Malware - Adware- Computer trashed.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ladyraven, Jul 31, 2008.

  1. ladyraven

    ladyraven Private E-2

    Been working on this with several people for a few weeks and not getting anywhere. I have tried everyone on the site for malware removal.
    Finally last night I deleted over 500 files................. I started to run my program again... the first one I ran came up with this

    a-squared Free - Version 3.5
    Last update: 7/31/2008 2:03:24 AM

    Scan settings:

    Objects: Memory, Traces, Cookies, C:\
    Scan archives: On
    Heuristics: On
    ADS Scan: On

    Scan start: 7/31/2008 2:16:26 AM

    [1800] C:\WINDOWS\System32\ATL71.DLL detected: Adware.Win32.PcTurboPro
    C:\Documents and Settings\Nicole\Cookies\nicole@windowsmedia[1].txt detected: Trace.TrackingCookie
    C:\Documents and Settings\Nicole\.housecall\Update\AU_Cache\housecall65.trendmicro.com\ini_xml.zip detected: Adware.Win32.SpyBouncer
    C:\Documents and Settings\Nicole\.housecall6.6\Update\AU_Cache\eu-housecall.trendmicro-europe.com\ini_xml.zip detected: Adware.Win32.SpyBouncer
    C:\Documents and Settings\Nicole\.housecall6.6\Update\AU_Cache\housecall65.trendmicro.com\ini_xml.zip detected: Adware.Win32.SpyBouncer
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\binaries\msvcm80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\binaries\msvcp80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\binaries\msvcr80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\packages\kos-bin-winnt-engine.jar/msvcp80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\packages\kos-bin-winnt-engine.jar/msvcr80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\packages\kos-bin-winnt-redist.jar/msvcm80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\packages\kos-bin-winnt-redist.jar/msvcp80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\jkos-Nicole\packages\kos-bin-winnt-redist.jar/msvcr80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Documents and Settings\Nicole\Local Settings\Temp\NIS10.0\Support\LUpdate\Psapi.Dll detected: Adware.Win32.CoolOnlineOffers.ScreenSaver
    C:\Documents and Settings\Nicole\Local Settings\Temp\NIS10.0\Support\Redist\MSRedist\atl71.dll detected: Adware.Win32.PcTurboPro
    C:\Program Files\Common Files\LightScribe\msvcm80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Program Files\Common Files\LightScribe\msvcp80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Program Files\Common Files\LightScribe\msvcr80.dll detected: Adware.Win32.XPSecurityCenter
    C:\Program Files\CyberLink\PowerProducer\gdiplus.dll detected: Adware.Win32.BPSSpywareCops
    C:\Program Files\HP\Digital Imaging\{BDBE2F3E-42DB-4d4a-8CB1-19BA765DBC6C}\gdiplus.dll detected: Adware.Win32.BPSSpywareCops
    C:\WINDOWS\SoftwareDistribution\Download\16b2c96a0c41f4dfdb4d3cc228a4f819\regwizc.dll detected: Adware.Win32.3DGorgeousFallFoliageScreensaver
    C:\WINDOWS\system32\atl71.dll detected: Adware.Win32.PcTurboPro
    C:\WINDOWS\system32\gdiplus.dll detected: Adware.Win32.BPSSpywareCops
    C:\WINDOWS\system32\SpOrder.dll detected: Adware.Win32.BabesSolitaires
    C:\WINDOWS\system32\ZoneLabs\avsys\msvcp80.dll detected: Adware.Win32.XPSecurityCenter
    C:\WINDOWS\system32\ZoneLabs\avsys\msvcr80.dll detected: Adware.Win32.XPSecurityCenter
    C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcm80.dll detected: Adware.Win32.XPSecurityCenter
    C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcp80.dll detected: Adware.Win32.XPSecurityCenter
    C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.42_x-ww_0de06acd\msvcr80.dll detected: Adware.Win32.XPSecurityCenter
    C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.10.0_x-ww_712befd8\GdiPlus.dll detected: Adware.Win32.FinalBurnerFreev1.19.0.102

    Scanned

    Files: 106188
    Traces: 428527
    Cookies: 47
    Processes: 31

    Found

    Files: 28
    Traces: 0
    Cookies: 1
    Processes: 1
    Registry keys: 0

    Scan end: 7/31/2008 4:06:46 AM
    Scan time: 1:50:20
    Then I put all in quarantine.... a window popped up and said
    Files that are required 4 windows to run properly have been replaced by an unknown version- unrecognized please put in CD Windows SP1
    Ok I put in my windows XP PRO disc and it cannot read it.
    For more information on my problem so I do not have to write it all again and all I tried... please go to

    This thread is located at:
    http://forums.majorgeeks.com/showthread.php?t=163913&goto=newpost

    if you can or want to try to help. I have been trying to find Cordil but have been unable, he was really helping me one night for 5 hours.... this is really
    What I would like to do is figure out how to export my books marks in FF - it is corrupted and I have tried re installing- my system restores are corrupted.... so, I need to find an inexpensive place on the web to store my picture, files and music for a month....
    Any suggestions would be greatly appreciate...thank you
    I love mycomputer..
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your log from A-Squared, it is either having major false positive issues or many of your file have become infected with a variety of different forms of malware. Everything listed is incorrect. Since it is even calling the version 8 runtime library files problems and accuses them from multiple locations, I would lean more towards A-Squared being wrong!! The first file ( C:\WINDOWS\System32\ATL71.DLL ) is even a Microsoft system file. It is ATL Module for Windows (Unicode)

    C:\WINDOWS\system32\gdiplus.dll is also a Windows System file.


    I suggest that you uninstall A-Squared and also report all these to them so they can fix their scanner.
     
    Last edited: Jul 31, 2008
  3. ladyraven

    ladyraven Private E-2

    Opps, well, I deleted all the files. My computer has been trashed for weeks, if you read my other post ??? I have scripts running all the time on different pages... I have been using A2 for months and nothing showed up and then I deleted about 500 files from my documents, ran A and this all came up! Did I delete something important from Windows? I just need to get my information off this computer, it will not let me back up on CD RW or DVD R, we have tried Sony and Scan plug in to USB and the machine will not recognize them, says they are working , then says they are malfunctioning. The computer is trashed ,,,,,,,,,
    I do not have the skills or the money to fix it. So, I need a place that is not expensive to upload my files, music and pictures ... about 4 - 5 Gig for a few days until I can load it on the machine my friend lent me. This machine if HP 751n from 2002, HP was on the line with me and there was nothing they could do to help me get the info offf the machine or figure out why I kept get script messages running on pages, why my screen freezes if more than one window is open or if I try to do 2 or more things at a time on the computer. I have plenty of space on the HD and plenty of memory, so, something is wrong

    Any suggestion what to do would be appreciate.
    Thanks for your time!
    I wonder what I deleted?

    PS, I updated and ran A again and now it says there is nothing in the computer, not since I deleted all the items in that report. I have run adware and AVG spy and a few other programs and they are all clean now, I am very confused!
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs you may have deleted files for Windows and also files for your LightScribe DVD drive. You should reinstall the software for your DVD recorder and burning software...etc and see if you can get things to work.

    I also suggest that you click Start, Run, and enter sfc /scannow into the run box and click OK. This may ask for your Windows CD so have it ready.

    This is not an issue for the malware forum.

    There is nothing to be confused about. There is simply nothing to detect. I suggest that you stop using A-Squared immediately and uninstall it.
     
  5. ladyraven

    ladyraven Private E-2

    Any suggestion what I should use for a free spyware and malware? I have AVG and ADWare, but something is in my computer or I would not be getting scrips running when I open pages... a window pops up and say, script running on page, do you want to stop it. Also, Pages freeze or sometimes I get a blue screen with an error message and then it has the memory counting down...



    So, I think there is something in this computer, that is not allowing me to backup, use the CD or DVD, backup to memory stick and has corrupted all my system restore points. Am I wrong in thinking something is wrong with this computer?
     
    Last edited: Aug 1, 2008
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't waste your time and resources with Ad-Aware. It provides no protection and is pretty useless against current malware that is infecting PCs.

    Many web pages contain Java and or ActiveX scripts. This can be normal behavior. However since you have not really checked your PC for malware using our procedures, you can run them to see if we find any malware issues.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions. If something does not run, write down the info to explain to us later but keep on going. Do not assume that because one step does not work that they all will not.

    READ & RUN ME FIRST. Malware Removal Guide


    Note: If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode



    Did you do what I stated in my previous message? What were the results of reinstalling the software and running sfc?
     
  7. ladyraven

    ladyraven Private E-2

    I did what you said, got rid of a2aquare, sent them a copy of my log and then ran it as you said. window came up bos saying put in disc, I put in disc, it ran for about 40 min and and then the box disappeared it did not say anything.
    So, you want me to try going throuh your malware procedure, but this time keep track of anything that comes up and try to copy and paste into a doc so you can see it. Ok, I can do that. last time I tried , the computer crashed, and I lost the man I was working with for 2 days. However, I will try it again.
    I will try it, I assume I can do it not in safe mode unless I have a problem , correct, or do I just do it in safe mode, I will go to the pages and see what they say!

    Again, thank you. I just tried to burn to CD my WMP list and it will not let me.
     
    Last edited by a moderator: Aug 1, 2008
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This means it found a bunch of problems and fixed them. You probably had many required files that were deleted.

    Not Word Doc. Just the text logs that are requested in the procedures of the READ & RUN ME. All logs must be attachments. Do not post them inline like you did with your A-Squared log.

    I don't know what you are referring to. This is your first thread in the Malware Forum.

    Everything should be run in normal boot mode as stated. The use of Safe Mode is only a fall back to try when Normal Mode does not work or a PC will not even boot in normal mode.

    I repeat.... have you reinstalled your software? This is not a malware issue.
     
  9. ladyraven

    ladyraven Private E-2

    Yes= it is still not working....
    However, I will work on the malware for now. I was working in another thread with Cordialia ( sp) he put me through the malware procedure about two weeks ago..it happened when some malware , virus , knocked my AVG out and I could not put it back on because I only have SP1 and when I try to update the computer crashes to the blue screen of death!
    Thanks again.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only people authorized to help you with malware removal are the people who can post in this forum. If you had previously run some kind of procedures and had not save logs to post here then there is nothing I can say about what was done and what may have been removed. All I can comment on is your first post in this forum which showed that A-Squared had a load of false positives and if you allowed it to remove all of them then it broke Windows and some of your other applications. You will have to take up software issues in the Software Forum and Hardware issues (if you have any) in the Hardware Forum. In this forum we will deal only with malware.
     
  11. ladyraven

    ladyraven Private E-2

    At point reloading Java and it says the Operating System will not support it. I need to SP2???
    Do I skip this for now?
     
  12. ladyraven

    ladyraven Private E-2

    I guess I had a problem and being a newbie posted in the wrong forum. I do not know at this point was are software and what are my hardware problems. I am assuming.. not being able to back up is a hard ware and the CD DVD not backing up are also hard ward?
     
  13. ladyraven

    ladyraven Private E-2

    I stopped at 3 am. Found one Adware, one Malware, stopped at Combo Fix, I do not really understand and I am afraid to do this Windows XP Recovery Console in Dos. This is way over my head. Do I really put it on my XP disc? Then I put the disc into the drive and try to run it from the drive. This and 2 more things to do.
    Please someone just let me know if this is safe and maybe give me a brief explanation.
    Thank you for all your time, energy and expertize.
     
  14. ladyraven

    ladyraven Private E-2

    Still stuck at Combo Fix.... and understanding windows xp recovery console.... when someone as a moment if you could explain it in easy baby steps. I am concerned about doing this.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can skip this update to Java even though it may run okay. You do need to get your Operating System updated at some point soon (not now while having problems).


    You do not install the Recovery console on your CD. You are installing it on your hard disk. As stated in the instructions, you can either get the Recovery Console from your Windows XP CD or you can use the other method shown with downloading the files and using ComboFix. You can also skip installing the Recovery Console since you have a Windows XP CD that you can always fall back on if the Recovery Console is needed at any point.

    If it was not safe, would not be asking you to do it. ;)
     
  16. ladyraven

    ladyraven Private E-2

    Sorry, did not mean to offend! :eek: I am just really scared. My comfuser is a big part of my life. I am disabled and this is my link to the world. I guess I read it wrong. I thought I had to do the recovery, and I had to use the CD, my dyslexia makes it hard for me to grok it sometimes.

    Ok, on to the next step. I will do it without going into recovery mode. Then finish all steps and then post what I found.
    I need many updates and I need to go to SP2 I cannot use many programs because I am at SP1.
    However, I will wait until this is finished and see if I still need to reformat or the computer is OK.
    I posted for help on the DVD stuff and they said I am posting in the wrong place.. LOL.. so, I will worry about that later. I have uploaded my files to a friend sever.!
    Be back later... back to work!
     
  17. ladyraven

    ladyraven Private E-2

    Well, it is me again, finally got my computer uploaded to my friends server. So, I have gotten this far and these are my reports so far. The last one said, do not do this alone, make sure you have someone who knows what they are doing ...
    So, I have the log reports I hope this is ok! :eek::eek:
    Malwarebytes' Anti-Malware 1.24
    Database version: 1015
    Windows 5.1.2600 Service Pack 1

    2:47:11 AM 8/2/2008
    mbam-log-8-2-2008 (02-47-11).txt

    Scan type: Quick Scan
    Objects scanned: 41510
    Time elapsed: 12 minute(s), 52 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 1
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)

    Combo Fix
    ComboFix 08-08-04.01 - Nicole 2008-08-04 20:16:38.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.1.1252.1.1033.18.369 [GMT -7:00]
    Running from: C:\Documents and Settings\Nicole\Desktop\ComboFix.exe
    * Created a new restore point

    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Documents and Settings\Nicole\Application Data\macromedia\Flash Player\#SharedObjects\L8XLF6D5\interclick.com
    C:\Documents and Settings\Nicole\Application Data\macromedia\Flash Player\#SharedObjects\L8XLF6D5\interclick.com\ud.sol
    C:\Documents and Settings\Nicole\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
    C:\Documents and Settings\Nicole\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
    C:\Documents and Settings\Nicole\g2mdlhlpx.exe
    C:\WINDOWS\Downloaded Program Files\setup.inf

    .
    ((((((((((((((((((((((((( Files Created from 2008-07-05 to 2008-08-05 )))))))))))))))))))))))))))))))
    .

    2008-08-02 12:54 . 2008-08-02 12:54 <DIR> d-------- C:\Program Files\MozBackup
    2008-08-02 10:53 . 2008-08-04 03:19 <DIR> d-------- C:\Documents and Settings\Nicole\Application Data\CoreFTP
    2008-08-02 10:34 . 2008-08-02 13:24 <DIR> d-------- C:\Program Files\CoreFTP
    2008-08-02 02:22 . 2008-08-02 02:47 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
    2008-08-02 02:22 . 2008-08-02 02:22 <DIR> d-------- C:\Documents and Settings\Nicole\Application Data\Malwarebytes
    2008-08-02 02:22 . 2008-08-02 02:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-08-02 02:22 . 2008-07-30 20:15 38,472 --a------ C:\WINDOWS\system32\drivers\mbamswissarmy.sys
    2008-08-02 02:22 . 2008-07-30 20:15 17,144 --a------ C:\WINDOWS\system32\drivers\mbam.sys
    2008-08-02 01:22 . 2008-08-02 01:22 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
    2008-08-02 01:22 . 2008-08-02 02:17 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-08-01 23:30 . 2008-08-01 23:30 <DIR> d-------- C:\Program Files\CCleaner
    2008-08-01 20:43 . 2008-08-04 10:43 <DIR> d-------- C:\Documents and Settings\Nicole\Application Data\AVG7
    2008-08-01 20:42 . 2008-08-01 20:42 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
    2008-08-01 20:42 . 2008-08-01 21:15 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg7
    2008-08-01 17:08 . 2001-08-17 22:36 112,640 --a--c--- C:\WINDOWS\system32\dllcache\xrxwiadr.dll
    2008-08-01 17:08 . 2001-08-17 22:37 99,865 --a--c--- C:\WINDOWS\system32\dllcache\xlog.exe
    2008-08-01 17:08 . 2001-08-17 22:37 27,648 --a--c--- C:\WINDOWS\system32\dllcache\xrxftplt.exe
    2008-08-01 17:08 . 2001-08-17 22:36 23,040 --a--c--- C:\WINDOWS\system32\dllcache\xrxwbtmp.dll
    2008-08-01 17:08 . 2001-08-17 12:49 18,688 --a--c--- C:\WINDOWS\system32\dllcache\wvchntxx.sys
    2008-08-01 17:08 . 2001-08-17 22:36 17,408 --a--c--- C:\WINDOWS\system32\dllcache\xrxscnui.dll
    2008-08-01 17:08 . 2001-08-17 12:11 16,970 --a--c--- C:\WINDOWS\system32\dllcache\xem336n5.sys
    2008-08-01 17:08 . 2001-08-17 12:49 12,160 --a--c--- C:\WINDOWS\system32\dllcache\wsiintxx.sys
    2008-08-01 17:08 . 2001-08-17 22:36 7,680 --a--c--- C:\WINDOWS\system32\dllcache\wshirda.dll
    2008-08-01 17:08 . 2001-08-17 22:37 4,608 --a--c--- C:\WINDOWS\system32\dllcache\xrxflnch.exe
    2008-08-01 17:06 . 2001-08-17 13:28 794,654 --a--c--- C:\WINDOWS\system32\dllcache\usr1801.sys
    2008-08-01 17:05 . 2001-08-17 14:56 252,032 --a--c--- C:\WINDOWS\system32\dllcache\sis300iv.dll
    2008-08-01 17:04 . 2001-08-17 22:36 495,616 --a--c--- C:\WINDOWS\system32\dllcache\sblfx.dll
    2008-08-01 17:03 . 2001-08-17 13:28 899,146 --a--c--- C:\WINDOWS\system32\dllcache\r2mdkxga.sys
    2008-08-01 17:02 . 2002-08-29 03:41 3,494,303 --a--c--- C:\WINDOWS\system32\dllcache\nv4_disp.dll
    2008-08-01 17:01 . 2001-08-17 12:11 128,000 --a--c--- C:\WINDOWS\system32\dllcache\n100325.sys
    2008-08-01 17:00 . 2001-08-17 13:28 802,683 --a--c--- C:\WINDOWS\system32\dllcache\ltsm.sys
    2008-08-01 16:59 . 2001-08-17 22:36 585,344 --a--c--- C:\WINDOWS\system32\dllcache\i81xdnt5.dll
    2008-08-01 16:58 . 2001-08-17 14:56 1,733,120 --a--c--- C:\WINDOWS\system32\dllcache\g400d.dll
    2008-08-01 16:57 . 2001-08-17 12:14 952,007 --a--c--- C:\WINDOWS\system32\dllcache\diwan.sys
    2008-08-01 16:56 . 2001-08-17 12:13 980,034 --a--c--- C:\WINDOWS\system32\dllcache\cicap.sys
    2008-08-01 16:55 . 2002-08-29 03:40 921,475 --a--c--- C:\WINDOWS\system32\dllcache\ati3d2ag.dll
    2008-08-01 16:54 . 2002-08-29 01:04 1,891,840 --a--c--- C:\WINDOWS\system32\dllcache\ntkrnlmp.exe
    2008-07-30 17:28 . 2002-08-29 01:28 24,448 --a------ C:\WINDOWS\system32\drivers\MemStPCI.SYS
    2008-07-30 17:28 . 2002-08-29 01:28 24,448 --a--c--- C:\WINDOWS\system32\dllcache\memstpci.sys
    2008-07-30 15:59 . 2008-08-02 00:14 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-07-30 15:59 . 2008-08-02 00:14 <DIR> d-------- C:\Documents and Settings\Nicole\Application Data\SUPERAntiSpyware.com
    2008-07-30 15:59 . 2008-07-30 15:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-07-17 03:59 . 2008-07-09 09:05 1,086,952 --a------ C:\WINDOWS\system32\zpeng24.dll
    2008-07-15 02:39 . 2008-07-15 03:01 <DIR> d-------- C:\Program Files\Know Your Future
    2008-07-09 17:35 . 2008-07-09 17:35 <DIR> d-------- C:\Documents and Settings\Nicole\Application Data\dvdcss
    2008-07-07 23:21 . 2008-07-08 06:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-07-07 23:05 . 2008-08-02 00:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
    2008-07-07 20:10 . 2008-07-07 21:30 <DIR> d-------- C:\Program Files\EsetOnlineScanner

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-08-02 08:26 --------- d-----w C:\Program Files\Lavasoft
    2008-08-02 08:26 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-08-02 06:03 --------- d-----w C:\Program Files\Windows Live Safety Center
    2008-08-02 04:56 --------- d-----w C:\Program Files\Common Files\Ahead
    2008-08-02 00:05 --------- d-----w C:\Program Files\a-squared Free
    2008-07-31 17:37 --------- d-----w C:\Program Files\Common Files\LightScribe
    2008-07-31 06:28 --------- d-----w C:\Documents and Settings\Nicole\Application Data\Image Zone Express
    2008-07-31 03:43 --------- d-----w C:\Documents and Settings\Nicole\Application Data\eBookPro6
    2008-07-23 16:36 28,831,073 ----a-w C:\WINDOWS\Internet Logs\tvDebug.zip
    2008-07-11 00:45 1,366,528 ----a-w C:\WINDOWS\Internet Logs\xDBC2.tmp
    2008-07-10 04:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-07-09 23:57 1,351,168 ----a-w C:\WINDOWS\Internet Logs\xDBC1.tmp
    2008-07-09 20:25 --------- d-----w C:\Documents and Settings\Nicole\Application Data\vlc
    2008-07-09 16:05 75,248 ----a-w C:\WINDOWS\zllsputility.exe
    2008-07-08 06:23 --------- d-----w C:\Program Files\Alwil Software
    2008-07-08 06:21 1,319,936 ----a-w C:\WINDOWS\Internet Logs\xDBC0.tmp
    2008-07-07 20:24 1,302,016 ----a-w C:\WINDOWS\Internet Logs\xDBBF.tmp
    2008-07-05 08:44 2,670,592 ----a-w C:\WINDOWS\Internet Logs\xDBBC.tmp
    2008-07-05 08:44 1,550,336 ----a-w C:\WINDOWS\Internet Logs\xDBBD.tmp
    2008-07-05 08:43 1,550,336 ----a-w C:\WINDOWS\Internet Logs\xDBBE.tmp
    2008-07-03 00:50 --------- d-----w C:\Program Files\Uniblue
    2008-07-02 22:32 --------- d-----w C:\Documents and Settings\Nicole\Application Data\System Tweaker
    2008-07-02 21:27 --------- d-----w C:\Documents and Settings\Nicole\Application Data\Uniblue
    2008-07-02 20:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Uniblue
    2008-06-29 17:52 1,517,568 ----a-w C:\WINDOWS\Internet Logs\xDBBB.tmp
    2008-06-27 16:14 1,510,400 ----a-w C:\WINDOWS\Internet Logs\xDBBA.tmp
    2008-06-25 17:44 1,488,384 ----a-w C:\WINDOWS\Internet Logs\xDBB9.tmp
    2008-06-25 17:36 1,488,384 ----a-w C:\WINDOWS\Internet Logs\xDBB8.tmp
    2008-06-24 05:02 --------- d-----w C:\Program Files\AtmLitev5
    2008-06-22 02:46 1,478,144 ----a-w C:\WINDOWS\Internet Logs\xDBB7.tmp
    2008-06-21 22:00 1,478,144 ----a-w C:\WINDOWS\Internet Logs\xDBB6.tmp
    2008-06-21 01:38 1,477,632 ----a-w C:\WINDOWS\Internet Logs\xDBB5.tmp
    2008-06-19 01:42 --------- d-----w C:\Documents and Settings\Nicole\Application Data\vlc(2)
    2008-06-15 00:51 1,474,048 ----a-w C:\WINDOWS\Internet Logs\xDBB4.tmp
    2008-06-11 01:21 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo!
    2008-06-10 17:07 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-06-10 16:56 --------- d-----w C:\Program Files\Adobe Media Player
    2008-06-05 22:57 --------- d-----w C:\Documents and Settings\Nicole\Application Data\Apple Computer
    2008-06-05 22:57 --------- d-----w C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-06-05 22:08 --------- d-----w C:\Program Files\ProcessExplorer
    2008-06-01 01:26 1,400,320 ----a-w C:\WINDOWS\Internet Logs\xDBB3.tmp
    2008-05-31 09:28 1,404,416 ----a-w C:\WINDOWS\Internet Logs\xDBB2.tmp
    2008-05-30 06:00 1,402,880 ----a-w C:\WINDOWS\Internet Logs\xDBB1.tmp
    2008-05-26 23:12 1,398,272 ----a-w C:\WINDOWS\Internet Logs\xDBAF.tmp
    2008-05-25 16:01 1,396,736 ----a-w C:\WINDOWS\Internet Logs\xDBAE.tmp
    2008-05-25 10:36 1,396,736 ----a-w C:\WINDOWS\Internet Logs\xDBAD.tmp
    2008-05-23 09:57 1,396,736 ----a-w C:\WINDOWS\Internet Logs\xDBB0.tmp
    2008-05-22 18:51 1,396,736 ----a-w C:\WINDOWS\Internet Logs\xDBAC.tmp
    2008-05-22 08:13 1,395,712 ----a-w C:\WINDOWS\Internet Logs\xDBAB.tmp
    2008-05-21 15:38 1,395,200 ----a-w C:\WINDOWS\Internet Logs\xDBAA.tmp
    2008-05-20 06:45 1,386,496 ----a-w C:\WINDOWS\Internet Logs\xDBA9.tmp
    2008-05-20 03:49 1,374,720 ----a-w C:\WINDOWS\Internet Logs\xDBA8.tmp
    2008-05-12 23:35 1,345,536 ----a-w C:\WINDOWS\Internet Logs\xDBA7.tmp
    2006-11-30 02:57 14 ----a-w C:\Documents and Settings\Nicole\getfile.dat
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-05-28 10:33 1506544]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-07-09 09:05 919016]
    "AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [2008-08-02 10:00 579584]
    "SiSPower"="SiSPower.dll" [2005-01-04 17:54 49152 C:\WINDOWS\system32\SiSPower.dll]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "AVG7_Run"="C:\PROGRA~1\Grisoft\AVG7\avgw.exe" [2008-08-01 20:42 219136]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
    "RunNarrator"="Narrator.exe" [2003-03-31 05:00 51200 C:\WINDOWS\system32\narrator.exe]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 10:13 77824]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
    2007-04-19 13:41 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll

    R1 saicdr;saicdr;C:\WINDOWS\System32\drivers\saicdr.sys [2003-06-24 15:18]
    R1 saicdrwup;saicdrwup;C:\WINDOWS\System32\drivers\saicdrwup.sys [2003-05-16 15:32]
    R1 saiudf;saiudf;C:\WINDOWS\System32\drivers\saiudf.sys [2003-06-24 15:13]
    R3 SiS7012;Service for AC'97 Sample Driver (WDM);C:\WINDOWS\System32\drivers\sis7012.sys [2004-11-03 15:14]
    S3 cpuz129;cpuz129;C:\Program Files\PC Wizard 2008\pcwiz32.sys []
    S3 MemStPCI;Sony Memory Stick controller (PCI);C:\WINDOWS\System32\DRIVERS\MemStPCI.SYS [2002-08-29 01:28]
    S3 snpstd2;USB PC Camera (SN9C103);C:\WINDOWS\System32\DRIVERS\snpstd2.sys [2004-06-17 01:12]

    *Newly Created Service* - CATCHME
    *Newly Created Service* - PROCEXP90
    .
    Contents of the 'Scheduled Tasks' folder

    2008-07-02 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job
    - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
    .
    - - - - ORPHANS REMOVED - - - -

    HKCU-Run-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe


    .
    ------- Supplementary Scan -------
    .
    FireFox -: Profile - C:\Documents and Settings\Nicole\Application Data\Mozilla\Firefox\Profiles\13fxyk9d.default\
    FF -: plugin - C:\Documents and Settings\Nicole\Application Data\Mozilla\Firefox\Profiles\13fxyk9d.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp07076007.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\npsnapfish.dll
    FF -: plugin - C:\Program Files\Mozilla Firefox\plugins\NPZoneSB.dll


    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-08-04 20:20:07
    Windows 5.1.2600 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...


    **************************************************************************
    .
    Completion time: 2008-08-04 20:25:01
    ComboFix-quarantined-files.txt 2008-08-05 03:23:55

    Pre-Run: 52,914,610,176 bytes free
    Post-Run: 52,927,918,080 bytes free

    181
    I do not know what any of this means.
    So do I go on to the next step... MG tools or do I have something left to do about this Combo? :(
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions for posting logs! All logs must be attachments.
     
  19. ladyraven

    ladyraven Private E-2

    I tried, I have no idea how to do it!!! Do you think I just ignored what it said...........I tried it would not work! And I cannot even find logs... I cannot find log c:MGlogs.zip.***

    Then running MGTools, this keeps coming up...
    c:/Window/System 32/cmd.exe
    c;/progra~/Symantec/S32evnt.DLL.
    An installable Virtual Device Driver failed DLL intialization.
    And it kept coming up! and then

    OK, I am not being difficult, I am disable, dsylexic and my computer is my life and I am alone trying to fix this and no one taught me, and I am not a kid....so, I am not stupid.. I just do not grok what it is telling me to do, I cannot find the files and I cannot attach them.
     
  20. ladyraven

    ladyraven Private E-2

    I am stuck at this point and do not know what is going on or what to do.. :crybaby
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please be more specific. What exactly is happening? Are you watching for error messages in the Manage Attachments window.

    You need a slash in front of MGlogs.zip. Did you let MGtools finish running? Did you try just putting C:\MGlogs.zip into the Manage Attachments box. You don't need to browse for it.

    See the instructions for MGtools ( Using MGtools ) you were given in the READ & RUN ME.
     
  22. ladyraven

    ladyraven Private E-2

    I cannot find the logs.. I am about to give up, maybe this is way beyond me, I have tried for over 3 weeks to fix this, sometimes putting 5-8 hours a day, slowly working through this.........I do not know, I cannot find the logs
    :eek:
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on what you have posted thus far, I tend to doubt we will find any major malware problems. So what problem is it that we are actually trying to solve at this point because you may not be in the correct forum.

    Please read message # 21.
     
  24. ladyraven

    ladyraven Private E-2

    Thanks again, I hope this makes sense

    I put the log in the attachment and it is still not showing up! :-(
     
    Last edited: Aug 5, 2008
  25. ladyraven

    ladyraven Private E-2

    I tried this, not sure if it worked.
     

    Attached Files:

  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I think perhaps you should consider inviting over a friend who has more experience with computers. Maybe that will help you sort thru all of this a little easier.

    As I said in my other message, I don't think we have any malware problems to remove anyway.

    Hmmm! I see you attached the log. So I guess it really was there all along. However due to the error you had, the logs are incomplete.
     
  27. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    And note: The ComboFix log is right where the READ & RUN ME said it would be too. It shows in your MGlogs.zip file. It is C:\combofix.txt
     
  28. ladyraven

    ladyraven Private E-2

    OK, thanks. I am not going into the registry. When I look at how to fix the problem I am having re DLL, it says to go into the registry. I cannot afford to mess around in there! :)
    I still have scripts running and cannot open more than one window at a time, but, I guess I need to just stop.
    All my friends are online, most in the East Coast or in UK.
    Anyway, I give up. I did the best I can, thanks for all you time. Well, at least I got the file to attach...a miracle
    Thanks for your time.
    I did find one adware and one malware while I was following all the steps. Hopefully the computer just needs me to reformat it, now that should be fun for whoever tries to help.
    :)
     
  29. ladyraven

    ladyraven Private E-2

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't need to go into the registry anyway to fix the issue for running MGtools. As I have stated multiple times, you do not have malware problems. All I see is a bunch of left over stuff that Norton never removed. All of the below show in your Uninstall Programs list in the registry:
    • Norton AntiVirus
    • Norton Confidential Browser Component
    • Norton Confidential Web Protection Component
    • Norton Internet Security (Symantec Corporation)
    • Norton Internet Security
    • Norton Protection Center
    You should try running this Norton Removal Tool (SymNRT) then immediately reboot your PC and then repeat this step again!! It may remove the rest of this stuff. It is also probably Symantec that has messed up your registry and it the reason for the error you saw while running MGtools.

    At any rate, I suggest that you either find someone to help you reinstall your OS (if that is what you are wishing to do) or continue posting in the Software Forum as there is nothing for us to do in the Malware Forum.
     
  31. ladyraven

    ladyraven Private E-2

    Thanks, Spybot and Super Anti got 1 Malware 1 Trojan and 1 spyware. So, thank you for the Norton suggestion. I have not been able to get rid of it. Computer is running much better. I will check in OS and see if there directions on how to reformat a HD. Thanks for all your help.
    Hopefully I will not have to bother you again.
    I appreciate all your help.
    :)
     
  32. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds