Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Actions to take for Threats found by Avast


  • This topic is locked This topic is locked
10 replies to this topic

#1 Mifferette

Mifferette

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:01 AM

Posted 08 June 2011 - 03:24 PM

Hi,

Recently my computer has been running really slowly and when I try to open Taskmanger it says: "The application failed to initialize properly (0xc000012d). Click on OK to terminate the application."

When I try to open firefox the top part of the window will be missing along with text that should be appearing on the screen.When I reopen firefox after closing it, it say: "C;\Program Files\Mozilla Firefox\ xul.dull is not a valid Windows image. Please check this against your installation diskette"

Also, When I go to shut down my computer the START text will be missing and the icons for restart, shutdown, or logoff will be missing text. Even if I click on the icon the computer will not shut down So I have to force shutdown.

I am using Windows XP and I ran an ActiveScan with Panda, ran Malwarebytes Anti-Malware, and full Avast scans.
I have included the logs except MbAM because it did not detect anything.
I just do not know what actions to take for the infected files found with AVast! or how to fix these problems.

Thanks in advance!

;***********************************************************************************************************************************************************************************
ANALYSIS: 2011-06-06 17:16:43
PROTECTIONS: 1
MALWARE: 29
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
avast! Antivirus 5.0.100664421 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139059 Cookie/Traffic Marketplace TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@trafficmp[1].txt
00139060 Cookie/Casalemedia TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@casalemedia[2].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@doubleclick[5].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@doubleclick[3].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@doubleclick[1].txt
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@doubleclick[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@casbqogh.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@catdpwxs.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@catw55s0.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@carnc3y7.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@capy5yk8.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@canky3x2.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@calxixn1.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caiztmvo.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caiw1tym.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caiu316v.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caharz7l.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[10].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[11].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[2].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[3].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[4].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[5].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[6].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[7].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[8].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@atdmt[9].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cagwphgl.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cafsclki.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caf8kmnm.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca0dpsq7.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca0gcc9k.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca1k9al5.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca3uaj2z.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca5wfver.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca72azpl.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca8d9jn0.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ca9ahohp.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cab2knjg.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cae15k1v.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caeoo072.txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@caf0nlzn.txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@fastclick[2].txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@tribalfusion[1].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@mediaplex[2].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@mediaplex[3].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@mediaplex[4].txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@mediaplex[1].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@statcounter[2].txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ad.yieldmanager[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@apmebf[1].txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@apmebf[3].txt
00168076 Cookie/BurstNet TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@burstnet[2].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@serving-sys[2].txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@serving-sys[1].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@bs.serving-sys[3].txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@bs.serving-sys[2].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@server.iad.liveperson[2].txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@advertising[2].txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@ads.pointroll[1].txt
00171633 Cookie/Cgi-bin TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@www5.addfreestats[2].txt
00171633 Cookie/Cgi-bin TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@www5.addfreestats[1].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@questionmarket[3].txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@questionmarket[1].txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@zedo[1].txt
00665475 Exploit/ByteVerify HackTools No 0 Yes No c:\documents and settings\owner\application data\sun\java\deployment\cache\6.0\14\27ad8f8e-4c6779bf[op.class]
00685047 Trj/WMAdownloader.J Virus/Trojan No 0 Yes No c:\program files\limewire\downloaded files\birds emiliana torrini.wma
01692698 Generic Malware Virus/Trojan No 0 Yes No c:\documents and settings\owner\application data\macromedia\shockwave player\xtras\download\thegroovealliance\3dgroovextrav181\groove.x32
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{f845fc26-6de3-4ae1-9736-4d4e0b21edf7}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{e3cd591a-f032-4e08-9652-06564aaa5bc6}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{b228584a-8f0a-47b4-ad89-e03e750b8194}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{bce36ff1-7f8f-4323-9ea4-d7edd5d8f610}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{c5375310-d8da-4397-912e-f7ea936c3e6d}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{cbf4ed41-e8c4-4b30-8896-597df9d29d67}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{de2c9628-359a-4650-9cbe-70b09ed7f947}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{d35ba36d-d2b8-429e-a0c5-9fb238d9374f}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{eef0e9fb-f052-402f-b1d0-a3f37acec5a7}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{d312e2a5-00bc-45e0-a079-a65cdfe60487}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{ee2688cc-b90c-4f7e-b1df-9a7b8dea3da5}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{cec95ee4-7676-4a7a-a8ef-05d6bb5da70f}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{cc610592-9426-48c6-a504-7add9e494081}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{8b8a56d4-109e-45cf-81de-d230575a8f52}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{8a1581e0-2d9e-4f7d-a42b-d528c11c31e2}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{ea5b6e18-8848-4f82-8aad-6aeb5933be0e}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{890e03fa-2a06-4c67-994f-b47a7c43e03f}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{88caf390-0b93-45b4-8b40-3a1e7e39823e}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{07892c22-d429-45db-b161-b403c3b449bf}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{10b3f7eb-1eaf-4606-a7c7-183e32ba63f1}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{12832851-112b-4e65-8972-62bed0071695}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{1ec05171-2028-49e9-a699-4e43fde22877}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{21f09c54-f256-4427-9bc8-eb0b65701dc0}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{281cedae-f6f3-4af1-b72b-bd7fc5ed6aff}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{28c5838d-0e4a-4898-ad1c-b19b4092dbb4}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{2b6bff68-c2b2-43a5-bd69-e9be71820d06}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{2cfe86a2-7405-42ed-aef4-994441219883}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{3f5ba278-3f09-4ffe-8868-7578d33d9318}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{50e2e57b-ea44-48aa-b228-0db6d4bc42d4}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{5598ef85-a522-4d35-9ccc-57f815836313}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{570a1e8e-0765-4d39-8df4-8dfcbdd92c01}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{5846f5f3-76db-4005-a594-d77c3d6722d4}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{5ed1fea3-88b5-4d1f-babc-0bc3f1b209bc}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{68d76c5d-3a58-45f5-a64b-df42baeab027}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{6e9572d1-294d-47b5-9217-5497fb1f5b87}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{6fe4b9de-93bb-4c60-9edf-5424a2763b1e}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{70f7db9d-fd37-4342-8087-7631996832f7}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{7f60c799-97bd-4d4d-aef0-8d03da29c655}\zip.dll
02901059 Trj/Downloader.SPH Virus/Trojan No 1 Yes No c:\windows\installer\{84c16745-0dab-42c9-a6ac-e5bc1df9eadd}\zip.dll
02909975 Cookie/CookingLuck TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cookingluck[1].txt
02909975 Cookie/CookingLuck TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cookingluck[2].txt
02909975 Cookie/CookingLuck TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cookingluck[3].txt
02909975 Cookie/CookingLuck TrackingCookie No 0 Yes No c:\documents and settings\owner\cookies\owner@cookingluck[5].txt
02947949 Exploit/ByteVerify HackTools No 0 Yes No c:\documents and settings\owner\application data\sun\java\deployment\cache\6.0\1\21fb6c01-4b2333e3
02947949 Exploit/ByteVerify HackTools No 0 Yes No c:\documents and settings\owner\application data\sun\java\deployment\cache\6.0\33\40bf31a1-75da302b
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\9v5rmqla\vxs3oflpw7exd[1].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\9v5rmqla\vxs3oflpw7exd[2].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\9v5rmqla\w22sdzdxym[1].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\3ahcab9a\vxs3oflpw7exd[1].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\n3yh94zi\w22sdzdxym[1].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\n3yh94zi\vxs3oflpw7exd[1].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\n3yh94zi\4jdbs7bgrpo89q[1].htm
03009106 W32/Xor-encoded.A Virus No 0 Yes No c:\documents and settings\localservice\local settings\temporary internet files\content.ie5\dwimn3ae\w22sdzdxym[1].htm
03259749 Exploit/ASF.Gen Virus/Trojan No 0 Yes No c:\program files\limewire\downloaded files\grey's anatomy\see what you feel katalyst.mp3
03259749 Exploit/ASF.Gen Virus/Trojan No 0 Yes No c:\program files\limewire\downloaded files\grey's anatomy\only yesterday taken by trees.mp3
03541233 HackTool/Rebooter HackTools No 0 Yes No c:\documents and settings\owner\desktop\smitfraudfix\reboot.exe
03927291 Trj/Rebooter.J Virus/Trojan No 0 Yes No c:\documents and settings\owner\desktop\smitfraudfix.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================

Edited by hamluis, 08 June 2011 - 04:02 PM.
Moved to Am I Infected from XP.


BC AdBot (Login to Remove)

 


#2 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,702 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:03:01 AM

Posted 13 June 2011 - 10:33 PM

Hello.

Please try the following.

Please download fixexe.reg by Grinler to your Desktop. This utility will reverse changes to your system made by the infection.

Once downloaded, please execute the utility by double clicking on it. Windows will ask you if you wish to merge information with the Registry. You should allow it to do so.

***************************************************

Please try running MBAM this way.

Please download RKill by Grinler from one of the 4 links below and save it to your desktop.

Link 1
Link 2
Link 3
Link 4
  • Before we begin, you should disable any anti-malware software you have installed so it does not interfere with RKill running. This is because some anti-malware software mistakenly detects RKill as malicious. Please refer to this page if you are not sure how to disable your security software.
  • Double-click on Rkill on your desktop to run it. (If you are using Windows Vista, please right-click on it and select Run As Administrator)
  • A black screen will appear and then disappear. Please do not worry, that is normal. This means that the tool has been successfully executed.
  • If nothing happens or if the tool does not run, please let me know in your next reply

***************************************************

  • Make sure you are connected to the Internet.
  • Launch Malwarebytes' Anti-Malware
  • Click on the Update tab and click the button Check for Updates
  • If you encounter any problems while downloading the definition updates, manually download them from http://data.mbamupdates.com/tools/mbam-rules.exe'>here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
  • Make sure the "Perform Quick Scan" option is selected.
  • Then click on the Scan button.
  • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
  • The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
  • When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
  • Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
  • Click on the Show Results button to see a list of any malware that was found.
  • Make sure that everything is checked, and click Remove Selected.
  • When removal is completed, a log report will open in Notepad.
  • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
  • Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
  • Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

~Blade


In your next reply, please include the following:
Malwarebytes Log

Edited by Blade Zephon, 13 June 2011 - 10:33 PM.

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#3 Mifferette

Mifferette
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:01 AM

Posted 15 June 2011 - 10:13 AM

Hi,

I followed all the steps.

When I go to shut down, there's still no text underneath the logout, restart icons. But it does shut down without any other problems.
I'm also still getting this message "C:\WINDOWS\system32\rundll32.exe not enough quota is available to process this command", when I try to open display or add remove in the control panel. Can anything be done to fix this?

Mbam didn't find anything, but I still have quite a few quarantined items that were not deleted from a previous scan. Should I be concerned with this? Do I need to do anything with this?
Here's the Mbam log:

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6859

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

14/06/2011 11:54:17 PM
mbam-log-2011-06-14 (23-54-17).txt

Scan type: Quick scan
Objects scanned: 174890
Time elapsed: 11 minute(s), 45 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

#4 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,702 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:03:01 AM

Posted 15 June 2011 - 10:29 AM

Are you still getting the ""C;\Program Files\Mozilla Firefox\ xul.dull is not a valid Windows image. Please check this against your installation diskette"" message?

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#5 Mifferette

Mifferette
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:01 AM

Posted 15 June 2011 - 12:38 PM

Not exactly, firefox and my computer itself runs alright for about an hour to an hour and a half. Firefox closes and when I reopen it this message appears "The application failed to initalize properly (0xc0000142). Click on OK to terminate the application"
After this I tried to shut down but the computer wouldn't.

#6 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,702 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:03:01 AM

Posted 15 June 2011 - 04:11 PM

Hello.

Please run a Full Scan with Malwarebytes and see if it comes up with anything.

~Blade

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#7 Mifferette

Mifferette
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:01 AM

Posted 16 June 2011 - 10:45 AM

Hi,

I ran a full scan last night, when it was done I clicked on show results, but the page was blank even though there was apparently 6 infected files. There wasn't a log and it shut down on its own. I tried it again early this morning and after over 2 hrs of scanning I came back to the computer and it apparently shut down on its own. I couldn't click on anything on the screen but I could move the cursor around. I'm trying the scan again now, but I think the computer stops functioning after a couple of hrs.

#8 Mifferette

Mifferette
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:01 AM

Posted 16 June 2011 - 03:17 PM

Hi,

I ran a full Mbam scan. It didn't find anything this time, but when I had ran it last night there was 6 infected files, but I couldn't view what they were or remove them.

Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org

Database version: 6872

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

16/06/2011 3:15:59 PM
mbam-log-2011-06-16 (15-15-59).txt

Scan type: Full scan (C:\|)
Objects scanned: 278692
Time elapsed: 2 hour(s), 11 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

#9 Blade

Blade

    Strong in the Bleepforce


  • Site Admin
  • 12,702 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:US
  • Local time:03:01 AM

Posted 17 June 2011 - 04:15 AM

Hello.

Sorry to say that there's not much more we can do at this level.

It appears that the issues on your system will require a more in-depth examination than can be performed in this forum. Please read the information in this guide, and follow all the steps beginning with step 6. After you have followed the steps in that guide, I would like you to start a new thread HERE and include a link to this thread.

If you can produce at least some of the logs, then please create the new topic and explain what happens when you try to create the log(s) that you couldn't get. If you cannot produce any of the logs, then still post the topic and explain that you followed the Prep. Guide, were unable to create the logs, and describe what happens when you try to create the logs.

It would be helpful if you post a note here once you have completed the steps in the guide and have started your topic in malware removal. Good luck and be patient. The MRT is very busy, so it could be several days (3-5 days is the average wait right now) before you receive a reply. But rest assured, help is on the way!

~Blade

Posted Image

If I am helping you, it has been 48 hours since your last post, and I have yet to reply to your topic, please send me a PM
Become a BleepingComputer fan: Facebook
Follow us on Twitter!
Circle us on Google+


#10 Mifferette

Mifferette
  • Topic Starter

  • Members
  • 22 posts
  • OFFLINE
  •  
  • Gender:Female
  • Local time:03:01 AM

Posted 17 June 2011 - 07:35 PM

Hi

I followed all the guide steps without any problems and I posted in the other forum http://www.bleepingcomputer.com/forums/topic404516.html
along with the logs.

Thanks for all your help

#11 boopme

boopme

    To Insanity and Beyond


  • Global Moderator
  • 72,934 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:NJ USA
  • Local time:03:01 AM

Posted 17 June 2011 - 08:53 PM

Now that your log is properly posted, you should NOT make further changes to your computer (install/uninstall programs, use special fix tools, delete files, edit the registry, etc) unless advised by a Malware Removal Team member, nor should you continue to ask for help elsewhere. Doing so can result in system changes which may not show it the log you already posted. Further, any modifications you make on your own may cause confusion for the helper assisting you and could complicate the malware removal process which would extend the time it takes to clean your computer.

From this point on the Malware Removal Team should be the only members that you take advice from, until they have verified your log as clean.

Please be patient. It may take a while to get a response because the Malware Removal Team members are very busy working logs posted before yours. They are volunteers who will help you out as soon as possible. Once you have made your post and are waiting, please DO NOT make another reply until it has been responded to by a member of the Malware Removal Team. Generally the staff checks the forum for postings that have 0 replies as this makes it easier for them to identify those who have not been helped. If you post another response there will be 1 reply. A team member, looking for a new log to work may assume another MRL Team member is already assisting you and not open the thread to respond.

To avoid confusion, I am closing this top
How do I get help? Who is helping me?For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....Become a BleepingComputer fan: Facebook




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users