Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.
Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.
DO NOT RUN ComboFix unless requested to.
Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.
When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.
Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
I recieved a particularily nasty trojan and ran Malware. After removing the trojan which took all day, on start up I recieve the following message:
DLL/documents and settings/david eichner/local settings/ application data/drmnetvdm/smpwebsched.dll is not a valid windows image
Once you click OK I get another message:
error loading/david eichner/ local settings/application data/drmnetvdm/smpwebsched.dll % is not a valid win32 application
How do I reienstall or correct this bleeping situation.
This post has been edited by Orange Blossom: 07 March 2011 - 01:44 PM
Reason for edit: Moved to AII. ~ OB
My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
---------------- If I am helping you, thenPlease Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
---------------- My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.
Open the log file in Notepad then go to Edit and select all then go back to edit and copy. After that right click in the add reply text box and hit paste.
My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
---------------- If I am helping you, thenPlease Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
---------------- My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.
The logs appear in a notepad file. Copy the log from the notepad then paste the log into the text area when you create a reply.
Orange Blossom
Help us help you. If HelpBot replies, you MUST follow step 1 in its reply so we know you need help.
Orange Blossom An ounce of prevention is worth a pound of cure SuperAntiSpyware, SpywareBlaster, WinPatrol Plus, ESET Smart Security, Malwarebytes' Anti-Malware, NoScript Firefox ext., Norton noscript
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus System 2011 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\ANTIVIRUS SYSTEM 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mscjm (Trojan.VB) -> Value: mscjm -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mscj (Backdoor.Bot) -> Value: mscj -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiVirus System 2011 (Trojan.FakeAlert) -> Value: AntiVirus System 2011 -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Security Manager (Trojan.FakeAlert) -> Value: Security Manager -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AntiVirus System 2011\BackgroundScan (Rogue.AntivirusSystem2011) -> Value: BackgroundScan -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\documents and settings\david eichner\start menu\Programs\antivirus system 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011 (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\david eichner\application data\92877\mscjm.exe (Trojan.VB) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\92877\mscj.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011\antivirus__system__2011.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011\securitymanager.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\92877\bbzzkzz18.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011\securityhelper.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\local settings\Temp\google.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\local settings\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\local settings\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\local settings\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\local settings\Temp\dfbleep.exe (Malware.Trace) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\microsoft\internet explorer\quick launch\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\start menu\Programs\antivirus system 2011\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\start menu\Programs\antivirus system 2011\activate antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\start menu\Programs\antivirus system 2011\help antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\start menu\Programs\antivirus system 2011\how to activate antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\start menu\Programs\antivirus system 2011.lnk (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\Desktop\antivirus system 2011.lnk (Rogue.AntiVirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011\icoactivate.ico (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011\IcoHelp.ico (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
c:\documents and settings\david eichner\application data\antivirus system 2011\icouninstall.ico (Rogue.AntivirusSystem2011) -> Quarantined and deleted successfully.
My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
---------------- If I am helping you, thenPlease Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
---------------- My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.
Yes I have seen it and have used it many times I just never had dll file taken out by it. I am looking at how to reinstall the missing files because it caused my computer to refuse to start until I went to safe mode and started it from an earlier date which did not help restore the files.
Hello, most likely this is a leftover registry setting. In order to correct it, I need to see a more detailed log. I'll move this topic to the appropriate forum.
OTL
-----
Please download OTL from one of the following mirrors:
Two reports will open, copy and paste them in a reply here:
OTListIt.txt <-- Will be opened
Extra.txt <-- Will be minimized
regards, Elise
"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton Follow BleepingComputer on: Facebook | Twitter | Google+
Hi Blonde. Sorry for the delay. I was traveling for work. I am afraid I do not know what a mirror is or how to do as you suggested. I feel silly being older but I only know enough about my computer to mess it once in awhile and reset the time or run virus ware.
Don't worry about it.
A mirror is a download link, so just click the link, download the file and run it as instructed.
regards, Elise
"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton Follow BleepingComputer on: Facebook | Twitter | Google+
"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton Follow BleepingComputer on: Facebook | Twitter | Google+
Due to the lack of feedback, this topic is now closed.
In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days.
regards, Elise
"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton Follow BleepingComputer on: Facebook | Twitter | Google+