Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Trojan:Win32/Sirefef.O


  • This topic is locked This topic is locked
4 replies to this topic

#1 kronski

kronski

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:04 AM

Posted 27 October 2011 - 03:22 AM

Hi, I would welcome any help that can be provided as my PC has contracted a big problem!

- When using google in browsers the search terms redirect to ad sites. While loading, the term "colossalsearch.com loading" or similar, appears in the browser.

- All anti-virus software programs have been affected. AVG no longer works, the trojan appears to have disabled the program. I've tried to download again and install but it cannot install. Malwarebytes only works in safe mode. I've tried to download avast free software but this does not work.
- Spybot works and identifies about 10 files which I keep removing but they come back.
- PC has gone extremely slow.

- Windows defender identified the virus as "Trojan:Win32/Sirefef.O".

- I tried to run GMER as instructed and it loaded but when I tried to scan, it seemed to disappear. When I tried to run again, it came up with the message "Windows cannot access the specified device, path or file. You may not have appropriate permissions to access the item".
- I'm currently in safe mode with networking.
-Logs attached below.

Thanks in advance for any help!

.
DDS (Ver_2011-08-26.01) - NTFSx86 NETWORK
Internet Explorer: 8.0.6001.19154 BrowserJavaVersion: 1.6.0_17
Run by Mark at 9:00:58 on 2011-10-27
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2045.1219 [GMT 1:00]
.
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: Lavasoft Ad-Watch Live! *Disabled/Updated* {61CDFD9D-3CAC-9270-C6FC-52325ACB795B}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\993469364:1272760516.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Users\Beetle\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\explorer.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.co.uk/ig/dell?hl=en&client=dell-usuk&channel=uk&ibd=0071015
uWindow Title = Internet Explorer provided by Dell
uURLSearchHooks: N/A: {28c14585-7e7c-43be-86fe-6528c1b19132} - c:\program files\mywebfaceie_2w\bar\1.bin\2wSrcAs.dll
mURLSearchHooks: H - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Search Assistant BHO: {37794d6d-2547-4cce-858f-1fd1dd8951fc} - c:\program files\mywebfaceie_2w\bar\1.bin\2wSrcAs.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\program files\spybot - search & destroy\SDHelper.dll
BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.2.4204.1700\swg.dll
BHO: Toolbar BHO: {c3e257db-debf-40a9-9eef-a9ebd6991cb0} - c:\progra~1\mywebf~2\bar\1.bin\2wbar.dll
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
TB: myWebFace: {dfa6f716-6499-4a36-ad6a-c9a98cce1eb7} - c:\program files\mywebfaceie_2w\bar\1.bin\2wbar.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - c:\program files\avast software\avast\aswWebRepIE.dll
TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File
uRun: [<NO NAME>]
uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
uRun: [Google Update] "c:\users\mark\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [<NO NAME>]
mRun: [ZoneAlarm Client] "c:\program files\zone labs\zonealarm\zlclient.exe"
mRun: [RtHDVCpl] RtHDVCpl.exe
mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
mRun: [PAC7332_Monitor] c:\windows\pixart\pac7332\GUCI_AVS.exe
mRun: [IntelliPoint] "c:\program files\microsoft intellipoint\ipoint.exe"
mRun: [itype] "c:\program files\microsoft intellitype pro\itype.exe"
mRun: [avast] "c:\program files\avast software\avast\avastUI.exe" /nogui
dRunOnce: [AutoLaunch] c:\program files\lavasoft\ad-aware\AutoLaunch.exe monthly
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\program files\spybot - search & destroy\SDHelper.dll
LSP: mswsock.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
TCP: DhcpNameServer = 192.168.1.254
TCP: Interfaces\{5C0004D0-F555-4E5D-8576-DD0175648705} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{65DB8BDE-B470-4ACF-9122-CD3D4E3145C0} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{8639BA37-2633-4482-9251-A685A91CA96F} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{910EDE45-6DDB-4EB0-A5D7-86382631FB91} : DhcpNameServer = 192.168.1.254
TCP: Interfaces\{925A36DA-1445-461C-BD59-508747CD6F41} : DhcpNameServer = 192.168.1.254
Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Notify: GoToAssist - c:\program files\citrix\gotoassist\480\G2AWinLogon.dll
SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
mASetup: ccc-core-static - msiexec /fums {65E6362A-B878-4A7B-86DA-D16F8DBD75C7} /qb
.
================= FIREFOX ===================
.
FF - ProfilePath - c:\users\mark\appdata\roaming\mozilla\firefox\profiles\9576rgtw.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.hattrick.org/|http://www.google.co.uk/webhp?sa=N&tab=lw
FF - component: c:\program files\mozilla firefox\extensions\{82af8dca-6de9-405d-bd5e-43525bdad38a}\components\SkypeFfComponent.dll
FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\program files\google\google updater\2.4.2432.1652\npCIDetect14.dll
FF - plugin: c:\program files\google\picasa3\npPicasa2.dll
FF - plugin: c:\program files\google\picasa3\npPicasa3.dll
FF - plugin: c:\program files\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\google\update\1.3.21.53\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.57\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.65\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\program files\mozilla firefox\plugins\npmidas.dll
FF - plugin: c:\program files\veetle\player\npvlc.dll
FF - plugin: c:\program files\veetle\plugins\npVeetle.dll
FF - plugin: c:\users\mark\appdata\local\google\update\1.3.21.79\npGoogleUpdate3.dll
FF - plugin: c:\users\mark\appdata\roaming\mozilla\firefox\profiles\9576rgtw.default\extensions\devicedetection@logitech.com\plugins\npLogitechDeviceDetection.dll
FF - Ext: PsicoTSI: {7E77F5DF-8022-40e3-9122-F03DEBEFC43B} - %profile%\extensions\{7E77F5DF-8022-40e3-9122-F03DEBEFC43B}
FF - Ext: Adblock Plus: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} - %profile%\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
FF - Ext: Property Bee: {da8bd68d-8e90-41cd-8345-a71b294e72e6} - %profile%\extensions\{da8bd68d-8e90-41cd-8345-a71b294e72e6}
FF - Ext: DownloadHelper: {b9db16a4-6edc-47ec-a1f4-b86292ed211d} - %profile%\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
FF - Ext: FoxTrick: {9d1f059c-cada-4111-9696-41a62d64e3ba} - %profile%\extensions\{9d1f059c-cada-4111-9696-41a62d64e3ba}
FF - Ext: HTLiveSight: {469b7d40-de9a-11e0-9572-0800200c9a66} - %profile%\extensions\{469b7d40-de9a-11e0-9572-0800200c9a66}
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Skype extension: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\mozilla firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF - Ext: avast! WebRep: wrc@avast.com - c:\program files\avast software\avast\webrep\FF
.
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - true
============= SERVICES / DRIVERS ===============
.
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-2-1 64160]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-26 442200]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2011-10-26 320856]
S1 RapportCerberus_32029;RapportCerberus_32029;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\32029\RapportCerberus32_32029.sys [2011-10-9 227312]
S1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2011-9-25 70416]
S1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2011-9-25 161936]
S2 AERTFilters;Andrea RT Filters Service;c:\windows\system32\AERTSrv.exe [2007-12-5 77824]
S2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2011-10-26 20568]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2011-10-26 54616]
S2 avast! Antivirus;avast! Antivirus;c:\program files\avast software\avast\AvastSvc.exe [2011-10-26 44768]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-17 21504]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-5-20 136176]
S2 myWebFaceIE_2wService;myWebFace Service;c:\progra~1\mywebf~2\bar\1.bin\2wbarsvc.exe [2011-3-25 36864]
S2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2011-9-25 919352]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2009-2-6 1153368]
S3 athrusb;Atheros Wireless LAN USB device driver;c:\windows\system32\drivers\athrusb.sys [2008-7-29 904192]
S3 GUCI_AVS;USB UVC VGA;c:\windows\system32\drivers\GUCI_AVS.sys [2011-5-6 574208]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-20 136176]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-1-18 1036104]
S3 MSHUSBVideo;NX6000/NX3000/VX2000/VX5000/VX5500/VX7000/Cinema Filter Driver;c:\windows\system32\drivers\nx6000.sys [2010-5-20 30576]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2011-10-27 07:06:18 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-10-27 06:56:54 56200 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{01b683ba-ad8d-427f-aff9-10b0912b6188}\offreg.dll
2011-10-27 06:56:53 48016 --sha-w- c:\windows\system32\c_98883.nl_
2011-10-26 22:56:55 -------- d-----w- c:\users\mark\appdata\roaming\Malwarebytes
2011-10-26 22:56:39 -------- d-----w- c:\programdata\Malwarebytes
2011-10-26 22:56:36 22216 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-10-26 22:56:36 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-10-26 22:04:24 442200 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2011-10-26 22:04:22 54616 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2011-10-26 22:03:34 41184 ----a-w- c:\windows\avastSS.scr
2011-10-26 22:03:08 -------- d-----w- c:\programdata\AVAST Software
2011-10-26 22:03:08 -------- d-----w- c:\program files\AVAST Software
2011-10-26 20:38:18 -------- d--h--w- C:\$AVG
2011-10-26 19:06:38 -------- d--h--w- c:\programdata\Common Files
2011-10-26 19:06:08 -------- d-----w- c:\programdata\MFAData
2011-10-26 12:25:13 -------- d-sh--w- c:\windows\system32\%APPDATA%
2011-10-26 07:34:06 6144 ----a-w- c:\program files\internet explorer\iecompat.dll
2011-10-25 07:43:09 6668624 ----a-w- c:\programdata\microsoft\windows defender\definition updates\{01b683ba-ad8d-427f-aff9-10b0912b6188}\mpengine.dll
2011-10-13 18:21:38 2043392 ----a-w- c:\windows\system32\win32k.sys
2011-10-13 18:21:35 293376 ----a-w- c:\windows\system32\psisdecd.dll
2011-10-13 18:21:35 217088 ----a-w- c:\windows\system32\psisrndr.ax
2011-10-13 18:21:34 69632 ----a-w- c:\windows\system32\Mpeg2Data.ax
2011-10-13 18:21:34 57856 ----a-w- c:\windows\system32\MSDvbNP.ax
2011-10-13 18:21:31 2409784 ----a-w- c:\program files\windows mail\OESpamFilter.dat
2011-10-13 18:19:51 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-10-13 18:19:51 555520 ----a-w- c:\windows\system32\UIAutomationCore.dll
2011-10-13 18:19:51 4096 ----a-w- c:\windows\system32\oleaccrc.dll
2011-10-13 18:19:51 238080 ----a-w- c:\windows\system32\oleacc.dll
2011-10-10 18:38:04 -------- d-----w- c:\users\mark\appdata\roaming\InfraRecorder
2011-10-10 18:37:53 -------- d-----w- c:\program files\InfraRecorder
.
==================== Find3M ====================
.
2011-10-26 22:44:28 72192 ----a-w- c:\windows\system32\drivers\tdx.sys
2011-10-24 07:20:28 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-09-30 23:06:24 916480 ----a-w- c:\windows\system32\wininet.dll
2011-09-30 23:02:06 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-09-30 23:01:51 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2011-09-30 23:01:34 71680 ----a-w- c:\windows\system32\iesetup.dll
2011-09-30 23:01:34 109056 ----a-w- c:\windows\system32\iesysprep.dll
2011-09-30 22:07:25 385024 ----a-w- c:\windows\system32\html.iec
2011-09-30 21:29:54 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2011-09-30 21:28:36 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2011-09-25 18:00:08 56336 ----a-w- c:\windows\system32\drivers\RapportKELL.sys
2011-09-23 19:23:56 1409 ----a-w- c:\windows\QTFont.for
2011-08-10 15:39:48 396136 ----a-w- c:\windows\system32\itpcoin82.dll
2011-08-01 14:56:42 40936 ----a-w- c:\windows\system32\drivers\point32.sys
2011-08-01 14:56:42 395624 ----a-w- c:\windows\system32\ipcoin82.dll
2011-08-01 14:56:42 1461992 ----a-w- c:\windows\system32\wdfcoinstaller01009.dll
.
============= FINISH: 9:02:51.87 ===============

BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:04 AM

Posted 29 October 2011 - 10:26 AM

Hello and Welcome to the forums!

My name is Gringo and I'll be glad to help you with your computer problems.

Somethings to remember while we are working together.

  • Do not run any other tool untill instructed to do so!
  • please Do not Attach logs or put in code boxes.
  • Tell me about any problems that have occurred during the fix.
  • Tell me of any other symptoms you may be having as these can help also.
  • Do not run anything while running a fix.
  • Do not run any other tool untill instructed to do so!


Click on the Watch Topic Button and select Immediate Notification and click on proceed, this will help you to get notified faster when I have replied and make the cleaning process faster.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 kronski

kronski
  • Topic Starter

  • Members
  • 2 posts
  • OFFLINE
  •  
  • Local time:07:04 AM

Posted 29 October 2011 - 11:15 AM

Hi Gringo,

Thanks for your reply. I've actually reinstalled Vista now, as my computer had been ultra slow for a while now anyway (so it seemed like the right thing to do). It seemed to have solved the problem (fingers crossed) so I won't need your help at this time. Thanks anyway for your reply. I guess that this thread can now be deleted/closed?

Thanks Kronski

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:04 AM

Posted 29 October 2011 - 06:35 PM

Thanks for letting me know


I will leave this open for a couple of days in case you have any questions


gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:04 AM

Posted 01 November 2011 - 12:43 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users