Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Infected with Comanglia - SysRest gets rid of popup but not browser error


  • This topic is locked This topic is locked
2 replies to this topic

#1 omegamusashi

omegamusashi

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:06:08 AM

Posted 27 December 2008 - 03:56 PM

DDS (Version 1.1.0) - NTFSx86
Run by Dean at 12:35:17.28 on 28/12/2008
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1014.640 [GMT 0:00]

AV: McAfee VirusScan *On-access scanning enabled* (Updated)
FW: McAfee Personal Firewall *enabled*

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Samsung\Samsung EDS\EDSAgent.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\Program Files\Samsung\Samsung Recovery Solution III\WCScheduler.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\WINDOWS\system32\igfxsrvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SAMSUNG\MagicKBD\MagicKBD.exe
C:\Program Files\SAMSUNG\MagicKBD\PerformanceManager.exe
C:\Program Files\Samsung\Easy Display Manager\dmhkcore.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\sol.exe
C:\WINDOWS\system32\igfxext.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Dean\Local Settings\Temporary Internet Files\Content.IE5\ODW52VSD\dds[1].scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\progra~1\mcafee\viruss~1\scriptsn.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.0.926.3450\swg.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_219B3E1547538286.dll
TB: &Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0\bin\jusched.exe
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [<NO NAME>]
mRun: [EDS] c:\program files\samsung\samsung eds\EDSAgent.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [DMHotKey] c:\program files\samsung\easy display manager\DMLoader.exe
mRun: [BatteryManager] c:\program files\samsung\samsung battery manager\BatteryManager.exe
mRun: [SamsungWInClon] c:\program files\samsung\samsung recovery solution iii\WCScheduler
mRun: [MagicKeyboard] c:\program files\samsung\magickbd\PreMKBD.exe
mRun: [mcagent_exe] c:\program files\mcafee.com\agent\mcagent.exe /runkey
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
IE: Send to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
Notify: igfxcui - igfxdev.dll

============= SERVICES / DRIVERS ===============

R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-11-11 201320]
R2 DOSMEMIO;MEMIO;\??\c:\windows\system32\MEMIO.SYS [2008-11-11 4300]
R2 McProxy;McAfee Proxy Service;c:\progra~1\common~1\mcafee\mcproxy\mcproxy.exe [2008-11-11 359248]
R2 McShield;McAfee Real-time Scanner;c:\progra~1\mcafee\viruss~1\mcshield.exe [2008-11-11 144704]
R2 SNM WLAN Service;SNM WLAN Service;"c:\program files\samsung\samsung network manager\SNMWLANService.exe" [2006-10-30 36864]
R3 DNSeFilter;DNSeFilter;c:\windows\system32\drivers\SamsungEDS.sys [2008-1-15 30208]
R3 McSysmon;McAfee SystemGuards;c:\progra~1\mcafee\viruss~1\mcsysmon.exe [2008-11-11 695624]
R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-11-11 79304]
R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-11-11 35240]
R3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-11-11 40488]
R3 VMC326;Vimicro Camera Service VMC326;c:\windows\system32\drivers\VMC326.sys [2008-11-11 238464]
S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-11-11 33832]

=============== Created Last 30 ================

2008-12-26 13:08 19,456 ac------ c:\windows\system32\dllcache\agt0401.dll
2008-12-26 13:08 19,456 ac------ c:\windows\system32\dllcache\agt040d.dll
2008-12-26 07:18 459,264 -c------ c:\windows\system32\dllcache\msfeeds.dll
2008-12-26 07:18 52,224 -c------ c:\windows\system32\dllcache\msfeedsbs.dll
2008-12-26 07:18 6,066,176 -c------ c:\windows\system32\dllcache\ieframe.dll
2008-12-26 07:18 991,232 -c------ c:\windows\system32\dllcache\ieframe.dll.mui
2008-12-26 07:18 267,776 -c------ c:\windows\system32\dllcache\iertutil.dll
2008-12-26 07:18 13,824 -c------ c:\windows\system32\dllcache\ieudinit.exe
2008-12-26 07:18 2,455,488 -c------ c:\windows\system32\dllcache\ieapfltr.dat
2008-12-26 07:18 383,488 -c------ c:\windows\system32\dllcache\ieapfltr.dll
2008-12-26 07:18 63,488 -c------ c:\windows\system32\dllcache\icardie.dll
2008-12-26 06:46 272,128 -c------ c:\windows\system32\dllcache\bthport.sys
2008-12-26 06:46 272,128 -------- c:\windows\system32\drivers\bthport.sys
2008-12-26 06:44 2,145,280 -c------ c:\windows\system32\dllcache\ntkrnlmp.exe
2008-12-26 06:44 2,189,184 -c------ c:\windows\system32\dllcache\ntoskrnl.exe
2008-12-26 06:44 2,023,936 -c------ c:\windows\system32\dllcache\ntkrpamp.exe
2008-12-26 06:44 2,066,048 -c------ c:\windows\system32\dllcache\ntkrnlpa.exe
2008-12-26 06:43 455,296 -c------ c:\windows\system32\dllcache\mrxsmb.sys
2008-12-26 06:42 <DIR> --d----- c:\windows\system32\PreInstall
2008-12-26 06:42 22,752 a------- c:\windows\system32\spupdsvc.exe
2008-12-26 06:42 <DIR> --d-h--- c:\windows\$hf_mig$
2008-12-26 06:30 <DIR> --dsh--- c:\documents and settings\dean\UserData
2008-12-26 06:30 <DIR> --d----- c:\windows\system32\SoftwareDistribution
2008-12-26 01:59 <DIR> --d----- c:\documents and settings\dean\Bluetooth Software
2008-12-26 01:58 149,123 a------- c:\windows\system32\drivers\btwdndis.sys
2008-12-26 01:58 37,424 a------- c:\windows\system32\drivers\btport.sys
2008-12-26 01:58 876,384 a------- c:\windows\system32\drivers\btkrnl.sys
2008-12-26 01:58 539,072 a------- c:\windows\system32\drivers\btaudio.sys
2008-12-26 01:57 <DIR> --d----- c:\program files\WIDCOMM
2008-12-26 01:57 1,520 -------- c:\windows\system32\Dean_KBD.ini
2008-12-26 01:57 0 a------- c:\windows\system32\drivers\144D_SAMSUNG_N_NC10_02CA.mrk
2008-12-26 01:56 <DIR> --d----- c:\documents and settings\Dean

==================== Find3M ====================

2008-12-26 16:22 76,487 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2008-11-11 23:37 319,488 a------- c:\windows\HideWin.exe
2008-11-11 23:30 21,640 a------- c:\windows\system32\emptyregdb.dat
2008-10-23 12:36 286,720 a------- c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 a------- c:\windows\system32\wininet.dll
2008-10-16 20:38 124,928 a------- c:\windows\system32\advpack(2).dll
2008-10-03 10:02 247,326 a------- c:\windows\system32\strmdll.dll
2008-09-30 16:43 1,286,152 a------- c:\windows\system32\msxml4.dll

============= FINISH: 12:36:05.65 ===============


Thanks for taking the time to help me guys, this is my friend's christmas present, I tried to install
Red Alert 2 for some ultimate retro-battling, but I needed win-ra so I downloaded it from
what appeared ( obviousley ) to be a kosher site, but unfortunately
as soon as it was installed I started getting a message in a small dialogue box saying:
Comaglia Comaglia Comaglia!!!
needless to say the first stage was googling the problem and low and behold i've been taken to
a site that looks like ( and most likely isn't ) a Microsoft help site.
Now I've done a system restore and that got rid of the pop up but whenever I try to google
or even use the goole taskbar, or youtube it directs me to the same foney looking site.
Please help!
( the model number incidentally is Samsung: NP-NC10 it's like a
glorified filofax but it's his )

Attached Files



BC AdBot (Login to Remove)

 


#2 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Staff Emeritus
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the &quot;Logic Free Zone&quot;, in Md, USA
  • Local time:02:08 AM

Posted 07 January 2009 - 03:26 PM

Hello and welcome to Bleeping Computer

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help.

If you have since resolved the original problem you were having, we would appreciate you letting us know. If not please perform the following steps below so we can have a look at the current condition of your machine. If you have not done so, include a description of your problem, along with any steps you may have performed so far.

Upon completing the steps below a staff member will review and take the steps necessary with you to get your machine back in working order clean and free of malware.


Thanks and again sorry for the delay.

We need to see some information about what is happening in your machine. Please perform the following scan:
  • Download DDS by sUBs from one of the following links. Save it to your desktop.
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet. Information on A/V control HERE

This may seem repetitive, but we need to see the current status of your system, please.
Please Hold on it may take us a day or so to get back with you.

R,
K
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)

#3 KoanYorel

KoanYorel

    Bleepin' Conundrum


  • Staff Emeritus
  • 19,461 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:65 miles due East of the &quot;Logic Free Zone&quot;, in Md, USA
  • Local time:02:08 AM

Posted 12 January 2009 - 09:31 AM

Due to the lack of feedback, this Topic is now closed.

If you still have problems, please Start a new topic.

R,
K
The only easy day was yesterday.

...some do, some don't; some will, some won't (WR)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users