Jump to content

Recommended Posts

  • Replies 5
  • Created
  • Last Reply

Top Posters In This Topic

Top Posters In This Topic

Posted

Hello Elaine,

 

Please download Malwarebytes' Anti-Malware by clicking the link below:

Malwarebytes Anti-Malware - Reviews and free Malwarebytes Anti-Malware downloads at Download.com

 

Double Click mbam-setup.exe to install the application.

 

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.

* If an update is found, it will download and install the latest version.

* Once the program has loaded, select "Perform Quick Scan", then click Scan.

* The scan may take some time to finish,so please be patient.

* When the scan is complete, click OK, then Show Results to view the results.

* Make sure that everything is checked, and click Remove Selected.

* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)

* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

* You'll be required to post the contents of this log later.

 

Please Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediately.

 

 

 

Next let's have you download ComboFix.exe. Please visit this webpage for downloading and instructions for running the tool:

 

Go here ======> A guide and tutorial on using ComboFix <====== Go here

 

Please ensure you read this guide carefully and install the Recovery Console first.This applies to XP Pro and XP Home users only.If you have SP3 installed you will need to use the download meant for SP2.

 

The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

 

Once installed, you should get a prompt that says:

 

The Recovery Console was successfully installed.

 

Please continue as follows:

 

(1) Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

(2) Click Yes to allow ComboFix to continue scanning for malware.

 

When the tool is finished, it will produce a report for you.

 

 

Please include the MBAM log and C:\ComboFix.txt for further review, so that we may continue cleansing the system.

 

 

Caution: Never run and remove files with Combofix unless supervised by a qualified security analyst who is experienced in the use of Combofix. Misuse can cause serious computer problems.

Posted

I cant open the first programme to copy the log i keep getting

"Illegal operation attempted on a registry key that has been marked for deletion"

I struggled to open IE too cause of same error message out of 4 shortcuts only 1 would open :-(

 

ComboFix 09-10-30.01 - Elaine 01/11/2009 20:19.1.2 - NTFSx86

Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.3034.1275 [GMT 0:00]

Running from: c:\users\Elaine\Desktop\ComboFix.exe

SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\$recycle.bin\S-1-5-21-2773397201-2855733099-4214572315-500

c:\$recycle.bin\S-1-5-21-3447794830-991531250-2897983773-500

c:\program files\SpeedBit Video Downloader\Toolbar\tbhelper.dll

c:\windows\system32\oem5.inf

.

((((((((((((((((((((((((( Files Created from 2009-10-01 to 2009-11-01 )))))))))))))))))))))))))))))))

.

2009-11-01 20:56 . 2009-11-01 20:56 -------- d-----w- c:\users\Lorraine\AppData\Local\temp

2009-11-01 20:56 . 2009-11-01 20:56 -------- d-----w- c:\users\Guest\AppData\Local\temp

2009-11-01 20:56 . 2009-11-01 20:56 -------- d-----w- c:\users\Default\AppData\Local\temp

2009-11-01 20:56 . 2009-11-01 20:56 -------- d-----w- c:\users\Rachel\AppData\Local\temp

2009-11-01 20:19 . 2008-09-01 10:15 317976 ----a-w- c:\windows\system32\drivers\iastor.sys

2009-11-01 19:19 . 2009-11-01 19:19 -------- d-----w- c:\users\Elaine\AppData\Roaming\Malwarebytes

2009-11-01 19:19 . 2009-09-10 14:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2009-11-01 19:19 . 2009-11-01 19:19 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2009-11-01 19:19 . 2009-11-01 19:19 -------- d-----w- c:\programdata\Malwarebytes

2009-11-01 19:19 . 2009-09-10 14:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-11-01 16:22 . 2009-11-01 16:22 -------- d-----w- c:\windows\system32\EventProviders

2009-10-28 10:46 . 2009-09-10 15:21 310784 ----a-w- c:\windows\system32\unregmp2.exe

2009-10-28 10:46 . 2009-09-10 15:21 8147456 ----a-w- c:\windows\system32\wmploc.DLL

2009-10-19 20:30 . 2009-10-19 20:31 -------- d-----w- c:\users\Guest\AppData\Roaming\Epson

2009-10-17 23:07 . 2009-10-17 23:07 -------- d-----w- c:\program files\MWSnap

2009-10-16 21:29 . 2009-10-16 21:29 -------- d-----w- c:\users\Elaine 2\AppData\Roaming\Yahoo!

2009-10-16 21:22 . 2009-10-16 21:22 -------- d-----w- c:\users\Elaine 2\AppData\Roaming\TweetDeckFast.F9107117265DB7542C1A806C8DB837742CE14C21.1

2009-10-16 21:17 . 2009-10-16 21:17 -------- d-----w- c:\users\Elaine 2\AppData\Roaming\Symantec

2009-10-16 21:17 . 2009-10-16 21:17 -------- d-----w- c:\users\Elaine 2\AppData\Local\PowerDVD DX

2009-10-16 21:17 . 2009-10-30 22:04 -------- d-----w- c:\users\Elaine 2\AppData\Local\Google

2009-10-16 21:17 . 2009-10-16 21:17 -------- d-----w- c:\users\Elaine 2\AppData\Roaming\Epson

2009-10-16 21:17 . 2009-10-16 21:17 -------- d-----w- c:\users\Elaine 2\AppData\Local\SupportSoft

2009-10-14 19:43 . 2009-09-10 17:30 213504 ----a-w- c:\windows\system32\msv1_0.dll

2009-10-14 19:42 . 2009-08-27 05:17 71680 ----a-w- c:\windows\system32\iesetup.dll

2009-10-14 19:42 . 2009-09-04 12:24 61440 ----a-w- c:\windows\system32\msasn1.dll

2009-10-14 19:42 . 2009-09-14 09:44 144896 ----a-w- c:\windows\system32\drivers\srv2.sys

2009-10-14 19:42 . 2009-04-02 12:37 604672 ----a-w- c:\windows\system32\WMSPDMOD.DLL

2009-10-13 23:54 . 2009-10-13 23:54 -------- d-----w- c:\windows\Sun

2009-10-13 23:48 . 2009-10-13 23:48 -------- d-----w- c:\programdata\McAfee Security Scan

2009-10-13 23:34 . 2009-10-13 23:34 -------- d-----w- c:\users\Elaine\AppData\Local\{7148F0A6-6813-11D6-A77B-00B0D0142050}

2009-10-03 11:23 . 2009-10-01 10:29 195440 ------w- c:\windows\system32\MpSigStub.exe

2009-10-03 11:16 . 2009-08-07 02:24 44768 ----a-w- c:\windows\system32\wups2.dll

2009-10-03 11:16 . 2009-08-07 02:24 53472 ----a-w- c:\windows\system32\wuauclt.exe

2009-10-03 11:16 . 2009-08-07 01:45 2421760 ----a-w- c:\windows\system32\wucltux.dll

2009-10-03 11:16 . 2009-08-07 02:23 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-10-03 11:16 . 2009-08-07 02:24 35552 ----a-w- c:\windows\system32\wups.dll

2009-10-03 11:16 . 2009-08-07 02:23 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-10-03 11:16 . 2009-08-07 01:44 87552 ----a-w- c:\windows\system32\wudriver.dll

2009-10-03 11:16 . 2009-08-06 18:23 171608 ----a-w- c:\windows\system32\wuwebv.dll

2009-10-03 11:16 . 2009-08-06 17:44 33792 ----a-w- c:\windows\system32\wuapp.exe

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2009-11-01 13:40 . 2009-04-28 20:39 -------- d-----w- c:\users\Lorraine.Millie\AppData\Roaming\Spotify

2009-10-31 12:50 . 2009-05-07 18:12 -------- d-----w- c:\users\Elaine\AppData\Roaming\Spotify

2009-10-23 23:14 . 2009-01-18 23:02 -------- d-----w- c:\users\Elaine\AppData\Roaming\uTorrent

2009-10-20 19:06 . 2009-09-15 23:05 -------- d-----w- c:\users\Elaine\AppData\Roaming\vlc

2009-10-19 23:01 . 2009-09-21 23:23 -------- d-----w- c:\program files\TweetDeck

2009-10-19 20:30 . 2009-01-13 16:50 101856 ----a-w- c:\users\Guest\AppData\Local\GDIPFONTCACHEV1.DAT

2009-10-18 17:31 . 2009-02-20 16:04 -------- d-----w- c:\users\Rachel\AppData\Roaming\vlc

2009-10-18 17:27 . 2009-06-19 21:01 -------- d-----w- c:\users\Rachel\AppData\Roaming\dvdcss

2009-10-16 21:25 . 2009-04-19 22:59 -------- d-----w- c:\program files\Common Files\Adobe AIR

2009-10-16 21:16 . 2009-10-16 21:16 -------- d-----w- c:\users\Elaine 2\AppData\Roaming\Dell

2009-10-16 21:16 . 2009-10-16 21:16 101856 ----a-w- c:\users\Elaine 2\AppData\Local\GDIPFONTCACHEV1.DAT

2009-10-16 04:46 . 2008-11-14 10:26 -------- d-----w- c:\programdata\McAfee

2009-10-15 10:06 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail

2009-10-15 00:04 . 2009-01-08 21:00 -------- d-----w- c:\programdata\Microsoft Help

2009-10-13 23:38 . 2008-11-14 10:21 -------- d-----w- c:\program files\Java

2009-10-13 21:45 . 2008-11-14 10:25 -------- d-----w- c:\program files\Google

2009-09-28 21:23 . 2009-09-28 21:23 -------- d-----w- c:\users\Rachel\AppData\Roaming\Yahoo!

2009-09-28 21:20 . 2009-02-12 15:00 101856 ----a-w- c:\users\Rachel\AppData\Local\GDIPFONTCACHEV1.DAT

2009-09-26 11:02 . 2009-01-06 14:34 101856 ----a-w- c:\users\Elaine\AppData\Local\GDIPFONTCACHEV1.DAT

2009-09-26 10:45 . 2009-09-26 10:45 -------- d-----w- c:\users\Lorraine.Millie\AppData\Roaming\Yahoo!

2009-09-26 10:42 . 2009-01-06 16:10 101856 ----a-w- c:\users\Lorraine.Millie\AppData\Local\GDIPFONTCACHEV1.DAT

2009-09-25 23:40 . 2008-11-14 10:24 -------- d-----w- c:\program files\Common Files\Adobe

2009-09-25 23:34 . 2009-04-16 20:35 -------- d-----w- c:\users\Elaine\AppData\Roaming\Amazon

2009-09-25 23:34 . 2009-03-31 21:24 -------- d-----w- c:\program files\Amazon

2009-09-25 23:31 . 2009-09-25 23:31 -------- d-----w- c:\program files\Yahoo!

2009-09-25 23:31 . 2009-09-25 23:31 -------- d-----w- c:\users\Elaine\AppData\Roaming\Yahoo!

2009-09-25 23:31 . 2009-09-25 23:31 -------- d-----w- c:\programdata\Yahoo! Companion

2009-09-20 23:06 . 2009-09-20 23:05 -------- d-----w- c:\users\Elaine\AppData\Roaming\Epson

2009-09-20 21:59 . 2009-09-20 21:59 -------- d-----w- c:\users\Lorraine.Millie\AppData\Roaming\Epson

2009-09-20 19:05 . 2009-09-20 19:04 -------- d-----w- c:\users\Rachel\AppData\Roaming\Epson

2009-09-20 13:38 . 2009-09-20 13:21 -------- d-----w- c:\programdata\EPSON

2009-09-20 13:34 . 2009-09-20 13:34 -------- d-----w- c:\programdata\UDL

2009-09-20 13:33 . 2009-09-20 13:29 -------- d-----w- c:\program files\Epson Software

2009-09-20 13:33 . 2008-11-14 10:21 -------- d--h--w- c:\program files\InstallShield Installation Information

2009-09-20 13:30 . 2009-09-20 13:19 -------- d-----w- c:\program files\epson

2009-09-20 13:28 . 2009-09-20 13:28 -------- d-----w- c:\program files\ABBYY FineReader 6.0 Sprint

2009-09-20 13:25 . 2009-09-20 13:25 -------- d-----w- c:\users\Elaine\AppData\Roaming\InstallShield

2009-09-15 23:08 . 2009-07-19 21:45 -------- d-----w- c:\users\Elaine\AppData\Roaming\dvdcss

2009-09-14 22:39 . 2009-02-23 22:39 -------- d-----w- c:\users\Lorraine.Millie\AppData\Roaming\dvdcss

2009-09-08 00:27 . 2009-01-11 21:56 -------- d-----w- c:\users\Elaine\AppData\Roaming\Skype

2009-09-07 23:18 . 2009-01-11 21:58 -------- d-----w- c:\users\Elaine\AppData\Roaming\skypePM

2009-08-31 13:55 . 2009-10-14 19:43 293376 ----a-w- c:\windows\system32\psisdecd.dll

2009-08-31 13:55 . 2009-10-14 19:43 428544 ----a-w- c:\windows\system32\EncDec.dll

2009-08-28 12:39 . 2009-09-02 22:32 28672 ----a-w- c:\windows\system32\Apphlpdm.dll

2009-08-28 10:15 . 2009-09-02 22:32 4240384 ----a-w- c:\windows\system32\GameUXLegacyGDFs.dll

2009-08-27 05:22 . 2009-10-14 19:43 916480 ----a-w- c:\windows\system32\wininet.dll

2009-08-27 05:17 . 2009-10-14 19:43 109056 ----a-w- c:\windows\system32\iesysprep.dll

2009-08-27 03:42 . 2009-10-14 19:43 133632 ----a-w- c:\windows\system32\ieUnatt.exe

2009-08-17 22:33 . 2009-08-17 22:33 1193832 ----a-w- c:\windows\system32\FM20.DLL

2009-08-14 17:07 . 2009-09-09 12:22 897608 ----a-w- c:\windows\system32\drivers\tcpip.sys

2009-08-14 16:29 . 2009-09-09 12:22 104960 ----a-w- c:\windows\system32\netiohlp.dll

2009-08-14 16:29 . 2009-09-09 12:22 17920 ----a-w- c:\windows\system32\netevent.dll

2009-08-14 14:16 . 2009-09-09 12:22 9728 ----a-w- c:\windows\system32\TCPSVCS.EXE

2009-08-14 14:16 . 2009-09-09 12:22 17920 ----a-w- c:\windows\system32\ROUTE.EXE

2009-08-14 14:16 . 2009-09-09 12:22 11264 ----a-w- c:\windows\system32\MRINFO.EXE

2009-08-14 14:16 . 2009-09-09 12:22 27136 ----a-w- c:\windows\system32\NETSTAT.EXE

2009-08-14 14:16 . 2009-09-09 12:22 19968 ----a-w- c:\windows\system32\ARP.EXE

2009-08-14 14:16 . 2009-09-09 12:22 8704 ----a-w- c:\windows\system32\HOSTNAME.EXE

2009-08-14 14:16 . 2009-09-09 12:22 10240 ----a-w- c:\windows\system32\finger.exe

2009-08-05 14:22 . 2009-10-14 19:43 3597896 ----a-w- c:\windows\system32\ntkrnlpa.exe

2009-08-05 14:22 . 2009-10-14 19:43 3546184 ----a-w- c:\windows\system32\ntoskrnl.exe

2009-03-31 21:47 . 2009-05-09 21:08 324976 ----a-w- c:\program files\mozilla firefox\components\coFFPlgn.dll

2008-11-14 11:50 . 2008-11-14 11:49 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-21 125952]

"msnmsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]

"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-21 202240]

"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-10-13 39408]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]

"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-09-04 200704]

"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-09-17 442460]

"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-09-17 150040]

"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-09-17 170520]

"Persistence"="c:\windows\system32\igfxpers.exe" [2008-09-17 145944]

"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]

"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2008-05-07 178712]

"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2008-05-23 128296]

"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-06-03 206064]

"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]

"osCheck"="c:\program files\Norton 360\osCheck.exe" [2008-02-26 988512]

"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]

"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]

"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]

"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]

"EEventManager"="c:\progra~1\EPSONS~1\EVENTM~1\EEventManager.exe" [2008-12-04 665424]

"Google Quick Search Box"="c:\program files\Google\Quick Search Box\GoogleQuickSearchBox.exe" [2009-10-13 122880]

c:\users\Elaine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\users\Lorraine.Millie\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

c:\users\Rachel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

c:\users\Elaine 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

c:\users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2008-7-15 1226024]

OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist]

2008-11-14 10:31 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]

"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~2\GoogleDesktopNetwork3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]

"mixer"=wdmaud.drv

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]

@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]

@="Service"

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\ipsdefs\20091101.001\IDSvix86.sys [01/11/2009 13:54 272432]

R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [27/08/2009 13:29 102448]

R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [19/02/2009 11:31 41008]

S3 COH_Mon;COH_Mon;c:\windows\System32\drivers\COH_Mon.sys [13/01/2008 02:32 23888]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - COMHOST

*NewlyCreated* - MBR

*Deregistered* - mbr

.

Contents of the 'Scheduled Tasks' folder

2009-11-01 c:\windows\Tasks\RegCure Program Check.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-11-01 c:\windows\Tasks\RegCure Startup.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

2009-06-19 c:\windows\Tasks\RegCure.job

- c:\program files\RegCure\RegCure.exe [2009-06-10 22:28]

.

.

------- Supplementary Scan -------

.

uStart Page = hxxp://www.google.com/

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000

IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_A54B7D6FB1DA63EA.dll/cmsidewiki.html

FF - ProfilePath - c:\users\Elaine\AppData\Roaming\Mozilla\Firefox\Profiles\2tbphxml.default\

FF - prefs.js: browser.startup.homepage - search.speedbit.com

FF - prefs.js: keyword.URL - hxxp://search.speedbit.com/searchresults.asp?src=default&q=

FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll

FF - plugin: c:\program files\Mozilla Firefox\plugins\NPAskSBr.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

.

.

------- File Associations -------

.

vbefile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*

vbsfile\shell\open2\command="%SystemRoot%\System32\CScript.exe" "%1" %*

jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, GMER - Rootkit Detector and Remover

Rootkit scan 2009-11-01 20:57

Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

Completion time: 2009-11-01 21:04

ComboFix-quarantined-files.txt 2009-11-01 21:04

Pre-Run: 124,320,927,744 bytes free

Post-Run: 124,372,475,904 bytes free

- - End Of File - - F68329F5E7026897CEBA56B94719D022

Love Elaine xxx
Posted

After re-booting it let me open the programme so here's the log

Malwarebytes' Anti-Malware 1.41

Database version: 3080

Windows 6.0.6001 Service Pack 1

01/11/2009 19:53:51

mbam-log-2009-11-01 (19-53-51).txt

Scan type: Quick Scan

Objects scanned: 138814

Time elapsed: 10 minute(s), 56 second(s)

Memory Processes Infected: 0

Memory Modules Infected: 0

Registry Keys Infected: 0

Registry Values Infected: 0

Registry Data Items Infected: 0

Folders Infected: 0

Files Infected: 0

Memory Processes Infected:

(No malicious items detected)

Memory Modules Infected:

(No malicious items detected)

Registry Keys Infected:

(No malicious items detected)

Registry Values Infected:

(No malicious items detected)

Registry Data Items Infected:

(No malicious items detected)

Folders Infected:

(No malicious items detected)

Files Infected:

(No malicious items detected)

Love Elaine xxx
Posted

Your system appears clean to me. Head back to that thread and let them know that malware isn't the cause. :)

 

 

Let's remove ComboFix.

 

Go to to Start > Run

Type in box

 

combofix /u

 

Note: the space between the X and the /u

 

Press Enter.

 

This command will:

 

Delete the following:

ComboFix and its associated files and folders.

VundoFix backups, if present

The C:\Deckard folder, if present

The C:_OtMoveIt folder, if present

 

Reset the clock settings.

Hide file extensions, if required.

Hide System/Hidden files, if required.

Reset System Restore.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...