Windows\system32\Drivers\gmdfrwkk.sys (Rootkit.Bubnix) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\0.345412721178449.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\0.7127039105708863.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\rvWPCqOsYw.exe (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrkB2F4.tmp_30 (Trojan.Scar) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrkC325.tmp_30 (Trojan.Scar) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrkD197.tmp_30 (Trojan.Scar) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrkD385.tmp_30 (Trojan.Scar) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrkF493.tmp_30 (Trojan.Scar) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\itse.exe (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\lvjhkt.exe (Adware.BHO) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insF954.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrkACE7.tmp_30 (Trojan.Scar) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\wrk66FC.tmp_30 (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\FC4E.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\ins77A4.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insB1B7.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insB861.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insC7D7.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insD648.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insD827.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\insE980.tmp (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\pkujnvv.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Local\Temp\jHYgUZOXVZ.exe (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Local\Temp\leajHKzMRQ.exe (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Windows\Temp\9.7027712845825E7.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Windows\Temp\VBEEceovwG.exe (Trojan.Hiloti) -> Quarantined and deleted successfully. C:\Windows\Temp\mrxru.exe (Adware.BHO) -> Quarantined and deleted successfully. C:\Windows\Temp\BFE1.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\About.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Activate.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Buy.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Defense Center Support.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Defense Center.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Scan.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Settings.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Update.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\About.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Activate.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Buy.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Defense Center Support.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Defense Center.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Scan.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Settings.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Defense Center\Update.lnk (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Sysinternals Antivirus\Sysinternals Antivirus.lnk (Rogue.SysinternalsAntivirus) -> Quarantined and deleted successfully. C:\Windows\System32\lowsec\local.ds (Stolen.data) -> Quarantined and deleted successfully. C:\Windows\System32\lowsec\user.ds (Stolen.data) -> Quarantined and deleted successfully. C:\Windows\System32\lowsec\user.ds.lll (Stolen.data) -> Quarantined and deleted successfully. C:\Windows\$NtUninstallMTF1011$\apUninstall.exe (Adware.Adrotator) -> Quarantined and deleted successfully. C:\Windows\$NtUninstallMTF1011$\zrpt.xml (Adware.Adrotator) -> Quarantined and deleted successfully. C:\ProgramData\Update\seupd.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Defense Center.LNK (Rogue.DefenseCenter) -> Quarantined and deleted successfully. C:\Windows\System32\ernel32.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\sdra64.exe (Spyware.Zbot) -> Quarantined and deleted successfully. C:\Windows\Temp\0.34194301437978314.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\0.6802962783401109.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\1_goo.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\6_ldry3no.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\4_pinnew.exe (Trojan.Downloader) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\2_load.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\60325cahp25ca0.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\60325cahp25ca2.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\avto.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\ffollower.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Users\IanP\AppData\Local\Temp\q1.exe (Trojan.Clicker) -> Quarantined and deleted successfully. C:\Windows\svc.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Windows\Tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 8:17:38 PM, on 7/24/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18904) Boot mode: Normal
Acrobat.com Adobe AIR Adobe AIR Adobe Download Manager Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9 Antivirus 2010 Apple Mobile Device Support Apple Software Update Banctec Service Agreement Bonjour BrightShadow Cisco EAP-FAST Module Cisco LEAP Module Cisco PEAP Module Compatibility Pack for the 2007 Office system Dell DataSafe Local Backup Dell DataSafe Local Backup - Support Software Dell DataSafe Online Dell Dock Dell Edoc Viewer Dell Getting Started Guide Dell Remote Access Dell Support Center (Support Software) Dell Touchpad Dell Wireless WLAN Card Utility Dell-eBay Dungeons & Dragons Online - Eberron Unlimited™ EPSON NX100 Series Printer Uninstall GoToAssist 8.0.0.514 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® Matrix Storage Manager ITRWoW 3.2.2a iTunes Java(TM) 6 Update 11 Junk Mail filter update Malwarebytes' Anti-Malware McAfee SecurityCenter Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Security Update (KB953297) Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 SP1 Microsoft Choice Guard Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office 2007 Service Pack 2 (SP2) Microsoft Office Excel MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office Home and Student 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2) Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Search Enhancement Pack Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Works Mozilla Firefox (3.6.6) MSVCRT OGA Notifier 2.0.0048.0 Pando Media Booster Playdom Toolbar Power Search Tool PowerDVD DX QuickSet QuickTime Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager Security Update for 2007 Microsoft Office System (KB969559) Security Update for 2007 Microsoft Office System (KB976321) Security Update for 2007 Microsoft Office System (KB978380) Security Update for Microsoft Office Excel 2007 (KB978382) Security Update for Microsoft Office PowerPoint 2007 (KB957789) Security Update for Microsoft Office system 2007 (972581) Security Update for Microsoft Office system 2007 (KB969613) Security Update for Microsoft Office system 2007 (KB974234) Security Update for Microsoft Office Visio Viewer 2007 (KB973709) Skype web features Skype™ 4.1 SlingPlayer SlingPlayer Turbine Download Manager Update for 2007 Microsoft Office System (KB967642) Update for 2007 Microsoft Office System (KB981715) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office InfoPath 2007 (KB976416) Update for Microsoft Office OneNote 2007 (KB980729) Update for Microsoft Office OneNote 2007 Help (KB963670) Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 (KB974561) Update for Microsoft Office Word 2007 Help (KB963665) Verizon Broadband Toolbar (IE only) Verizon Servicepoint 3.5.10 Vz In Home Agent Windows Live Call Windows Live Communications Platform Windows Live Essentials Windows Live Essentials Windows Live Family Safety Windows Live Mail Windows Live Messenger Windows Live Photo Gallery Windows Live Sign-in Assistant Windows Live Sync Windows Live Toolbar Windows Live Upload Tool Windows Live Writer Wizard101 Yahoo! Messenger Yahoo! Search Protection Yahoo! Software Update Yahoo! Toolbar
The Microsoft Recovery Console prompt never appeared during the search just thought I should point it out. Also the Combofix icon is no longer in my Desktop, for some reason I can't find it.
ComboFix 10-07-24.03 - IanP 07/25/2010 9:05.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3545.2353 [GMT -4:00] Running from: c:\windows\system32\config\systemprofile\Desktop\ComboFix.exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
Infected copy of c:\windows\system32\drivers\i8042prt.sys was found and disinfected Restored copy from - Kitty had a snack :p . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) .
- - End Of File - - 2CCE191580357C6B07308EA75C3185B3
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 9:33:54 AM, on 7/25/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18904) Boot mode: Normal
If you don't want it, please go to Add/Remove and uninstall it.
Following that, delete the Playdom folder: c:\program files\Playdom
If you cannot find ComboFix on your Desktop, download it again. Make sure you save it DIRECTLY to the Desktop this time.
You had quite a mess in there.That is unusual for a Vista system running McAfee - unless you installed McAfee after the fact.. I'm not sure we can get all of it, but I will certainly try. Any idea how that computer got so intected?
Do you have any idea what this is? c:\users\IanP\AppData\Roaming\Niumor
Let's continue with ComboFix:
Disconnect from the internet....pull the plug! Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray.
Here are the McAfee instructions to be sure McAfee is not deleting Combofix or interfering:
If that does not work, please uninstall McAfee. (If you have the CD's, or use McAfee Support, you can re-install it once we have verified that the computer is clean.)
Please open McAfee Security Centre
Under Common Tasks click on Home
Click Computer Files
Click Configure
Make sure the following are disabled by ticking the "Off" button.
Virus protection Spyware protection System Guards Protection Script Scanning Protection (you may have to scroll down to see it)
Next, select never for "When to re-enable real time scanning"
Open Notepad and copy/paste the following text between the lines below. Do not copy the dotted lines. ** Make sure you copy/paste ALL the text at once. Do not try to edit extra spaces. It will copy correctly to Notepad if you highlight and copy as is.
Referring to the picture above, drag CFScript into ComboFix.exe
You will be prompted to run Combofix again.
Follow the same instructions you did before for running ComboFix. CAUTION: Do not mouse-click ComboFix while it is running. It may cause it to stall.
When finished, a log is produced here: C:\ComboFix.txt.
Please download GooredFix and save it to your Desktop.
Double-click Goored.exe to run it.
Select 1. Find Goored (no fix) by typing 1 and pressing Enter.
A log will open, please post the contents of that log in your next reply along with your other requested logs. (It can also be found on your desktop, called Goored.txt). Note:Do not run Option #2 yet.
In your next reply, please post that log along with:
Goored Fix gives me a prompt that it will check for infections and remove them, doesn't let me type anything so I don't know if I should continue because you said no "fix". Also I have no idea how the computer got so infected and no I do not know what that file is.
Bugbatter
4 Apprentice
•
20487 Posts
654
0
Posted July 24th, 2010 11:00
Welcome. Thank you for using Dell Community Forums.
I am reviewing your log. It appears that you have quite a bit of malware in there. It is surprising that McAfee did not see it. When you say that you barely open Malwarebytes is that because it will not run, or because you do not choose to use it?
While I arrange how to deal with this, you can help me by addressing the following:
* Have you have posted this issue on another forum? If so, please provide a link to the topic.
* If you have disabled System Restore in an attempt to begin cleaning malware, please enable it now. We will flush System Restore when we are finished cleaning and we are sure that everything is running smoothly.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE.
* If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE.
* If this computer belongs to someone else, do you have authority to apply the fixes we will use?
* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures. Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using. Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate. It is understood by the trained analysts that once a helper replies to a log, he continues working with you until the issue is resolved.
* During the course of our cleanup please do not do any additional online work or surfing until we have verified that your system is clean.
* We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case. Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.
We need to see some additional information about what is happening in your machine.
1. DDS.txt
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE.
Download Security Check by screen317 and save it to your Desktop: here or here
No Reply within 3 days will result in this topic being closed, and I will remove it from my subscriptions. If you require more time, please let me know.
Instructions posted for this user are customized for this user only. The tools used may cause damage if used on a computer with different infections. If you think you have similar problems, please post a log at the top of this board to start a new forum topic.