Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Nov 30 2008, 10:35 PM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
I have a computer that had no antivirus software on it. It became so bad that popups made using the internet nearly impossible. I installed Norton on it and it showed that I had viruses and various other problems (I wrote down 3: Vundo, Metajuar and Brojack) Removing this in Norton did not fix the popups. Also I think the computer was being pharmed, it was a couple of weeks ago. I had found that the DNS server had an address in it that suggested it was being pharmed (or thats what it told me on the antivirus website). I think I may have solved that one particular problem by clicking on "Obtain DNS Server Address Automatically," I really don't know though... Lastly Automatic updates will NOT turn on, even when i try to go into services.msc and make it start it will not and gives me error 1058. I am positive that there is something wrong with this computer, I just dont know what or how to fix it.... If anyone can help me I would greatly appreciate it, and thank you in advanced. Mia |
|
|
|
Nov 30 2008, 10:39 PM
Post
#2
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hello and welcome ...We should do these scans first. Post back 2 logs and tell us how the PC is afterwards,thanks.
Please download Malwarebytes Anti-Malware and save it to your desktop.
NEXT: Please download ATF Cleaner by Atribune & save it to your desktop.
NOW: SAS scan this will be at least an hour. Please download and scan with SUPERAntiSpyware Free
Scan with SUPERAntiSpyware as follows:
This post has been edited by boopme: Nov 30 2008, 10:41 PM -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Dec 1 2008, 01:20 AM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
Thanks for the quick response boopme. I did everything you said and now the computer will not start beyond the XP start up screen and then it restarts and has the windows did not start sucessfully message with starting in safe mode or last known good configuration message.
Any advice? |
|
|
|
Dec 1 2008, 02:41 PM
Post
#4
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Have you tried ,Last good Configuration?
Did the scans complete? Have yoiu tried to fully shut the PC down from the rear switch,wait a minute and restart? -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Dec 1 2008, 06:05 PM
Post
#5
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
Hi Boopme,
Sorry it took so long for me to reply, I was at work Starting the computer from the last known good config worked. I had to run the Malwarebytes Anti-Malware from safe mode because the computer would freeze otherwise. Also it seems like I can now enable Automatic updates.... Here are the logs Malwarebytes' Anti-Malware 1.30 Database version: 1439 Windows 5.1.2600 Service Pack 2 11/30/2008 10:57:21 PM mbam-log-2008-11-30 (22-57-21).txt Scan type: Quick Scan Objects scanned: 50040 Time elapsed: 4 minute(s), 8 second(s) Memory Processes Infected: 0 Memory Modules Infected: 1 Registry Keys Infected: 46 Registry Values Infected: 9 Registry Data Items Infected: 12 Folders Infected: 12 Files Infected: 29 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: C:\WINDOWS\system32\opnlKBqp.dll (Trojan.Vundo.H) -> Delete on reboot. Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18a97d34-eb8a-4b6d-b5f7-48d3e35c76ec} (Trojan.Vundo.H) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{18a97d34-eb8a-4b6d-b5f7-48d3e35c76ec} (Trojan.Vundo.H) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{76cfb752-e1b5-45e5-871f-e696b997ffb1} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\byxphyvv (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{76cfb752-e1b5-45e5-871f-e696b997ffb1} (Trojan.Vundo.H) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbax (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbax.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbinfoband (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.hbinfoband.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebutton (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebutton.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebuttona (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.iebuttona.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.rprtctrl (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\shoppingreport.rprtctrl.1 (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\vreslabwarning.warningbho (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\vreslabwarning.warningbho.1 (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\z444.z444mgr (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\z444.z444mgr.1 (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{8ad9ad05-36be-4e40-ba62-5422eb0d02fb} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{aebf09e2-0c15-43c8-99bf-928c645d98a0} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d8560ac2-21b5-4c1a-bdd4-bd12bc83b082} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b494e7bb-1e33-4922-a947-f74eff4e714f} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{c9ccbb35-d123-4a31-affc-9b2933132116} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{a16ad1e9-f69a-45af-9462-b1c286708842} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{20ea9658-6bc3-4599-a87d-6371fe9295fc} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{cdca70d8-c6a6-49ee-9bed-7429d6c477a2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{d136987f-e1c4-4ccc-a220-893df03ec5df} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{e343edfc-1e6c-4cb5-aa29-e9c922641c80} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b494e7bb-1e33-4922-a947-f74eff4e714f} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b494e7bb-1e33-4922-a947-f74eff4e714f} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\VResLab (Rogue.AntiVirusLab) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\System Alert Popup (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\AMeOpt (Adware.NetOptimizer) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{9034a523-d068-4be8-a284-9df278be776e} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b2} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Extensions\CmdMapping\{c5428486-50a0-4a02-9d20-520b59a9f9b3} (Adware.Shopping.Report) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ba934431-76af-4c99-93c2-c3d21944a72e} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus (Rogue.Antivirus) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securewebinfo.com (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.safetyincludes.com (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\*.securemanaging.com (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\smile (Trojan.Zlob) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\opnlkbqp -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\opnlkbqp -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://windiwsfsearch.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant (Hijack.Search) -> Bad: (http://windiwsfsearch.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://windiwsfsearch.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully. Folders Infected: C:\resycled (Trojan.DNSChanger) -> Quarantined and deleted successfully. C:\Program Files\YourSiteBar (Adware.ISTBar) -> Quarantined and deleted successfully. C:\Program Files\WAV (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully. C:\WINDOWS\system32\512686 (Trojan.BHO) -> Quarantined and deleted successfully. C:\WINDOWS\system32\675873 (Trojan.BHO) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\Application Data (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\db (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\dwld (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\report (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\res1 (Adware.Shopping.Report) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\system32\opnlKBqp.dll (Trojan.Vundo.H) -> Delete on reboot. C:\WINDOWS\system32\pqBKlnpo.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pqBKlnpo.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\byXPHyvv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\ghuhtnbv.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\vbnthuhg.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\wficwttg.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\gttwcifw.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yakydjqt.dll (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\WINDOWS\system32\tqjdykay.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Local Settings\Application Data\qoqsaee_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Local Settings\Application Data\qoqsaee_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Local Settings\Application Data\qoqsaee.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully. C:\Program Files\YourSiteBar\version.txt (Adware.ISTBar) -> Quarantined and deleted successfully. C:\Program Files\YourSiteBar\yoursitebar.xml (Adware.ISTBar) -> Quarantined and deleted successfully. C:\Program Files\WAV\WAV1.dat (Rogue.WindowsAntivirus2008) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\Config.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\db\Aliases.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\db\Sites.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\dwld\WhiteList.xip (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\report\aggr_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\report\send_storage.xml (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\Application Data\ShoppingReport\cs\res1\WhiteList.dbs (Adware.Shopping.Report) -> Quarantined and deleted successfully. C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully. C:\WINDOWS\system32\nvs2.inf (Adware.EGDAccess) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\My Documents\My Music\My Music.url (Trojan.Zlob) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\My Documents\My Pictures\My Pictures.url (Trojan.Zlob) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\My Documents\My Videos\My Video.url (Trojan.Zlob) -> Quarantined and deleted successfully. C:\Documents and Settings\Mario\My Documents\My Documents.url (Trojan.Zlob) -> Quarantined and deleted successfully. This is the SAS log: SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 12/01/2008 at 01:15 AM Application Version : 4.22.1014 Core Rules Database Version : 3656 Trace Rules Database Version: 1637 Scan type : Complete Scan Total Scan Time : 01:28:00 Memory items scanned : 162 Memory threats detected : 0 Registry items scanned : 4804 Registry threats detected : 22 File items scanned : 33869 File threats detected : 11 Rogue.VirusResponseLab2009 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B494E7BB-1E33-4922-A947-F74EFF4E714F} Adware.Vundo/Variant-Greek HKU\S-1-5-21-790525478-1085031214-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{090D36E1-C518-46FB-B98E-00DCD044A043} HKCR\CLSID\{090D36E1-C518-46FB-B98E-00DCD044A043} HKCR\CLSID\{090D36E1-C518-46FB-B98E-00DCD044A043}\InprocServer32 HKCR\CLSID\{090D36E1-C518-46FB-B98E-00DCD044A043}\InprocServer32#ThreadingModel C:\WINDOWS\SYSTEM32\GHCCWW.DLL C:\WINDOWS\SYSTEM32\HHBDPPVJ.DLL C:\WINDOWS\SYSTEM32\INISXH.DLL C:\WINDOWS\SYSTEM32\IPTXUHYH.DLL C:\WINDOWS\SYSTEM32\MSWPBATC.DLL C:\WINDOWS\SYSTEM32\NBNBUG.DLL C:\WINDOWS\SYSTEM32\NYQJPB.DLL C:\WINDOWS\SYSTEM32\RENOUPVM.DLL C:\WINDOWS\SYSTEM32\XEWUNSJQ.DLL C:\WINDOWS\SYSTEM32\ZPUJNH.DLL Rootkit.NDisProt/Fake HKLM\System\ControlSet001\Services\Ndisprot C:\WINDOWS\SYSTEM32\DRIVERS\NDISPROT.SYS HKLM\System\ControlSet001\Enum\Root\LEGACY_Ndisprot HKLM\System\ControlSet002\Services\Ndisprot HKLM\System\ControlSet002\Enum\Root\LEGACY_Ndisprot HKLM\System\ControlSet003\Services\Ndisprot HKLM\System\ControlSet003\Enum\Root\LEGACY_Ndisprot HKLM\System\CurrentControlSet\Services\Ndisprot HKLM\System\CurrentControlSet\Enum\Root\LEGACY_Ndisprot Adware.Vundo Variant/Rel HKLM\SOFTWARE\Microsoft\MS Juan HKLM\SOFTWARE\Microsoft\MS Juan#RID HKLM\SOFTWARE\Microsoft\MS Track System HKLM\SOFTWARE\Microsoft\MS Track System#Uid Rogue.Component/Trace HKLM\Software\Microsoft\F02C5E10 HKLM\Software\Microsoft\F02C5E10#f02c5e10 HKLM\Software\Microsoft\F02C5E10#Version HKLM\Software\Microsoft\F02C5E10#f02cf390 HKLM\Software\Microsoft\F02C5E10#f02c9a75 |
|
|
|
Dec 1 2008, 08:53 PM
Post
#6
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Hello you have a lot of malware and some of it is stubborn so we may need to rerun things. Also as you see the troubles having no antivirus can cause, So we need you to install one ,else all we do here will be for naught in only a few days.
The malwares are restricting the updates and its a good sign that they are working. Did you run windows update sucessfully yet? Probably be easier once we've cleaned the machine. First Open MBAM scanner again. Click the update button. Rescan and post that log. Try running MBAM from normal mode as this app is stronger that way. If not run from safe again. Promise me you will install and keep it Free antivirus... Avira AntiVir Install update and scan. We have more to do but lets get this done...thanks -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Dec 1 2008, 09:04 PM
Post
#7
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
I do currently have Norton Internet Security, is that enough?
|
|
|
|
Dec 1 2008, 09:12 PM
Post
#8
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
Here is the new log for MBAM
Malwarebytes' Anti-Malware 1.30 Database version: 1443 Windows 5.1.2600 Service Pack 2 12/1/2008 9:10:08 PM mbam-log-2008-12-01 (21-10-08).txt Scan type: Quick Scan Objects scanned: 51182 Time elapsed: 6 minute(s), 40 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 4 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b494e7bb-1e33-4922-a947-f74eff4e714f} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b494e7bb-1e33-4922-a947-f74eff4e714f} (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Dec 1 2008, 09:14 PM
Post
#9
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
My bad, I read that wrong. Yes thats good.
Also if you have not rebooted after those scans please do so to complete the makware removal. We're posting close Then follow the Mbam scan with SDFix Please print out and follow these instructions: "How to use SDFix". <- This program is for Windows 2000/XP ONLY. When using this tool, you must use the Administrator's account or an account with "Administrative rights"
This post has been edited by boopme: Dec 1 2008, 09:16 PM -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Dec 1 2008, 10:20 PM
Post
#10
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
Is it okay that I ran the second SDFix scan in normal mode (not safe mode?) with virus scanners on?
Here is the log SDFix: Version 1.240 Run by Mario on Mon 12/01/2008 at 09:53 PM Microsoft Windows XP [Version 5.1.2600] Running From: C:\SDFix Checking Services : Restoring Default Security Values Restoring Default Hosts File Rebooting Checking Files : Trojan Files Found: C:\DOCUME~1\Mario\LOCALS~1\Temp\TMP17.tmp - Deleted C:\DOCUME~1\Mario\LOCALS~1\Temp\TMP1C.tmp - Deleted C:\DOCUME~1\Mario\LOCALS~1\Temp\TMP1D.tmp - Deleted C:\DOCUME~1\Mario\LOCALS~1\Temp\TMP1E.tmp - Deleted C:\DOCUME~1\Mario\LOCALS~1\Temp\TMPD3.tmp - Deleted Removing Temp Files ADS Check : Final Check : catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-12-01 22:07:43 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden services & system hive ... scanning hidden registry entries ... scanning hidden files ... scan completed successfully hidden processes: 0 hidden services: 0 hidden files: 0 Remaining Services : Authorized Application Key Export: [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire" "C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Application Loader" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"="C:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe:*:Enabled:AOL" "C:\\Program Files\\AOL 9.0\\waol.exe"="C:\\Program Files\\AOL 9.0\\waol.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe:*:Enabled:AOLTsMon" "C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"="C:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe:*:Enabled:AOLTopSpeed" "C:\\Program Files\\Common Files\\AOL\\1132101710\\EE\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1132101710\\EE\\AOLServiceHost.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"="C:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\AOLSP Scheduler.exe:*:Enabled:AOL" "C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe"="C:\\Program Files\\Common Files\\AOL\\AOL Spyware Protection\\asp.exe:*:Enabled:AOL" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" "C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:ęTorrent" "C:\\Program Files\\Blubster\\Blubster.exe"="C:\\Program Files\\Blubster\\Blubster.exe:*:Enabled:Blubster" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1" "C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files : File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes : Finished! |
|
|
|
Dec 1 2008, 10:36 PM
Post
#11
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
QUOTE I ran the second SDFix scan in normal mode (not safe mode?) with virus scanners on Did you run it once from Safe,if so can we see that log too. Or would it not run in safe? Do you need hlp disabling your scanners? Also run another Updated MBAM scan. Sorry but there just aren't any real shortcuts to malware removal. -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Dec 1 2008, 10:40 PM
Post
#12
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
Sorry-- I should have made myself more clear, when the computer rebooted to do the "final check" the computer was not in safe mode. But when I started the scan it was. Also I guess i do need help disabling my scanners since i didnt think any were running (i didnt see them in the tray beside the clock)
This post has been edited by MiaGirl: Dec 1 2008, 10:43 PM |
|
|
|
Dec 1 2008, 10:41 PM
Post
#13
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
Just finished the last MBAM scan
Malwarebytes' Anti-Malware 1.30 Database version: 1443 Windows 5.1.2600 Service Pack 2 12/1/2008 10:39:24 PM mbam-log-2008-12-01 (22-39-24).txt Scan type: Quick Scan Objects scanned: 51194 Time elapsed: 10 minute(s), 1 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) |
|
|
|
Dec 1 2008, 11:03 PM
Post
#14
|
|
![]() To INSANITY and BEYOND !! ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 21,869 Joined: 10-September 04 From: NJ USA Member No.: 2,608 |
Well it may have worked but I'd rather be sure as in safe mode malwares are in active and easier to remve.
See Enabling or disabling Norton Internet Security or Norton Personal Firewall Leave firewall on. MBAM is not active and SAS should have a System Tray icon. That by right clicking will produce a window with a On/Off option. Do you have any others? Then run SDFix and MBAM again. -------------------- Can you spare some PC cycles to help FIND A CURE .. BC FOLDING TEAM Click me /info..
ThoughtVent a goodplace to discuss.<<>>>Staying Updated Calendar of Updates. For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear.... Become a BleepingComputer fan: Facebook |
|
|
|
Dec 1 2008, 11:15 PM
Post
#15
|
|
|
New Member ![]() Group: Members Posts: 14 Joined: 30-November 08 Member No.: 263,255 |
These instructions ( Enabling or disabling Norton Internet Security or Norton Personal Firewall) dont seem to apply to me, there is no left pane with User Accounts in it.....
|
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 22nd November 2009 - 02:20 AM |