Go Back   Cyber Tech Help Support Forums > Software > Malware Removal Forum

Notices

Reply
 
Topic Tools
  #1  
Old November 5th, 2009, 12:42 AM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
Completely lost!!!!

My Anti-virus software lisence recently expired. I purchased the Kaspersky Internet Security 2010 software. Problem is: when I click it to install, all I get is a "varifying installer" indication. After that, the Installation Wizard does not come up for me to actually install the software. I see a box pop up that says "Extract:kis.en.msi", but it goes away before I can see what options are on it. I uninstalled all the old software. I thought it may have something to do with the firewall, so I attempted to turn that off only to run into another problem. When I try to open the Windows firewall settins I get the message:
"Windows firewall settings cannot be displayed because the associated service is not running." It gives me the option to start the Windows firewall/internet Connection Sharing (ICS) Service. When I click on the "YES" option I then get a message saying that it cannot start it. I have a Registry Mechanic Prgram still on the computer so I decided to run it and see if there may be any problems in there that may be causing this. There were 95 problems found and corrected but the problem still occurs. I am about to pull my hair out here and would really appreciate any help that I can get. By the way this is a 2002 COMPAQ Presario 900 PC. I know it is considered obsolite but this is all I got and EVERYTHING was running perfect unitll the lisence expired on the old software and I attempted to install the new.
Reply With Quote


  #2  
Old November 5th, 2009, 03:39 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: New Zealand
Posts: 57,865
Hi rebsfan4 and welcome. What antivirus software did you have installed previously?
Reply With Quote
  #3  
Old November 6th, 2009, 12:25 AM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
Defender Pro. Can't recall the version though. It had Anti-Virus, Spyware, and PC Tune and Repair
Reply With Quote
  #4  
Old November 6th, 2009, 01:47 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: New Zealand
Posts: 57,865
Well you may have to contact Kaspersky support but if you like, I can have a look at what is running on your computer to see if I spot any issues that might be contributing to your problem.

Go here and download DDS to your Desktop and doubleclick on DDS.scr to run it. When the scan has finished, two logs will open. Copy and paste both reports in this topic. The logs will be reasonably large so you may have to divide them into sections and make several posts to post them.
Reply With Quote
  #5  
Old November 8th, 2009, 10:07 PM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
I think this is what you was asking for but not 100% sure. Nowhere near computer savy.

DDS (Ver_09-10-26.01) - NTFSx86
Run by Bryan Wesley at 15:16:03.83 on Sun 11/08/2009
Internet Explorer: 6.0.2900.2180

============== Running Processes ===============


============== Pseudo HJT Report ===============

uStart Page = hxxp://www.comcast.net/
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.micros oft:en-US&ie=utf8&oe=utf8
mDefault_Search_URL = hxxp://www.google.com/ie
mStart Page = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
mSearch Bar = hxxp://rd.yahoo.com/customize/yessentials_cq/defaults/sb/*http://www.yahoo.com/search/ie.html
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: ALO: {506cd401-5203-4b27-bb5a-03c97758fd02} - ALO
BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.3.4501.1418\s wg.dll
BHO: CPub Object: {c68ae9c0-0909-4ddc-b661-c1afb9f5ae53} - c:\program files\defenderpro antispy\popupblocker\PopupBlocker.dll
BHO: Google Dictionary Compression sdch: {c84d72fe-e17d-4195-bb24-76c02e2e7c4e} - c:\program files\google\google toolbar\component\fastsearch_B7C5AC242193BB3E.dll
TB: Defender Pro Anti-Scam: {102bad8b-cd05-46ff-94ff-a2c1abd5f7d5} - c:\program files\defender pro\defender pro anti-scam\mscoree.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
EB: {4528BBE0-4E08-11D5-AD55-00010333D0AD} - No File
EB: {32683183-48a0-441b-a342-7c2a440a9478} - No File
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNo tifier.exe"
uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [AAWTray] c:\program files\lavasoft\ad-aware 2007\AAWTray.exe
mRun: [smrtprt] c:\program files\smart protector\smrtprt.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
mRun: [SunJavaUpdateSched] c:\program files\java\jre1.5.0_06\bin\jusched.exe
mRun: [srmclean] c:\cpqs\scom\srmclean.exe
mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
mRun: [KAVPersonal50] "c:\program files\defender pro\defender pro anti-virus\kav.exe" /minimize
mRun: [DPAS] "c:\program files\defenderpro antispy\DPASNT.exe"
mRun: [Cpqset] c:\compaq\cpqsetup\cpqset.exe
mRun: [BellSouthWCC_McciTrayApp] c:\program files\bellsouthwcc\McciTrayApp.exe
mRun: [AtiPTA] atiptaxx.exe
mRun: [ATIModeChange] Ati2mdxx.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
dRun: [ALUAlert] c:\program files\symantec\liveupdate\ALUNotify.exe
IE: { - c:\program files\messenger\msmsgs.exe
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC} - c:\program files\java\jre1.5.0_06\bin\ssv.dll
IE: {0D555BC6-E331-48b3-A60E-AAC0DF79438A} - {93F764AC-24D1-484F-92EA-3C84E31CDF72} - c:\program files\defenderpro antispy\popupblocker\PopupBlocker.dll
IE: {2499216C-4BA5-11D5-BD9C-000103C116D5} - {2499216C-4BA5-11D5-BD9C-000103C116D5} - c:\program files\yahoo!\common\ylogin.dll
DPF: Microsoft XML Parser for Java - file://c:\windows\java\classes\xmldso.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 85.255.116.105 85.255.112.236
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Notify: eaebaccffee - c:\windows\system32\eaebaccffee.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
SSODL: SysiNet - {7BD3D390-A4D1-46DF-BB98-3715E1D2A940} - c:\documents and settings\all users\microsoft adata\sysinet.dll
Reply With Quote
  #6  
Old November 8th, 2009, 10:07 PM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
============= SERVICES / DRIVERS ===============


=============== Created Last 30 ================

2009-11-08 08:22:06 0 d-----w- c:\windows\DED53B0BB67C4244AE6AD6FD3C28D1EF.TMP
2009-11-03 22:29:15 0 d-----w- c:\program files\Smart Protector
2009-11-03 22:18:42 0 d-----w- c:\docume~1\alluse~1\applic~1\Kaspersky Lab Setup Files
2009-11-03 05:40:22 193040 ----a-w- c:\windows\system32\lastmon.dll
2009-11-03 05:36:04 277007 ------w- c:\windows\system32\eaebaccffee.dll
2009-11-03 05:36:01 379904 ----a-w- c:\windows\system32\winsc.exe
2009-11-03 05:36:00 38352 ----a-w- c:\windows\regred.exe
2009-11-03 05:36:00 33149 ----a-w- c:\windows\usexplorer.exe
2009-11-03 05:36:00 18941 ----a-w- c:\windows\microsoftdef.dll
2009-11-03 05:35:59 51197 ----a-w- c:\windows\spoov.exe
2009-11-03 05:35:59 47872 ----a-w- c:\windows\certsystem.exe
2009-11-03 05:35:59 28320 ----a-w- c:\windows\securits.com
2009-11-03 05:35:40 0 d-----w- c:\documents and settings\all users\Microsoft AData
2009-11-02 02:32:38 0 d-----w- c:\docume~1\bryanw~1\applic~1\com.adobe.mauby.4875 E02D9FB21EE389F73B8D1702B320485DF8CE.1
2009-11-02 02:22:22 0 d-----w- c:\windows\SxsCaPendDel
2009-11-02 02:04:16 0 d-----w- c:\docume~1\alluse~1\applic~1\McAfee Security Scan
2009-10-30 19:27:54 0 d-----w- c:\windows\system32\CatRoot_bak
2009-10-29 23:37:11 60416 -c----w- c:\windows\system32\dllcache\colbact.dll
2009-10-29 23:37:10 473088 -c----w- c:\windows\system32\dllcache\fastprox.dll
2009-10-29 23:37:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-10-29 23:37:10 110592 -c----w- c:\windows\system32\dllcache\services.exe

==================== Find3M ====================

2009-09-25 05:49:02 668672 ----a-w- c:\windows\system32\wininet.dll
2009-09-25 05:49:01 532480 ----a-w- c:\windows\system32\dllcache\mstime.dll
2009-09-25 05:48:59 96256 ----a-w- c:\windows\system32\dllcache\inseng.dll
2009-09-25 05:48:59 81920 -c--a-w- c:\windows\system32\ieencode.dll
2009-09-25 05:48:59 81920 ----a-w- c:\windows\system32\dllcache\ieencode.dll
2009-09-25 05:48:59 55808 ----a-w- c:\windows\system32\dllcache\extmgr.dll
2009-09-25 05:48:58 1054208 ----a-w- c:\windows\system32\dllcache\danim.dll
2009-09-18 09:46:06 18432 ----a-w- c:\windows\system32\dllcache\iedw.exe
2009-09-11 14:33:52 133632 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 20:45:26 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-26 08:16:37 247326 -c--a-w- c:\windows\system32\strmdll.dll
2009-08-26 08:16:37 247326 ----a-w- c:\windows\system32\dllcache\strmdll.dll
2007-02-01 01:03:46 778 -c--a-w- c:\program files\INSTALL.LOG
2001-08-18 12:00:00 94784 -csh--w- c:\windows\twain.dll
2004-08-04 07:56:46 50688 -csh--w- c:\windows\twain_32.dll
2004-08-04 07:56:43 413696 --sha-w- c:\windows\system32\msvcp60.dll
2004-08-04 07:56:43 343040 --sha-w- c:\windows\system32\msvcrt.dll
2007-12-04 18:38:13 550912 --sh--w- c:\windows\system32\oleaut32.dll
2004-08-04 07:56:44 83456 --sh--w- c:\windows\system32\olepro32.dll
2004-08-04 07:56:55 11776 -csh--w- c:\windows\system32\regsvr32.exe

============= FINISH: 15:16:53.84 ===============
Reply With Quote
  #7  
Old November 8th, 2009, 10:10 PM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
This is all greek to me. One more thing has done started happening too. Now when I type something in the address bar in will find the website and pull it up, but it immediately closes the site and sends the computer back to the desktop. If I don't have a shortcut on the desktop to a site or have it in the FAVORITES; then I cannot access it. I think I just need to take the old thang and throw it in the river!!!!

There was also an ATTACH NOTEPAD window that came up after it ran; do I need to post that as well. It just looks like the same stuff over and over.

Last edited by rebsfan4; November 8th, 2009 at 10:13 PM.
Reply With Quote
  #8  
Old November 8th, 2009, 10:30 PM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: New Zealand
Posts: 57,865
Yes please. Your operating system is infected so I'm transferring this topic to the Malware removal Forum.
Reply With Quote
  #9  
Old November 8th, 2009, 10:33 PM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_09-10-26.01)


==== Disk Partitions =========================


==== Disabled Device Manager Items =============

==== System Restore Points ===================

No restore point in system.

==== Installed Programs ======================

Ad-Aware 2007
Adobe Flash Player 10 ActiveX
Apple Software Update
ATI Display Driver
Google Toolbar for Internet Explorer
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB970653-v3)
InterVideo WinDVD
J2SE Runtime Environment 5.0 Update 6
Lexmark 1200 Series
Lexmark Fax Solutions
Logitech Desktop Messenger
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Data Access Components KB870669
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 97, Professional Edition
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft XML Parser
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
Photo Explosion Special Edition
RealPlayer
Registry Mechanic 5.1
RTLSetup
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB944338-v2)
Reply With Quote
  #10  
Old November 8th, 2009, 10:34 PM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB945553)
Security Update for Windows XP (KB946026)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950749)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956844)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958470)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958869)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB960859)
Security Update for Windows XP (KB961371-v2)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969059)
Security Update for Windows XP (KB970238)
Security Update for Windows XP (KB971486)
Security Update for Windows XP (KB971557)
Security Update for Windows XP (KB971633)
Security Update for Windows XP (KB971657)
Security Update for Windows XP (KB971961)
Security Update for Windows XP (KB973354)
Security Update for Windows XP (KB973507)
Security Update for Windows XP (KB973525)
Security Update for Windows XP (KB973869)
Security Update for Windows XP (KB974112)
Security Update for Windows XP (KB974455)
Security Update for Windows XP (KB974571)
Security Update for Windows XP (KB975025)
Security Update for Windows XP (KB975467)
Setup Compaq Software
Smart Protector
Synaptics TouchPad
Ulead COOL 360 1.0
Ulead Photo Explorer 8.0 SE Basic
Ulead Photo Express 5 SE
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update for Windows XP (KB953356)
Update for Windows XP (KB967715)
Update for Windows XP (KB968389)
Update for Windows XP (KB973815)
Update for Windows XP (KB976749)
WebFldrs XP
Windows Backup Utility
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
Yahoo! Login

==== End Of File ===========================
Reply With Quote
  #11  
Old November 8th, 2009, 10:35 PM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
Is that whats stopping me from installing this new security program?
Reply With Quote
  #12  
Old November 8th, 2009, 10:38 PM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: New Zealand
Posts: 57,865
Yes.

Download the latest version of Combofix.exe from here and save it to your Desktop.

Doubleclick on combofix.exe and the scan will start. Go ahead and install the Recovery Console if you are asked to do so (this doesnt apply to Vista). When the scan completes, a text window with your log will open. Please copy and paste that log back here.

A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Also download the latest version of Gmer from here to your Desktop. Once downloaded, doubleclick on gmer.zip and unzip the file to its own folder

When you have done this, close all running programs including those in your notification area (bottom righthand corner of your screen) and doubleclick on Gmer.exe to run it. Click on the Rootkit tab and look at the righthand side (under Files) and uncheck all drives with the exception of your C drive and then click on Scan (before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while this scan completes. Also do not use your computer during the scan). When completed, click on the Copy button and rightclick on your Desktop, choose "New" > Text document. Once the file is created, open it and rightclick again and choose Paste. Save the file and copy the information and post it here please.

Warning! Please do not select the "Show all" checkbox during the scan
Reply With Quote
  #13  
Old November 9th, 2009, 12:04 AM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
Ok I did the combofix download and it completed the scan. The log is huge. Is there someway I can post the log info here in say like a folder so it don't take up so much space on the forum page. And at the risk of sounding like a complete moron, I have no clue how to unzip the Gmer to it's own folder. I have it downloaded to the desktop as well.
Reply With Quote
  #14  
Old November 9th, 2009, 12:13 AM
AnnMarie's Avatar
AnnMarie AnnMarie is offline
Cyber Tech Help Moderator
 
Join Date: Oct 2001
O/S: Windows Vista 32-bit
Location: New Zealand
Posts: 57,865
Quote:
The log is huge. Is there someway I can post the log info here in say like a folder so it don't take up so much space on the forum page.
I may need to keep referring to it so it needs to be posted in this topic. Divide it into sections and make several posts.

Quote:
I have no clue how to unzip the Gmer to it's own folder.
Just doubleclick on it and choose Extract all files.
Reply With Quote
  #15  
Old November 9th, 2009, 12:14 AM
rebsfan4 rebsfan4 is offline
Member
 
Join Date: Nov 2009
Posts: 44
ComboFix 09-11-08.03 - Bryan Wesley 11/08/2009 16:48.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.239.123 [GMT -6:00]
Running from: c:\documents and settings\Bryan Wesley\Desktop\ComboFix.exe
.
ADS - svchost.exe: deleted 68 bytes in 1 streams.
ADS - ntoskrnl.exe: deleted 68 bytes in 1 streams.
ADS - explorer.exe: deleted 68 bytes in 1 streams.
ADS - win32k.sys: deleted 68 bytes in 1 streams.
ADS - netcfgx.dll: deleted 100 bytes in 1 streams.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\All Users\Microsoft AData
c:\documents and settings\All Users\Microsoft AData\sysinet.dll
c:\program files\Common Files\Real\WeatherBug\MiniBugTransporter.dll
c:\program files\INSTALL.LOG
c:\program files\Smart Protector
c:\program files\Smart Protector\config.scf
c:\program files\Smart Protector\mmbase.sdb
c:\program files\Smart Protector\q.sdb
c:\program files\Smart Protector\queue.sdb
c:\program files\Smart Protector\smrtprt.exe
c:\program files\Smart Protector\uninstalls.exe
c:\program files\Smart Protector\vvbase.sdb
c:\recycler\NPROTECT
c:\recycler\NPROTECT\00000798.
c:\recycler\NPROTECT\00000799.
c:\recycler\NPROTECT\00000800.
c:\recycler\NPROTECT\00000801.
c:\recycler\NPROTECT\00000802.
c:\recycler\NPROTECT\00000803.
c:\recycler\NPROTECT\00000804.
c:\recycler\NPROTECT\00000805.
c:\recycler\NPROTECT\00000806.
c:\recycler\NPROTECT\00000807.
c:\recycler\NPROTECT\00000808.
c:\recycler\NPROTECT\00000809.
c:\recycler\NPROTECT\00000810.
c:\recycler\NPROTECT\00000811.
c:\recycler\NPROTECT\00000812.
c:\recycler\NPROTECT\00000813.
c:\recycler\NPROTECT\00000814.
c:\recycler\NPROTECT\00000815.
c:\recycler\NPROTECT\00000816.
c:\recycler\NPROTECT\00000817.
c:\recycler\NPROTECT\00000818.
c:\recycler\NPROTECT\00000819.
c:\recycler\NPROTECT\00000820.
c:\recycler\NPROTECT\00000821.
c:\recycler\NPROTECT\00000822.
c:\recycler\NPROTECT\00000823.
c:\recycler\NPROTECT\00000824.
c:\recycler\NPROTECT\00000825.
c:\recycler\NPROTECT\00000826.
c:\recycler\NPROTECT\00000827.
c:\recycler\NPROTECT\00000828.
c:\recycler\NPROTECT\00000829.
c:\recycler\NPROTECT\00000830.
c:\recycler\NPROTECT\00000831.
c:\recycler\NPROTECT\00000832.
c:\recycler\NPROTECT\00000833.
c:\recycler\NPROTECT\00000834.
c:\recycler\NPROTECT\00000835.
c:\recycler\NPROTECT\00000836.
c:\recycler\NPROTECT\00000837.
c:\recycler\NPROTECT\00000838.
c:\recycler\NPROTECT\00000839.
c:\recycler\NPROTECT\00000840.
c:\recycler\NPROTECT\00000841.
c:\recycler\NPROTECT\00000842.
c:\recycler\NPROTECT\00000843.
c:\recycler\NPROTECT\00000844.
c:\recycler\NPROTECT\00000845.
c:\recycler\NPROTECT\00000846.
c:\recycler\NPROTECT\00000847.
c:\recycler\NPROTECT\00000848.
c:\recycler\NPROTECT\00000849.
c:\recycler\NPROTECT\00000850.
c:\recycler\NPROTECT\00000851.
c:\recycler\NPROTECT\00000852.
c:\recycler\NPROTECT\00000853.
c:\recycler\NPROTECT\00000854.
c:\recycler\NPROTECT\00000855.
c:\recycler\NPROTECT\00000856.
c:\recycler\NPROTECT\00000857.
c:\recycler\NPROTECT\00000858.
c:\recycler\NPROTECT\00000859.
c:\recycler\NPROTECT\00000860.
c:\recycler\NPROTECT\00000861.
c:\recycler\NPROTECT\00000862.
c:\recycler\NPROTECT\00000863.
c:\recycler\NPROTECT\00000864.
c:\recycler\NPROTECT\00000865.
c:\recycler\NPROTECT\00000866.
c:\recycler\NPROTECT\00000867.
c:\recycler\NPROTECT\00000868.
c:\recycler\NPROTECT\00004703.
c:\windows\certsystem.exe
c:\windows\microsoftdef.dll
c:\windows\regred.exe
c:\windows\securits.com
c:\windows\spoov.exe
c:\windows\system32\eaebaccffee.dll
c:\windows\system32\winsc.exe
c:\windows\usexplorer.exe
Reply With Quote
Reply

Bookmarks

Topic Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump




All times are GMT +1. The time now is 05:32 AM.