BleepingComputer.com: Is this a virus?

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Is this a virus?

#16 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 03 January 2011 - 08:15 PM

Good ,good after MBAM's log move to post 8
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#17 User is offline   justanotherguy 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 70
  • Joined: 02-January 11
  • Gender:Male
  • Location:Puerto Rico

Posted 03 January 2011 - 08:28 PM

And here is the final log from Malawarebytes
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5450

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

1/3/2011 7:22:20 PM
mbam-log-2011-01-03 (19-22-20).txt

Scan type: Quick scan
Objects scanned: 162463
Time elapsed: 9 minute(s), 0 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\system32\spool\prtprocs\w32x86\914E.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\spool\prtprocs\w32x86\94312.tmp (Trojan.Agent) -> Quarantined and deleted successfully.

#18 User is offline   justanotherguy 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 70
  • Joined: 02-January 11
  • Gender:Male
  • Location:Puerto Rico

Posted 03 January 2011 - 09:21 PM

now the bad thing is the tdsskiller isnt working. i have it saved to my desktop , and ive renamed it with ".com" in the end. but still it doesnt respond. the rename is "123abc.com"

#19 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 03 January 2011 - 09:57 PM

Hi, You have to make sure that extension for know file types are not hidden.

Go here L@@K

Scroll a little to --------------------------------------------------------------------------------
TDSS, Alureon, Tidserv, TDL3 removal instructions using TDSSKiller utility:

See step 2
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#20 User is offline   justanotherguy 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 70
  • Joined: 02-January 11
  • Gender:Male
  • Location:Puerto Rico

Posted 03 January 2011 - 10:06 PM

yea i made sure they werent hidden. and i did what the page told me to but to no avail. do you think i should download Gmer, if so can you give me the link.?

#21 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 03 January 2011 - 10:11 PM

Ok, yea we will need a deeper look to see what's wrong here.

Please go here....
Preparation Guide ,do steps 6 - 9.

Create a DDS log and post it in the new topic explained in step 9,which is here Virus, Trojan, Spyware, and Malware Removal Logs and not in this topic,thanks.
If Gmer won't run,skip it and move on.
Let me know if that went well.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

#22 User is offline   justanotherguy 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 70
  • Joined: 02-January 11
  • Gender:Male
  • Location:Puerto Rico

Posted 03 January 2011 - 10:18 PM

the dds.scr note pad appears with weird symbols and as the rkill.scr said. "this program cannot run in DOS mode" those are the only readable text in there the others are just symbols.

#23 User is offline   justanotherguy 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 70
  • Joined: 02-January 11
  • Gender:Male
  • Location:Puerto Rico

Posted 03 January 2011 - 10:20 PM

should i change it to dds.com?

#24 User is offline   boopme 

  • To Insanity and Beyond
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 48,761
  • Joined: 10-September 04
  • Gender:Male
  • Location:NJ USA

Posted 03 January 2011 - 10:26 PM

If you cannot get DDS to work, please try this instead.

Please download RSIT by random/random from the link provided for your operating system and save it to your desktop.

This tool needs to run while the computer is connected to the Internet so it can download HijackThis if it is not located on your system. If you get a warning from your firewall or other security programs regarding RSIT attempting to contact the Internet, please allow the connection.

  • Close all applications and windows so that you have nothing open and are at your Desktop.
  • Double-click on RSIT.exe to start the program.
    If using Windows Vista, be sure to Run As Administrator.
  • Read the disclaimer and click Continue.
  • When the scan is complete, a text file named log.txt will automatically open in Notepad.
  • Another text file named info.txt will open minimized.
  • Save the log files to your desktop and copy/paste the contents of log.txt by highlighting everything and pressing Ctrl+C.
  • After highlighting, right-click, choose Copy and then paste the contents into a new topic in the Virus, Trojan, Spyware, and Malware Removal Logs forum, NOT here.
  • Copies of both log files are automatically saved in the C:\RSIT folder which the tool creates during the scan.
-- Note: Do not post the contents of info.txt in your reply. Instead, just include it as an attachment to upload using the "Browse" button in the text editor when making your reply.

Important: Be sure to mention that you tried to follow the Prep Guide but were unable to get DDS to run. If RSIT did not work, then reply back here.
How do I get help? Who is helping me?
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

Share this topic:


  • 2 Pages +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users