Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

FBI MoneyPak Removal


  • This topic is locked This topic is locked
8 replies to this topic

#1 tj78492

tj78492

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:39 AM

Posted 25 November 2012 - 12:18 PM

Parents computer affected by the fbi ransomware any help would be awesome

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 23-11-2012
Ran by SYSTEM at 25-11-2012 12:04:40
Running from H:\
Windows 7 Home Premium (X64) OS Language: English(US)
The current controlset is ControlSet001

==================== Registry (Whitelisted) ===================

HKLM\...\Run: [MSC] "c:\Program Files\Microsoft Security Client\mssecex.exe" -hide -runkey [x]
HKLM\...\Run: [LogMeIn GUI] "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe" [57928 2011-09-16] (LogMeIn, Inc.)
HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe" [87336 2010-10-01] (CyberLink Corp.)
HKLM-x32\...\Run: [PDVD9LanguageShortcut] "C:\Program Files (x86)\CyberLink\PowerDVD9\Language\Language.exe" [50472 2010-09-17] (CyberLink Corp.)
HKLM-x32\...\Run: [] [x]
HKLM-x32\...\Run: [RoxWatchTray] "C:\Program Files (x86)\Common Files\Roxio Shared\OEM\12.0\SharedCOM\RoxWatchTray12OEM.exe" [240112 2010-11-25] (Sonic Solutions)
HKLM-x32\...\Run: [Desktop Disc Tool] "C:\Program Files (x86)\Roxio\OEM\Roxio Burn\RoxioBurnLauncher.exe" [514544 2010-11-17] ()
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [843712 2012-04-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [254696 2011-06-09] (Sun Microsystems, Inc.)
HKU\Family\...\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe" /MINIMIZED [879984 2012-04-28] (BitTorrent, Inc.)
HKU\Family\...\Run: [Spotify Web Helper] "C:\Users\Family\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [1193176 2012-10-04] ()
HKU\Family\...\Run: [SpeedUpMyPC] "C:\Program Files (x86)\Uniblue\SpeedUpMyPC\launcher.exe" -d 20000 [68504 2012-07-08] (Uniblue Systems Ltd)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 71.252.0.12
AppInit_DLLs: C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\datamngr.dll C:\PROGRA~2\IMESHA~1\MediaBar\Datamngr\x64\IEBHO.dll
Startup: C:\Users\All Users\Start Menu\Programs\Startup\Subsonic.lnk
ShortcutTarget: Subsonic.lnk -> C:\Program Files (x86)\Subsonic\subsonic-agent.exe ()

==================== Services (Whitelisted) ===================

2 LMIGuardianSvc; "C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe" [375728 2012-11-06] (LogMeIn, Inc.)
2 LMIMaint; "C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe" [147888 2012-11-06] (LogMeIn, Inc.)
2 LogMeIn; "C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe" [407424 2011-09-16] (LogMeIn, Inc.)
2 MsMpSvc; "C:\Program Files\Microsoft Security Client\MsMpEng.exe" [22072 2012-09-12] (Microsoft Corporation)
3 NisSrv; "C:\Program Files\Microsoft Security Client\NisSrv.exe" [368896 2012-09-12] (Microsoft Corporation)
2 Subsonic; C:\Program Files (x86)\Subsonic\subsonic-service.exe [215040 2012-09-12] ()

==================== Drivers (Whitelisted) =====================

1 A2DDA; \??\C:\Users\Family\Downloads\EmsisoftEmergencyKit\Run\a2ddax64.sys [23208 2012-11-24] (Emsi Software GmbH)
2 LMIInfo; \??\C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [15928 2011-09-16] (LogMeIn, Inc.)
0 MpFilter; C:\Windows\System32\Drivers\MpFilter.sys [228768 2012-08-30] (Microsoft Corporation)
2 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [128456 2012-08-30] (Microsoft Corporation)
1 atogatex; \??\C:\Windows\system32\drivers\atogatex.sys [x]
3 catchme; \??\C:\ComboFix\catchme.sys [x]
1 dgstepbb; \??\C:\Windows\system32\drivers\dgstepbb.sys [x]
4 LMIRfsClientNP; [x]

==================== NetSvcs (Whitelisted) ====================


==================== One Month Created Files and Folders ========

2012-11-25 08:34 - 2012-11-25 08:34 - 00000000 ____D C:\32788R22FWJFW
2012-11-25 08:32 - 2012-11-25 08:32 - 00000000 ____D C:\FRST
2012-11-25 08:04 - 2012-11-25 08:05 - 00907994 ____A (Farbar) C:\Users\Family\Downloads\FRST.exe
2012-11-25 07:59 - 2012-11-25 07:59 - 00000000 ____D C:\Users\Family\Downloads\mbar-1.01.0.1009
2012-11-25 07:58 - 2012-11-25 07:58 - 12961620 ____A C:\Users\Family\Downloads\mbar-1.01.0.1009.zip
2012-11-25 06:14 - 2012-11-25 06:14 - 00480125 ____A C:\Users\Family\Downloads\adwcleaner(1).exe
2012-11-25 06:14 - 2012-11-25 06:14 - 00001474 ____A C:\AdwCleaner[R1].txt
2012-11-25 06:10 - 2012-11-25 06:10 - 00895464 ____A (Oracle Corporation) C:\Users\Family\Downloads\jxpiinstall.exe
2012-11-25 00:06 - 2012-07-25 20:55 - 00785512 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys
2012-11-25 00:06 - 2012-07-25 20:55 - 00054376 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys
2012-11-25 00:06 - 2012-07-25 18:36 - 00009728 ____A (Microsoft Corporation) C:\Windows\System32\Wdfres.dll
2012-11-25 00:06 - 2012-06-02 06:35 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
2012-11-25 00:02 - 2012-10-08 04:19 - 17811968 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2012-11-25 00:02 - 2012-10-08 03:42 - 10925568 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2012-11-25 00:02 - 2012-10-08 03:31 - 02312704 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2012-11-25 00:02 - 2012-10-08 03:24 - 01346048 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2012-11-25 00:02 - 2012-10-08 03:23 - 01392128 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2012-11-25 00:02 - 2012-10-08 03:22 - 01494528 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2012-11-25 00:02 - 2012-10-08 03:22 - 00237056 ____A (Microsoft Corporation) C:\Windows\System32\url.dll
2012-11-25 00:02 - 2012-10-08 03:20 - 00085504 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2012-11-25 00:02 - 2012-10-08 03:18 - 00173056 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2012-11-25 00:02 - 2012-10-08 03:17 - 00816640 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2012-11-25 00:02 - 2012-10-08 03:17 - 00599040 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2012-11-25 00:02 - 2012-10-08 03:15 - 02144768 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2012-11-25 00:02 - 2012-10-08 03:15 - 00729088 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2012-11-25 00:02 - 2012-10-08 03:13 - 02382848 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2012-11-25 00:02 - 2012-10-08 03:13 - 00096768 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2012-11-25 00:02 - 2012-10-08 03:09 - 00248320 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2012-11-25 00:02 - 2012-10-08 00:28 - 12320768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2012-11-25 00:02 - 2012-10-08 00:02 - 09738240 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2012-11-25 00:02 - 2012-10-07 23:56 - 01800704 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2012-11-25 00:02 - 2012-10-07 23:48 - 01129472 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2012-11-25 00:02 - 2012-10-07 23:48 - 01103872 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2012-11-25 00:02 - 2012-10-07 23:47 - 01427968 ____A (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2012-11-25 00:02 - 2012-10-07 23:46 - 00231936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2012-11-25 00:02 - 2012-10-07 23:45 - 00065024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2012-11-25 00:02 - 2012-10-07 23:44 - 00142848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2012-11-25 00:02 - 2012-10-07 23:43 - 00717824 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2012-11-25 00:02 - 2012-10-07 23:43 - 00420864 ____A (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2012-11-25 00:02 - 2012-10-07 23:42 - 00607744 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2012-11-25 00:02 - 2012-10-07 23:41 - 01793024 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2012-11-25 00:02 - 2012-10-07 23:41 - 00073216 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2012-11-25 00:02 - 2012-10-07 23:40 - 02382848 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2012-11-25 00:02 - 2012-10-07 23:37 - 00176640 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2012-11-25 00:00 - 2012-07-25 19:08 - 00744448 ____A (Microsoft Corporation) C:\Windows\System32\WUDFx.dll
2012-11-25 00:00 - 2012-07-25 19:08 - 00229888 ____A (Microsoft Corporation) C:\Windows\System32\WUDFHost.exe
2012-11-25 00:00 - 2012-07-25 19:08 - 00194048 ____A (Microsoft Corporation) C:\Windows\System32\WUDFPlatform.dll
2012-11-25 00:00 - 2012-07-25 19:08 - 00084992 ____A (Microsoft Corporation) C:\Windows\System32\WUDFSvc.dll
2012-11-25 00:00 - 2012-07-25 19:08 - 00045056 ____A (Microsoft Corporation) C:\Windows\System32\WUDFCoinstaller.dll
2012-11-25 00:00 - 2012-07-25 18:26 - 00198656 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFRd.sys
2012-11-25 00:00 - 2012-07-25 18:26 - 00087040 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\WUDFPf.sys
2012-11-25 00:00 - 2012-06-02 06:57 - 00000003 ____A C:\Windows\System32\Drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
2012-11-24 18:32 - 2012-10-09 10:17 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcore6.dll
2012-11-24 18:32 - 2012-10-09 10:17 - 00055296 ____A (Microsoft Corporation) C:\Windows\System32\dhcpcsvc6.dll
2012-11-24 18:32 - 2012-10-09 09:40 - 00193536 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcore6.dll
2012-11-24 18:32 - 2012-10-09 09:40 - 00044032 ____A (Microsoft Corporation) C:\Windows\SysWOW64\dhcpcsvc6.dll
2012-11-24 18:32 - 2012-09-25 14:47 - 00078336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\synceng.dll
2012-11-24 18:32 - 2012-09-25 14:46 - 00095744 ____A (Microsoft Corporation) C:\Windows\System32\synceng.dll
2012-11-24 18:31 - 2012-10-18 10:25 - 03149824 ____A (Microsoft Corporation) C:\Windows\System32\win32k.sys
2012-11-24 18:30 - 2012-10-03 09:56 - 01914248 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2012-11-24 18:30 - 2012-10-03 09:44 - 00303104 ____A (Microsoft Corporation) C:\Windows\System32\nlasvc.dll
2012-11-24 18:30 - 2012-10-03 09:44 - 00246272 ____A (Microsoft Corporation) C:\Windows\System32\netcorehc.dll
2012-11-24 18:30 - 2012-10-03 09:44 - 00216576 ____A (Microsoft Corporation) C:\Windows\System32\ncsi.dll
2012-11-24 18:30 - 2012-10-03 09:44 - 00070656 ____A (Microsoft Corporation) C:\Windows\System32\nlaapi.dll
2012-11-24 18:30 - 2012-10-03 09:44 - 00018944 ____A (Microsoft Corporation) C:\Windows\System32\netevent.dll
2012-11-24 18:30 - 2012-10-03 09:42 - 00569344 ____A (Microsoft Corporation) C:\Windows\System32\iphlpsvc.dll
2012-11-24 18:30 - 2012-10-03 08:42 - 00175104 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netcorehc.dll
2012-11-24 18:30 - 2012-10-03 08:42 - 00156672 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ncsi.dll
2012-11-24 18:30 - 2012-10-03 08:42 - 00018944 ____A (Microsoft Corporation) C:\Windows\SysWOW64\netevent.dll
2012-11-24 18:30 - 2012-10-03 08:07 - 00045568 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpipreg.sys
2012-11-24 18:30 - 2012-01-12 23:12 - 00052224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2012-11-24 16:00 - 2012-11-24 16:01 - 00587372 ____A C:\Users\Family\Downloads\Leader System Center for Upgrade_20120106153228.apk
2012-11-24 14:26 - 2012-11-24 14:26 - 00010121 ____A C:\ComboFix.txt
2012-11-24 14:21 - 2011-06-25 22:45 - 00256000 ____A C:\Windows\PEV.exe
2012-11-24 14:21 - 2010-11-07 09:20 - 00208896 ____A C:\Windows\MBR.exe
2012-11-24 14:21 - 2009-04-19 20:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe
2012-11-24 14:21 - 2000-08-30 16:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe
2012-11-24 14:21 - 2000-08-30 16:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe
2012-11-24 14:21 - 2000-08-30 16:00 - 00098816 ____A C:\Windows\sed.exe
2012-11-24 14:21 - 2000-08-30 16:00 - 00080412 ____A C:\Windows\grep.exe
2012-11-24 14:21 - 2000-08-30 16:00 - 00068096 ____A C:\Windows\zip.exe
2012-11-24 14:20 - 2012-11-24 14:26 - 00000000 ____D C:\Windows\erdnt
2012-11-24 14:20 - 2012-11-24 14:26 - 00000000 ____D C:\Qoobox
2012-11-24 14:19 - 2012-11-25 08:34 - 05006177 ____A (Swearware) C:\Users\Family\Downloads\ComboFix.exe
2012-11-24 13:38 - 2012-11-24 13:43 - 00002120 ____A C:\scu.dat
2012-11-24 13:30 - 2012-11-24 13:30 - 02322184 ____A (ESET) C:\Users\Family\Downloads\esetsmartinstaller_enu.exe
2012-11-24 13:30 - 2012-11-24 13:30 - 00001953 ____A C:\Users\Family\Documents\aswMBR.txt
2012-11-24 13:30 - 2012-11-24 13:30 - 00000512 ____A C:\Users\Family\Documents\MBR.dat
2012-11-24 13:30 - 2012-11-24 13:30 - 00000000 ____D C:\Program Files (x86)\ESET
2012-11-24 12:44 - 2012-11-24 12:45 - 04732416 ____A (AVAST Software) C:\Users\Family\Downloads\aswMBR.exe
2012-11-24 12:41 - 2012-11-24 12:41 - 00002203 ____A C:\Users\Family\Desktop\RKreport[3]_D_11242012_02d1541.txt
2012-11-24 12:41 - 2012-11-24 12:41 - 00001291 ____A C:\Users\Family\Desktop\RKreport[4]_S_11242012_02d1541.txt
2012-11-24 12:38 - 2012-11-24 12:38 - 00002269 ____A C:\Users\Family\Desktop\RKreport[2]_S_11242012_02d1538.txt
2012-11-24 12:37 - 2012-11-24 12:40 - 00000000 ____D C:\Users\Family\Desktop\RK_Quarantine
2012-11-24 12:37 - 2012-11-24 12:37 - 00002232 ____A C:\Users\Family\Desktop\RKreport[1]_S_11242012_02d1537.txt
2012-11-24 12:36 - 2012-11-24 12:36 - 01461039 ____A (Farbar) C:\Users\Family\Downloads\FRST64.exe
2012-11-24 12:34 - 2012-11-24 12:35 - 00752128 ____A C:\Users\Family\Downloads\RogueKiller.exe
2012-11-24 12:33 - 2012-11-24 12:33 - 00881863 ____A C:\Users\Family\Downloads\SecurityCheck.exe
2012-11-24 12:08 - 2012-11-24 12:09 - 00000000 ____D C:\Users\All Users\HitmanPro
2012-11-24 12:08 - 2012-11-24 12:08 - 09105176 ____A (SurfRight B.V.) C:\Users\Family\Downloads\HitmanPro36_x64.exe
2012-11-24 12:07 - 2012-11-24 12:08 - 02213976 ____A (Kaspersky Lab ZAO) C:\Users\Family\Downloads\tdsskiller.exe
2012-11-24 11:49 - 2012-11-24 11:49 - 00480125 ____A C:\Users\Family\Downloads\adwcleaner.exe
2012-11-24 11:49 - 2012-11-24 11:49 - 00011475 ____A C:\AdwCleaner[S1].txt
2012-11-24 11:42 - 2012-11-24 11:42 - 00001115 ____A C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2012-11-24 11:42 - 2012-11-24 11:42 - 00000000 ____D C:\Users\Family\AppData\Roaming\Malwarebytes
2012-11-24 11:42 - 2012-11-24 11:42 - 00000000 ____D C:\Users\All Users\Malwarebytes
2012-11-24 11:42 - 2012-11-24 11:42 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2012-11-24 11:42 - 2012-09-29 16:54 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys
2012-11-24 11:41 - 2012-11-24 11:41 - 10669952 ____A (Malwarebytes Corporation ) C:\Users\Family\Downloads\mbam-setup-1.65.1.1000.exe
2012-11-24 08:47 - 2012-11-24 08:47 - 00000000 ____D C:\Users\Family\Downloads\EmsisoftEmergencyKit
2012-11-24 08:03 - 2012-11-24 08:43 - 249414067 ____A C:\Users\Family\Downloads\EmsisoftEmergencyKit.zip
2012-11-21 16:52 - 2012-11-21 16:52 - 00000000 ____D C:\Users\All Users\353CC
2012-11-19 13:25 - 2012-11-19 13:25 - 00001087 ____A C:\Users\Family\Desktop\MX300 series - Shortcut.lnk
2012-11-18 06:42 - 2012-11-18 06:42 - 00000000 ____D C:\Windows\Sun
2012-11-16 17:08 - 2012-11-16 17:08 - 00014390 ____A C:\Users\Family\Downloads\loan-details.htm
2012-11-16 17:08 - 2012-11-16 17:08 - 00000000 ____D C:\Users\Family\Downloads\loan-details_files
2012-11-15 17:40 - 2012-11-15 17:40 - 00000000 ____D C:\Program Files (x86)\toolbar2
2012-11-05 09:21 - 2012-11-06 12:14 - 00000000 ____D C:\Users\All Users\A4EE7555006EAB830000A4EDD06BB003


==================== One Month Modified Files and Folders =======

2012-11-25 08:44 - 2012-04-28 17:10 - 00000000 ____D C:\Users\Family\AppData\Roaming\uTorrent
2012-11-25 08:43 - 2009-07-13 20:45 - 00020880 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2012-11-25 08:43 - 2009-07-13 20:45 - 00020880 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2012-11-25 08:39 - 2012-04-04 14:28 - 01252194 ____A C:\Windows\WindowsUpdate.log
2012-11-25 08:39 - 2009-07-13 21:13 - 00727182 ____A C:\Windows\System32\PerfStringBackup.INI
2012-11-25 08:38 - 2009-07-13 20:51 - 00042438 ____A C:\Windows\setupact.log
2012-11-25 08:35 - 2012-04-28 14:03 - 00074856 ____A C:\Users\Family\AppData\Local\GDIPFONTCACHEV1.DAT
2012-11-25 08:34 - 2012-11-25 08:34 - 00000000 ____D C:\32788R22FWJFW
2012-11-25 08:34 - 2012-11-24 14:19 - 05006177 ____A (Swearware) C:\Users\Family\Downloads\ComboFix.exe
2012-11-25 08:32 - 2012-11-25 08:32 - 00000000 ____D C:\FRST

BC AdBot (Login to Remove)

 


#2 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:39 AM

Posted 25 November 2012 - 02:37 PM

Greetings and Welcome to The Forums!!

My name is Gringo and I'll be glad to help you with your malware problems.

I have put together somethings for you to keep in mind while I am helping you to make things go easier and faster for both of us

  • Please do not run any tools unless instructed to do so.
    • We ask you to run different tools in a specific order to ensure the malware is completely removed from your machine, and running any additional tools may detect false positives, interfere with our tools, or cause unforeseen damage or system instability.
  • Please do not attach logs or use code boxes, just copy and paste the text.
    • Due to the high volume of logs we receive it helps to receive everything in the same format, and code boxes make the logs very difficult to read. Also, attachments require us to download and open the reports when it is easier to just read the reports in your post.
  • Please read every post completely before doing anything.
    • Pay special attention to the NOTE: lines, these entries identify an individual issue or important step in the cleanup process.
  • Please provide feedback about your experience as we go.
    • A short statement describing how the computer is working helps us understand where to go next, for example: I am still getting redirected, the computer is running normally, etc. Please do not describe the computer as "the same", this requires the extra step of looking back at your previous post.
NOTE: At the top of your post, click on the Watch Topic Button, select Immediate Notification, and click on Proceed. This will send you an e-mail as soon as I reply to your topic, allowing us to resolve the issue faster.

NOTE: Backup any files that cannot be replaced. Removing malware can be unpredictable and this step can save a lot of heartaches if things don't go as planed. You can put them on a CD/DVD, external drive or a pen drive, anywhere except on the computer.

NOTE: It is good practice to copy and paste the instructions into notepad and print them in case it is necessary for you to go offline during the cleanup process. To open notepad, navigate to Start Menu > All Programs > Accessories > Notepad. Please remember to copy the entire post so you do not miss any instructions.




These are the programs I would like you to run next, if you have any problems with these just skip it and run the next one.

-Security Check-

  • Download Security Check by screen317 from here.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

-AdwCleaner-

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Delete.
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

--RogueKiller--

  • Download & SAVE to your Desktop RogueKiller or from here
  • Quit all programs that you may have started.
  • Please disconnect any USB or external drives from the computer before you run this scan!
  • For Vista or Windows 7, right-click and select "Run as Administrator to start"
  • For Windows XP, double-click to start.
  • Wait until Prescan has finished ...
  • Then Click on "Scan" button
  • Wait until the Status box shows "Scan Finished"
  • click on "delete"
  • Wait until the Status box shows "Deleting Finished"
  • Click on "Report" and copy/paste the content of the Notepad into your next reply.
  • The log should be found in RKreport[1].txt on your Desktop
  • Exit/Close RogueKiller+

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#3 tj78492

tj78492
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:39 AM

Posted 25 November 2012 - 04:52 PM

Security Check
Results of screen317's Security Check version 0.99.56  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 9  
[b][u]``````````````Antivirus/Firewall Check:``````````````[/b][/u] 
 [color=red][b]Windows Security Center service is not running! This report may not be accurate![/b][/color] 
 Windows Firewall Enabled!  
Microsoft Security Essentials   
 Antivirus up to date!  
[b][u]`````````Anti-malware/Other Utilities Check:`````````[/b][/u] 
 Malwarebytes Anti-Malware version 1.65.1.1000  
 Java(TM) 6 Update 27  
 [color=red][b]Java version out of Date![/b][/color] 
 Adobe Reader 10.1.3 [color=red][b]Adobe Reader out of Date![/b][/color]  
 Mozilla Firefox 15.0.1 [color=red][b]Firefox out of Date![/b][/color]  
[b][u]````````Process Check: objlist.exe by Laurent````````[/b][/u]  
 Microsoft Security Essentials MSMpEng.exe 
[b][u]`````````````````System Health check`````````````````[/b][/u] 
 Total Fragmentation on Drive C:  
[b][u]````````````````````End of Log``````````````````````[/b][/u]

ADW:
# AdwCleaner v2.009 - Logfile created 11/25/2012 at 16:15:44
# Updated 24/11/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Family - FAMILY
# Boot Mode : Safe mode with networking
# Running from : C:\Users\Family\Downloads\adwcleaner(1).exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****

Key Deleted : HKLM\Software\BabylonToolbar

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Mozilla Firefox v15.0.1 (en-US)

Profile name : default 
File : C:\Users\Family\AppData\Roaming\Mozilla\Firefox\Profiles\jxxiip79.default\prefs.js

Deleted : user_pref("extensions.claro.bbDpng", "25");
Deleted : user_pref("extensions.claro.cntry", "US");
Deleted : user_pref("extensions.claro.envrmnt", "production");
Deleted : user_pref("extensions.claro.hdrMd5", "");
Deleted : user_pref("extensions.claro.hmpg", false);
Deleted : user_pref("extensions.claro.lastVrsnTs", "");
Deleted : user_pref("extensions.claro.mntrvrsn", "1.3.1");
Deleted : user_pref("extensions.claro.newTab", false);
Deleted : user_pref("extensions.claro.sg", "free");
Deleted : user_pref("extensions.claro.smplGrp", "free");

*************************

AdwCleaner[R1].txt - [1474 octets] - [25/11/2012 09:14:18]
AdwCleaner[S1].txt - [11475 octets] - [24/11/2012 14:49:56]
AdwCleaner[S2].txt - [1427 octets] - [25/11/2012 16:15:44]

########## EOF - C:\AdwCleaner[S2].txt - [1487 octets] ##########

RK:
RogueKiller V8.3.1 [Nov 23 2012] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : Family [Admin rights]
Mode : Remove -- Date : 11/25/2012 16:49:24

 Bad processes : 0 

 Registry Entries : 3 
[RUN][ROGUE ST] HKCU\[...]\Run : SpeedUpMyPC ("C:\Program Files (x86)\Uniblue\SpeedUpMyPC\launcher.exe" -d 20000 ) -> DELETED
[HJPOL] HKCU\[...]\System : disableregistrytools (0) -> DELETED
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> DELETED

 Particular Files / Folders: 

 Driver : [NOT LOADED] 

 HOSTS File: 
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1       localhost


 MBR Check: 

+++++ PhysicalDrive0: ST31000524AS ATA Device +++++
--- User ---
[MBR] e907fc98a39c2f00b29d51e26484ac2e
[BSP] 08a809d453217df6855f4cb488f43d03 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 939867 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 1924849664 | Size: 14000 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[6]_D_11252012_02d1649.txt >>
RKreport[1]_S_11242012_02d1537.txt ; RKreport[2]_S_11242012_02d1538.txt ; RKreport[3]_D_11242012_02d1541.txt ; RKreport[4]_S_11242012_02d1541.txt ; RKreport[5]_S_11252012_02d1648.txt ; 
RKreport[6]_D_11252012_02d1649.txt




Thanks for your assistance

#4 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:39 AM

Posted 26 November 2012 - 07:12 AM

Hello

I Would like you to do the following.

Please print out or make a copy in notpad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Run Combofix:

You may be asked to install or update the Recovery Console (Win XP Only) if this happens please allow it to do so (you will need to be connected to the internet for this)

Before you run Combofix I will need you to turn off any security software you have running, If you do not know how to do this you can find out >here< or >here<

Combofix may need to reboot your computer more than once to do its job this is normal.

You can download Combofix from one of these links. I want you to save it to the desktop and run it from there.
Link 1
Link 2
Link 3
1. Close any open browsers or any other programs that are open.
2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.

Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall

Note 2: If you recieve an error "Illegal operation attempted on a registery key that has been marked for deletion." Please restart the computer

"information and logs"

  • In your next post I need the following
  • Log from Combofix
  • let me know of any problems you may have had
  • How is the computer doing now?

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#5 tj78492

tj78492
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:02:39 AM

Posted 26 November 2012 - 11:19 AM

Ran in safe mode, once finished the FBI warning popped up again (from safemode, which normally doesn't happen)

Here are the results:
[co]ComboFix 12-11-26.02 - Family 11/26/2012 10:56:07.2.4 - x64 NETWORK
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8105.7109 [GMT -5:00]
Running from: c:\users\Family\Downloads\ComboFix.exe
AV: Microsoft Security Essentials *Enabled/Updated* {B140BF4E-23BB-4198-90AB-A51A4C60A69C}
SP: Microsoft Security Essentials *Enabled/Updated* {0A215EAA-0581-4E16-AA1B-9E6837E7EC21}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((( Files Created from 2012-10-26 to 2012-11-26 )))))))))))))))))))))))))))))))
.
.
2012-11-26 16:00 . 2012-11-26 16:00 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp
2012-11-26 16:00 . 2012-11-26 16:00 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-11-25 21:57 . 2012-11-25 21:57 -------- d-----w- c:\users\Family\AppData\Roaming\Macrovision
2012-11-25 21:57 . 2012-11-25 21:57 -------- d-----w- c:\users\Family\AppData\Local\Sonic_Solutions
2012-11-25 16:36 . 2012-11-25 16:36 76232 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{78C51B93-C0D3-4E36-93BD-E691ED213562}\offreg.dll
2012-11-25 16:32 . 2012-11-25 16:32 -------- d-----w- C:\FRST
2012-11-25 08:06 . 2012-07-26 04:47 2560 ----a-w- c:\windows\system32\drivers\en-US\wdf01000.sys.mui
2012-11-25 08:06 . 2012-07-26 04:55 785512 ----a-w- c:\windows\system32\drivers\Wdf01000.sys
2012-11-25 08:06 . 2012-07-26 04:55 54376 ----a-w- c:\windows\system32\drivers\WdfLdr.sys
2012-11-25 08:06 . 2012-07-26 02:36 9728 ----a-w- c:\windows\system32\Wdfres.dll
2012-11-25 08:00 . 2012-07-26 03:08 84992 ----a-w- c:\windows\system32\WUDFSvc.dll
2012-11-25 08:00 . 2012-07-26 03:08 194048 ----a-w- c:\windows\system32\WUDFPlatform.dll
2012-11-25 08:00 . 2012-07-26 02:26 87040 ----a-w- c:\windows\system32\drivers\WUDFPf.sys
2012-11-25 08:00 . 2012-07-26 02:26 198656 ----a-w- c:\windows\system32\drivers\WUDFRd.sys
2012-11-25 08:00 . 2012-07-26 03:08 229888 ----a-w- c:\windows\system32\WUDFHost.exe
2012-11-25 08:00 . 2012-07-26 03:08 744448 ----a-w- c:\windows\system32\WUDFx.dll
2012-11-25 08:00 . 2012-07-26 03:08 45056 ----a-w- c:\windows\system32\WUDFCoinstaller.dll
2012-11-25 07:00 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{78C51B93-C0D3-4E36-93BD-E691ED213562}\mpengine.dll
2012-11-25 02:33 . 2012-11-08 17:24 9125352 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-11-25 02:32 . 2012-09-25 22:47 78336 ----a-w- c:\windows\SysWow64\synceng.dll
2012-11-25 02:32 . 2012-09-25 22:46 95744 ----a-w- c:\windows\system32\synceng.dll
2012-11-25 02:32 . 2012-10-09 18:17 55296 ----a-w- c:\windows\system32\dhcpcsvc6.dll
2012-11-25 02:32 . 2012-10-09 18:17 226816 ----a-w- c:\windows\system32\dhcpcore6.dll
2012-11-25 02:32 . 2012-10-09 17:40 193536 ----a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-11-25 02:32 . 2012-10-09 17:40 44032 ----a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-11-25 02:31 . 2012-10-18 18:25 3149824 ----a-w- c:\windows\system32\win32k.sys
2012-11-25 02:30 . 2012-10-03 17:56 1914248 ----a-w- c:\windows\system32\drivers\tcpip.sys
2012-11-25 02:30 . 2012-10-03 17:44 303104 ----a-w- c:\windows\system32\nlasvc.dll
2012-11-25 02:30 . 2012-10-03 17:44 246272 ----a-w- c:\windows\system32\netcorehc.dll
2012-11-25 02:30 . 2012-10-03 17:44 216576 ----a-w- c:\windows\system32\ncsi.dll
2012-11-25 02:30 . 2012-10-03 17:42 569344 ----a-w- c:\windows\system32\iphlpsvc.dll
2012-11-25 02:30 . 2012-10-03 16:42 156672 ----a-w- c:\windows\SysWow64\ncsi.dll
2012-11-25 02:30 . 2012-10-03 16:42 175104 ----a-w- c:\windows\SysWow64\netcorehc.dll
2012-11-25 02:30 . 2012-10-03 16:07 45568 ----a-w- c:\windows\system32\drivers\tcpipreg.sys
2012-11-25 02:30 . 2012-01-13 07:12 52224 ----a-w- c:\windows\SysWow64\nlaapi.dll
2012-11-25 02:30 . 2012-10-03 17:44 70656 ----a-w- c:\windows\system32\nlaapi.dll
2012-11-25 02:30 . 2012-10-03 17:44 18944 ----a-w- c:\windows\system32\netevent.dll
2012-11-25 02:30 . 2012-10-03 16:42 18944 ----a-w- c:\windows\SysWow64\netevent.dll
2012-11-24 22:26 . 2012-11-26 16:00 -------- d-----w- c:\users\Family\AppData\Local\temp
2012-11-24 21:30 . 2012-11-24 21:30 -------- d-----w- c:\program files (x86)\ESET
2012-11-24 20:08 . 2012-11-24 20:09 -------- d-----w- c:\programdata\HitmanPro
2012-11-24 19:42 . 2012-11-24 19:42 -------- d-----w- c:\users\Family\AppData\Roaming\Malwarebytes
2012-11-24 19:42 . 2012-11-24 19:42 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-11-24 19:42 . 2012-11-24 19:42 -------- d-----w- c:\programdata\Malwarebytes
2012-11-24 19:42 . 2012-09-30 00:54 25928 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-11-22 00:52 . 2012-11-22 00:52 -------- d-----w- c:\programdata\353CC
2012-11-18 14:42 . 2012-11-18 14:42 -------- d-----w- c:\windows\Sun
2012-11-16 01:40 . 2012-11-16 01:40 -------- d-----w- c:\program files (x86)\toolbar2
2012-11-05 17:21 . 2012-11-06 20:14 -------- d-----w- c:\programdata\A4EE7555006EAB830000A4EDD06BB003
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-11-06 10:23 . 2012-04-29 00:22 35240 ----a-w- c:\windows\system32\LMIport.dll
2012-11-06 10:23 . 2012-04-29 00:22 88008 ----a-w- c:\windows\system32\LMIRfsClientNP.dll
2012-11-06 10:23 . 2012-04-29 00:22 83880 ----a-w- c:\windows\system32\LMIinit.dll
2012-10-02 07:11 . 2012-10-20 17:02 972192 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{2019E6F0-16D6-430B-9840-14DB31C34395}\gapaengine.dll
2012-10-02 07:11 . 2012-06-13 02:40 972192 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\NISBackup\gapaengine.dll
2012-09-14 19:19 . 2012-10-10 16:20 2048 ----a-w- c:\windows\system32\tzres.dll
2012-09-14 18:28 . 2012-10-10 16:20 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2012-08-31 18:19 . 2012-10-10 16:20 1659760 ----a-w- c:\windows\system32\drivers\ntfs.sys
2012-08-31 02:03 . 2012-08-31 02:03 228768 ----a-w- c:\windows\system32\drivers\MpFilter.sys
2012-08-31 02:03 . 2012-03-21 00:44 128456 ----a-w- c:\windows\system32\drivers\NisDrvWFP.sys
2012-08-30 18:03 . 2012-10-10 16:20 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-30 17:12 . 2012-10-10 16:20 3968880 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-30 17:12 . 2012-10-10 16:20 3914096 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-21 . 9D56FE29A0C99A83CE22EF16381D5E92 . 861696 . . [6.1.7601.17514] .. c:\windows\SysWOW64\user32.dll
[7] 2010-11-21 . 5E0DB2D8B2750543CD2EBB9EA8E6CDD3 . 833024 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-user32_31bf3856ad364e35_6.1.7601.17514_none_35b31c02b85ccb6e\user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.0.1 71.252.0.12
FF - ProfilePath - c:\users\Family\AppData\Roaming\Mozilla\Firefox\Profiles\jxxiip79.default\
FF - ExtSQL: 2012-11-15 20:40; {348bd83c-b2cd-4319-a605-c96bb458dd80}; c:\users\Family\AppData\Roaming\Mozilla\Firefox\Profiles\jxxiip79.default\extensions\{348bd83c-b2cd-4319-a605-c96bb458dd80}
FF - ExtSQL: !HIDDEN! 2012-08-24 22:42; {1FD91A9C-410C-4090-BBCC-55D3450EF433}; c:\program files (x86)\iMesh Applications\MediaBar\Datamngr\FirefoxExtension
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-{6DA399FC-350F-41AC-8CA6-B9F8496753BE}_is1 - c:\program files (x86)\Media Finder\unins000.exe
AddRemove-{8FB495A1-4A3F-4C1D-BD27-3F3AB2E66763} - c:\programdata\{B1148819-B88A-4DDE-A988-CA8093A887F4}\iMesh_V11_en_Setup.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-11-26 11:01:32
ComboFix-quarantined-files.txt 2012-11-26 16:01
ComboFix2.txt 2012-11-24 22:26
.
Pre-Run: 647,859,376,128 bytes free
Post-Run: 647,848,497,152 bytes free
.
- - End Of File - - 23ACD504498A51ED0329CC85562CA54E
[/code]

Edited by gringo_pr, 26 November 2012 - 04:25 PM.


#6 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:39 AM

Posted 26 November 2012 - 04:26 PM

Hello

Lets get a deeper look into the system and see if something shows up.

Download and run OTL

Download OTL by Old Timer and save it to your Desktop.
  • Double click on OTL.exe to run it.
  • Under Output, ensure that Minimal Output is selected.
  • Under Extra Registry section, select Use SafeList.
  • Click the Scan All Users checkbox.
  • Click on Run Scan at the top left hand corner.
  • When done, two Notepad files will open.
    • OTL.txt <-- Will be opened and the that I need posted back here
    • Extra.txt <-- Will be minimized - save this one on your desktop in case I ask for it later
  • Please post the contents of OTL.txt in your next reply.

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#7 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:39 AM

Posted 30 November 2012 - 09:22 AM

Greetings


I have not heard from you in a couple of days so I am coming by to check on you to see if you are having problems or you just need some more time.

Also to remind you that it is very important that we finish the process completely so as to not get reinfected. I will let you know when we are complete and I will ask to remove our tools




Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#8 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:39 AM

Posted 02 December 2012 - 11:51 PM

Hello

48 Hour bump

It has been more than 48 hours since my last post.

  • do you still need help with this?
  • do you need more time?
  • are you having problems following my instructions?
  • if after 48hrs you have not replied to this thread then it will have to be closed!

Gringo
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University

#9 gringo_pr

gringo_pr

    Bleepin Gringo


  • Malware Response Team
  • 136,772 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Puerto rico
  • Local time:03:39 AM

Posted 08 December 2012 - 01:59 AM

Due to the lack of feedback, this topic is now closed.In the event you still have problems, please send me or any Moderator a Private Message and ask them to reopen this topic within the next 5 days. Please include a link to your topic in the Private Message. Thank you.
I Close My Topics If You Have Not Replied In 5 Days If You Will Be Longer Please Let Me Know

If I Have Not Replied To One Of My Topics In 48 Hrs Please Bump The Topic



My help is free, however, if you wish to make a small donation to show your appreciation or to help me continue the fight against Malware, then click here -->btn_donate_SM.gif<-- Don't worry every little bit helps.

Proud Graduate Of Malware Removal University




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users