Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Jun 3 2009, 09:33 PM
Post
#1
|
|
|
Member ![]() ![]() Group: Members Posts: 25 Joined: 11-October 04 Member No.: 3,528 |
Since two days ago, a screen keeps popping up saying I am iunfected and it looks like it is from Window Internet Explorer. The address is http: //dapcleaner.com/?affid02942 - My Computer Online Scan - Windows internet Explorer. I tried to get a snagit of it, but when it it up, it will not allow me to do anything else. I went into safe mode and did a Adaware scan and removed the things it came up with, but now, when I open my browser, Internet Explorer and go to facebook, my browser automatically closes down. And when I search for something and I click on it, I do not get that page, but another seach engine page like http: //www.ave99.com open in a new window. Cathy This post has been edited by garmanma: Jun 4 2009, 07:48 AM
Reason for edit: Disabled links
|
|
|
|
Jun 4 2009, 07:49 AM
Post
#2
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,832 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
The process of cleaning your computer may require you to temporarily disable some security programs. If you are using SpyBot Search and Destroy, please refer to Note 2 at the bottom of this page. Please download Malwarebytes Anti-Malware and save it to your desktop. alternate download link 2
-- If MBAM encounters a file that is difficult to remove, you may be asked to reboot your computer so it can proceed with the disinfection process. Regardless if prompted to restart the computer or not, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. Note 2: -- MBAM may make changes to your registry as part of its disinfection routine. If you're using other security programs that detect registry changes (like Spybot's Teatimer), they may interfere with the fix or alert you after scanning with MBAM. Please disable such programs until disinfection is complete or permit them to allow the changes. To disable these programs, please view this topic: How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs -------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
Jun 4 2009, 04:05 PM
Post
#3
|
|
|
Member ![]() ![]() Group: Members Posts: 25 Joined: 11-October 04 Member No.: 3,528 |
Thank you for your help. I followed the instructions and here is the note log.
Does it look ok to you? Malwarebytes' Anti-Malware 1.37 Database version: 2230 Windows 5.1.2600 Service Pack 2 6/4/2009 5:57:34 PM mbam-log-2009-06-04 (17-57-34).txt Scan type: Quick Scan Objects scanned: 97628 Time elapsed: 8 minute(s), 47 second(s) Memory Processes Infected: 1 Memory Modules Infected: 0 Registry Keys Infected: 6 Registry Values Infected: 4 Registry Data Items Infected: 0 Folders Infected: 1 Files Infected: 14 Memory Processes Infected: C:\WINDOWS\pp10.exe (Worm.Koobface) -> Unloaded process successfully. Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\mp.mediapops (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\mp.mediapops.1 (Adware.Delphinmediaviewer) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{465a0df8-1673-49cb-b2b1-b2a500513dc8} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{465a0df8-1673-49cb-b2b1-b2a500513dc8} (Trojan.BHO) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Screensavers.com (Adware.Comet) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\pp (Worm.Koobface) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow\www.mysearchnow.com (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\WINDOWS\system32\sysloc (Trojan.BHO) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\pp10.exe (Worm.Koobface) -> Quarantined and deleted successfully. c:\documents and settings\Cathy\local settings\temporary internet files\Content.IE5\1E7J80FS\pp.10[1].exe (Worm.Koobface) -> Quarantined and deleted successfully. c:\documents and settings\Cathy\local settings\temporary internet files\Content.IE5\XYL0S46C\6244[1].exe (Worm.Koobface) -> Quarantined and deleted successfully. c:\WINDOWS\system32\sysloc\sysloc.dll (Trojan.BHO) -> Quarantined and deleted successfully. c:\documents and settings\Cathy\Cookies\MM2048.DAT (Trojan.Agent) -> Quarantined and deleted successfully. c:\documents and settings\Cathy\Cookies\MM256.DAT (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\acrsecB.fon (Trojan.Agent) -> Quarantined and deleted successfully. C:\WINDOWS\Fonts\acrsecI.fon (Trojan.Agent) -> Quarantined and deleted successfully. c:\RECYCLER\ADAPT_Installer.exe (Heuristics.Malware) -> Quarantined and deleted successfully. c:\WINDOWS\9g2234wesdf3dfgjf23 (Worm.KoobFace) -> Quarantined and deleted successfully. C:\WINDOWS\f23567.dat (Worm.KoobFace) -> Quarantined and deleted successfully. c:\WINDOWS\sonce122714.dat (Worm.KoobFace) -> Quarantined and deleted successfully. c:\WINDOWS\sonce122715.dat (Worm.KoobFace) -> Quarantined and deleted successfully. c:\WINDOWS\smdat32m.sys (Rootkit.Agent) -> Quarantined and deleted successfully. |
|
|
|
Jun 4 2009, 07:45 PM
Post
#4
|
|
![]() Computer Masochist ![]() ![]() ![]() ![]() ![]() ![]() Group: Moderator Posts: 23,832 Joined: 27-January 07 From: Cleveland, Ohio Member No.: 108,618 |
Update mbam and run a FULL scan
Please post the results Then run ATF and SAS ATF Please download ATF Cleaner by Atribune & save it to your desktop.
------------------------------------ SAS,may take a long time to scan Please download and scan with SUPERAntiSpyware Free
Scan with SUPERAntiSpyware as follows:
-------------------- Mark
why won't my laptop work? Having grandkids is God's way of giving you a 2nd chance because you were too busy working your butt off the 1st time around Do not send me PMs with problems that should be posted in the forums. Keep it in the forums, so everyone benefits Become a BleepingComputer fan: Facebook and Twitter |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 26th November 2009 - 11:47 AM |