Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Dec 2 2008, 06:01 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
Please help. This post has been edited by Orange Blossom: Dec 2 2008, 07:15 PM
Reason for edit: Move from HiJack This forum to Am I Infected as there are no logs. ~ OB
|
|
|
|
Dec 3 2008, 03:10 PM
Post
#2
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 17,515 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Please download Malwarebytes Anti-Malware and save it to your desktop.
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs about the problems which you are posting about. Keep it in the forums Become a BleepingComputer fan: Facebook |
|
|
|
Dec 4 2008, 11:47 AM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
Thanks so much for helping me.
|
|
|
|
Dec 4 2008, 11:50 AM
Post
#4
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
Sorry, I forgot to mention that the MBAM report keeps coming back clean, but doesn't have the log window pop open at all. Also, when my pc freezes, I can't bring up the task manager. I have to force shut down my pc when this happens.
This post has been edited by Azrea: Dec 4 2008, 12:37 PM |
|
|
|
Dec 4 2008, 02:45 PM
Post
#5
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 17,515 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
You have some infected Mp3 files
Can you run Kaspersky again and post the log please -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs about the problems which you are posting about. Keep it in the forums Become a BleepingComputer fan: Facebook |
|
|
|
Dec 8 2008, 10:00 AM
Post
#6
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
Sorry for the delay in my reply, my access to wireless is limited. Anyways, Kaspersky keeps freezing and such. Luckily, about a month ago, I ran it and saved the report.
KASPERSKY ONLINE SCANNER 7 REPORT Tuesday, November 11, 2008 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Tuesday, November 11, 2008 14:09:24 Records in database: 1379894 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ Scan statistics: Files scanned: 75420 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 00:52:30 File name / Threat name / Threats count C:\Users\Owner\Documents\LimeWire\Incomplete\T-2753268-i want to come over melissa 192kb.mp3 Infected: Trojan-Downloader.WMA.GetCodec.f 1 C:\Users\Owner\Documents\LimeWire\Incomplete\T-3877629-melissa etheridge come to my .mp3 Infected: Trojan-Downloader.WMA.GetCodec.n 1 The selected area was scanned. Since I found out the infection came from limewire, I uninstalled it and never plan on using it again. |
|
|
|
Dec 8 2008, 03:18 PM
Post
#7
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 17,515 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Did you delete those two files? you should.
You always run the risk when using P2P and torrent sites, no matter how safe they claim to be -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs about the problems which you are posting about. Keep it in the forums Become a BleepingComputer fan: Facebook |
|
|
|
Dec 8 2008, 03:35 PM
Post
#8
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
I deleted the folder, but the problems remain. I don't know where the files got moved to, but I think it is hiding as another process. Isn't there a program I can use to find it again?
This post has been edited by Azrea: Dec 8 2008, 04:33 PM |
|
|
|
Dec 9 2008, 10:04 AM
Post
#9
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 17,515 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
ATF
Please download ATF Cleaner by Atribune & save it to your desktop.
Now SAS,may need an hour Please download and scan with SUPERAntiSpyware Free
Scan with SUPERAntiSpyware as follows:
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs about the problems which you are posting about. Keep it in the forums Become a BleepingComputer fan: Facebook |
|
|
|
Dec 9 2008, 10:37 AM
Post
#10
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
I am so screwed. I can't even save any files. I says that I don't have permission, but I AM the admin. I have an earlier restore point- not before the infection, but before it got this bad. Should I restore? I am going to a friend's house later, so I will try to download these files to my usb and transfer them.
This post has been edited by Azrea: Dec 9 2008, 11:07 AM |
|
|
|
Dec 9 2008, 12:04 PM
Post
#11
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 17,515 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
If you are using XP you can try SDfix
------------------------------------------------- http://www.bleepingcomputer.com/forums/topic131299.html Please print out and follow these instructions: "How to use SDFix". <- for Windows 2000/XP ONLY. When using this tool, you must use the Administrator's account or an account with "Administrative rights"
This post has been edited by garmanma: Dec 9 2008, 12:05 PM -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs about the problems which you are posting about. Keep it in the forums Become a BleepingComputer fan: Facebook |
|
|
|
Dec 9 2008, 01:35 PM
Post
#12
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
I have Vista. Fortunately the usb method worked. I ran AVG with no problems. My browser windows connect and open faster now. This would be a good time to mention that I heard combofix was amazing at getting rid of stuff like this. I didn't run it for fear of ruining my pc beyond repair. Anyways, it found a remnant of it combofix and I don't know if it was a false positive.
SUPERAntiSpyware Scan Log http://www.superantispyware.com Generated 12/09/2008 at 01:13 PM Application Version : 4.23.1006 Core Rules Database Version : 3661 Trace Rules Database Version: 1647 Scan type : Complete Scan Total Scan Time : 00:44:19 Memory items scanned : 217 Memory threats detected : 0 Registry items scanned : 6565 Registry threats detected : 0 File items scanned : 19050 File threats detected : 1 Trojan.SystemDriver C:\COMBOFIX\CREG.DAT This post has been edited by Azrea: Dec 9 2008, 01:36 PM |
|
|
|
Dec 9 2008, 03:16 PM
Post
#13
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 17,515 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Please do not run Combofix on your own
You have done most of the prep work, read and follow this guide: http://www.bleepingcomputer.com/forums/topic34773.html Then post the log in the proper forum here: http://www.bleepingcomputer.com/forums/forum22.html There's a bit of a backlog, so be patient and someone will eventually get to you Good luck -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs about the problems which you are posting about. Keep it in the forums Become a BleepingComputer fan: Facebook |
|
|
|
Dec 9 2008, 03:37 PM
Post
#14
|
|
|
Member ![]() ![]() Group: Members Posts: 20 Joined: 18-November 08 Member No.: 258,025 |
K thanks
This post has been edited by Azrea: Dec 9 2008, 03:38 PM |
|
|
|
Dec 10 2008, 10:44 PM
Post
#15
|
|
|
The Bookworm ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 12,880 Joined: 14-July 06 From: Bloomington, IN Member No.: 76,150 |
Hello Azrea,
Now that you log is posted here: http://www.bleepingcomputer.com/forums/topic185611.html you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a HJT Team member, nor should you continue to ask for help elsewhere. Doing so can result in system changes which may not show in the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer. From this point on the HJT Team should be the only members that you take advice from, until they have verified your log as clean. Please be patient. It may take a while to get a response because the HJT Team members are EXTREMELY busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the HJT Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another HJT Team member is already assisting you and not open the thread to respond. If after 5 days you still have received no response, then post a link to your HJT log in the thread titled "Haven't Had A Reply In Five Days?". To avoid confusion, I am closing this topic. Good luck with your log. The BC Staff -------------------- Orange Blossom An ounce of prevention is worth a pound of cure ESET NOD32, SuperAntiSpyware Pro, SpywareBlaster, Spybot 1.6.2.46, WinPatrol Plus, Sunbelt Personal Firewall - Full, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 4th July 2009 - 09:32 PM |