Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Am I still infected?


  • This topic is locked This topic is locked
23 replies to this topic

#1 ICKIER

ICKIER

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 24 June 2012 - 06:47 PM

At boopme's request, (here: http://www.bleepingcomputer.com/forums/topic457582.html/page__pid__2736408#entry2736408)
attached are my Combofix logs and DDS log.

Redirects appear to have stopped but system still acting a little funny.

Attached Files

  • Attached File  dds.txt   8.63KB   9 downloads
  • Attached File  log.txt   9.69KB   4 downloads
  • Attached File  log2.txt   8.61KB   4 downloads


BC AdBot (Login to Remove)

 


#2 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 29 June 2012 - 10:32 AM

Hello, Welcome to BleepingComputer.
I'm nasdaq and will be helping you.

If you can please print this topic it will make it easier for you to follow the instructions and complete all of the necessary steps.
===

Nothing suspicious was found on your logs.

Please run this security check for my review.

Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
===

Please let me know of any issues with this computer.

#3 ICKIER

ICKIER
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 29 June 2012 - 05:07 PM

Here's the results.
Not much here.

I was kinda hoping to hear there were some questionable items in the other logs. Seems to me there are.

Attached Files



#4 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 30 June 2012 - 08:02 AM

Fragmentation on Drive C:: 17% [color=red][b]Defragment your hard drive soon

When you can free you computer for a few hours take care of this.
===

I was kinda hoping to hear there were some questionable items in the other logs. Seems to me there are.

What is you concern?

#5 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 06 July 2012 - 09:45 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

#6 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 16 July 2012 - 12:52 PM

The topic is reopened.

Please post a DDS and a ComboFix log for my review.

#7 ICKIER

ICKIER
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 16 July 2012 - 10:36 PM

Defrag done.
As requested, DDS and Combofix logs attached.

If I reboot the omputer and open IE it wants to restore last session. Some files won't download (itunes only gets 147-176kb before thinking it's done - nowhere near the 76+mb it should be) I've cleared cache and the same thing happens.
If I click a hyperlink I hear the internal speaker beep and it does nothing. I click it again and it opens the link.
Zone Alarm reported while running DDS that MBR.DAT is trying to installa driver and gain full access to OS.
The folder Sytem Volume Information is 100% accessable!

Something's not right with this machine, I think.
Comments?

Attached Files


Edited by ICKIER, 16 July 2012 - 10:38 PM.


#8 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 17 July 2012 - 08:05 AM

The folder Sytem Volume Information is 100% accessable!


If you system is showing System File the folder will be viewed.

To Hide it reverse the first instructions on this microsotf page.


How to gain access to the System Volume Information folder
http://support.microsoft.com/kb/309531

===

If I click a hyperlink I hear the internal speaker beep and it does nothing. I click it again and it opens the link.


First thing you should do is check your mouse setting.

Troubleshoot mouse double-clicking when you single-click
http://support.microsoft.com/kb/266738

As for your download do you have any problem with smaller files?
Did you try a download Manager?

http://download.cnet.com/Internet-Download-Manager/3000-2071_4-10071618.html

Keep me posted.

#9 ICKIER

ICKIER
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 22 July 2012 - 05:08 PM

Looking back up the System Volume Folder doesn't help me understand why it's open.
It's not my mouse settings. It just started doing this when the redirects started.
I was able to stop those but still have the little issues. Any download I try seems to work.
It's just Apple itunes! (well so far) I even tried the uk site of apple...same thing.
I am able to download it off oldapps.com. But when I clicked on that link, IE beeped at me 3 times before it went to the page!
I would rather try to figure out why this is happening before installing a download manager.
That's just something else to muck up a system.

Are my logs not showing any clues?

Edited by ICKIER, 22 July 2012 - 05:12 PM.


#10 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 23 July 2012 - 09:18 AM

Install Microsoft Security Essentials

http://windows.microsoft.com/en-US/windows/products/security-essentials

When running disable ZoneAlarm and try your downloads.

Any change?

#11 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 29 July 2012 - 09:37 AM

Are you still with me?

#12 ICKIER

ICKIER
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 29 July 2012 - 12:11 PM

Are you still with me?

Yes, sorry. I will run that this weekend and get back to you.

#13 ICKIER

ICKIER
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 01 August 2012 - 04:08 PM

Tried to download MS Security Essentials and ZA quickly said it was done and scanning, said it was fine. Tried to open, not a valid Win32 file.
Same thing I got with itunes. Shut down ZA rebooted without it at startup, same thing. Download ended just after it started, only saving a 87kb file.

I tried running oldtimer's TFC and it hangs at closeing applications.

Something's is still up with this machine. And still no hint from reading my logs?

#14 nasdaq

nasdaq

  • Malware Response Team
  • 39,578 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:01:15 AM

Posted 02 August 2012 - 08:02 AM

I'd like us to scan your machine with ESET OnlineScan
  • Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  • Click the Posted Image button.
  • For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    • Click on Posted Image to download the ESET Smart Installer. Save it to your desktop.
    • Double click on the Posted Image icon on your desktop.
  • Check Posted Image
  • Click the Posted Image button.
  • Accept any security warnings from your browser.
  • Check Posted Image
  • Push the Start button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes, push Posted Image
  • Push Posted Image, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  • Push the Posted Image button.
  • Push Posted Image

Please download Farbar Service Scanner and run it on the computer with the issue.
  • Make sure the following options are checked:
    [list]
  • Internet Services
  • Windows Firewall
  • System Restore
  • Security Center/Action center
  • Windows Update
  • Windows Defender
[*]Press "Scan".
[*]It will create a log (FSS.txt) in the same directory the tool is run.

#15 ICKIER

ICKIER
  • Topic Starter

  • Members
  • 33 posts
  • OFFLINE
  •  
  • Local time:01:15 AM

Posted 03 August 2012 - 08:56 PM

Here are the results. I'm not so sure I agree with Nero being a virus. It's a direct copy from an install CD that came bundled with my drive.
Please let me know what you think.

Comments on why TFC won't get past the stopping applications screen and start deleting temp files?

Attached Files






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users