Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: computer infectd here are the logs requested  (Read 7782 times)

0 Members and 1 Guest are viewing this topic.

alyoob

    Topic Starter


    Intermediate

    Thanked: 1
    • Experience: Experienced
    • OS: Windows 8
    computer infectd here are the logs requested
    « on: March 20, 2010, 03:01:11 PM »
    Here are the logs attatched

    [Saving space, attachment deleted by admin]

    SuperDave

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: computer infectd here are the logs requested
    « Reply #1 on: March 21, 2010, 12:20:42 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    You're using an outdated version of SAS. Please download the newest version and follow these instructions.
    SUPERAntiSpyware

    Download SuperAntispyware Free Edition (SAS)
    * Double-click the icon on your desktop to run the installer.
    * When asked to Update the program definitions, click Yes
    * If you encounter any problems while downloading the updates, manually download and unzip them from here
    * Next click the Preferences button.

    •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
    * Click the Scanning Control tab.
    * Under Scanner Options make sure only the following are checked:

    •Close browsers before scanning
    •Scan for tracking cookies
    •Terminate memory threats before quarantining
    Please leave the others unchecked

    •Click the Close button to leave the control center screen.

    * On the main screen click Scan your computer
    * On the left check the box for the drive you are scanning.
    * On the right choose Perform Complete Scan
    * Click Next to start the scan. Please be patient while it scans your computer.
    * After the scan is complete a summary box will appear. Click OK
    * Make sure everything in the white box has a check next to it, then click Next
    * It will quarantine what it found and if it asks if you want to reboot, click Yes

    •To retrieve the removal information please do the following:
    •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
    •Click Preferences. Click the Statistics/Logs tab.

    •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

    •It will open in your default text editor (preferably Notepad).
    •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

    * Save the log somewhere you can easily find it. (normally the desktop)
    * Click close and close again to exit the program.
    *Copy and Paste the log in your post

    ===========================
    Please run MBAM and, this time, Be sure that everything is checked, and click Remove Selected.
    Post a new log.

    ===========================
    Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the desktop.

    =============================
    Open HijackThis and select Open the Misc Tools section. Select open process manager. select
    C:\WINDOWS\ALCXMNTR.EXE

    and click on kill process and exit HJT.
    =========================
    Copy and paste the text in the code box below into Notepad.
    Code: [Select]
    del C:\WINDOWS\ALCXMNTR.EXE

    exit

    Then click File > Save as
    Save to the Desktop as blackpudding.bat
    And Save as type: All Files.

    Double-click on blackpudding.bat to run it. It will only take a few seconds to run.

    Please run HJT and post a new log.
    Windows 8 and Windows 10 dual boot with two SSD's

    alyoob

      Topic Starter


      Intermediate

      Thanked: 1
      • Experience: Experienced
      • OS: Windows 8
      Re: computer infectd here are the logs requested
      « Reply #2 on: March 21, 2010, 03:49:26 PM »
      What do i do with the things in quarantine in the last scan with malwarebyte Befor I sacan again. Do I delete them.

      alyoob

        Topic Starter


        Intermediate

        Thanked: 1
        • Experience: Experienced
        • OS: Windows 8
        Re: computer infectd here are the logs requested
        « Reply #3 on: March 21, 2010, 05:11:16 PM »
        Here are the logs that you requested




        [Saving space, attachment deleted by admin]

        SuperDave

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: computer infectd here are the logs requested
        « Reply #4 on: March 22, 2010, 12:55:09 PM »
        Looking over your log it seems you don't have any Anti-Virus software.

        Before we continue, please download and install a free Anti-Virus.

        Remember to only install one antivirus!

        I recommend MSE because of its high efficiency rate and not being a resource hog.

        1) Avast! Home Edition
        2) AVG Free Edition
        3) Avira AntiVir Personal
        4) Microsoft Security Essentials for Windows Vista\Windows 7 - 64 bit Download
        4-a) Microsoft Security Essentials for Windows XP
        5) Comodo Antivirus (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" if you choose this one)
        6) PC Tools AntiVirus Free Edition

        It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

        ==============================

        1. Close all open Web browsers.
        2. From the Start menu in Windows select Control Panel.
        3. Select Add or Remove Programs.
        4. Uninstall any of the following programs associated with Ask.com: (the names may be slightly different)

        - Ask.com
        - Ask Bar
        - Ask Desktop Search
        - Ask Search
        - Ask Toolbar
        - Ask Jeeves

        5. Click Change/Remove for each and uninstall all found.
        Also look for Crawler or Crawler Toolbar and uninstall it.

        ================================

        Open HijackThis and select Do a system scan only

        Place a check mark next to the following entries: (if there)

        O3 - Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
        O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
        O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (file missing)
        O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Advanced Micro Devices - (no file)
        O23 - Service: Avira AntiVir Guard (AntiVirService) - Advanced Micro Devices - (no file)


        Important: Close all open windows except for HijackThis and then click Fix checked.

        Once completed, exit HijackThis.
        ================================

        Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

        link # 1
        link #2

        Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

        Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

        Vista users Right-click combofix.exe and select Run as Administrator and follow the prompts. (you will receive a UAC prompt, please allow it)

        Double-click combofix.exe and follow the prompts.
        When finished, ComboFix will produce a log for you.
        Post the ComboFix log and a new HijackThis log in your next reply.

        NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

        Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

        If you have problems with ComboFix usage, see How to use ComboFix

        Windows 8 and Windows 10 dual boot with two SSD's

        alyoob

          Topic Starter


          Intermediate

          Thanked: 1
          • Experience: Experienced
          • OS: Windows 8
          Re: computer infectd here are the logs requested
          « Reply #5 on: March 22, 2010, 10:03:56 PM »
          Cannot unistall crawler toolbar because it is important for my internet usage it warns me of websites that are harmful that i should not go to and blocks them for me.

          SuperDave

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: computer infectd here are the logs requested
          « Reply #6 on: March 23, 2010, 08:27:07 AM »
          Crawler ToolBar has a somewhat dubious reputation but it's up to you if you want to keep it.
          I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

          Did you download and run ComboFix?
          Windows 8 and Windows 10 dual boot with two SSD's

          alyoob

            Topic Starter


            Intermediate

            Thanked: 1
            • Experience: Experienced
            • OS: Windows 8
            Re: computer infectd here are the logs requested
            « Reply #7 on: March 23, 2010, 08:49:51 AM »
            About combofix I am having issues with combofix I ran the program and it went through all the steps then it restarted my computer when it came back to the screen that states preparing log report do not run any programs until combofix has finished the screen stayed there for a very long time and no log file was produced and so I exited combofix and there seems to be no log report produced. What should I do?

            SuperDave

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: computer infectd here are the logs requested
            « Reply #8 on: March 23, 2010, 09:53:26 AM »
            Please delete ComboFix from your desktop.

            Please download ComboFix from BleepingComputer.com

            Alternate link: GeeksToGo.com

            Alternate link: Forospyware.com

            Rename ComboFix.exe to commy.exe before you save it to your Desktop
            • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools ]A guide to do this can be found here
            • Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
            • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal.
            • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console


            Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

            Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


            • Click on Yes, to continue scanning for malware.
            • When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.
            Windows 8 and Windows 10 dual boot with two SSD's

            alyoob

              Topic Starter


              Intermediate

              Thanked: 1
              • Experience: Experienced
              • OS: Windows 8
              Re: computer infectd here are the logs requested
              « Reply #9 on: March 23, 2010, 12:52:10 PM »
              How do i know if the things combofix has detected are really infected and here is the log file



              [Saving space, attachment deleted by admin]

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: computer infectd here are the logs requested
              « Reply #10 on: March 23, 2010, 07:27:48 PM »
              ComboFix is a very trusted tool. It will take some time to go throught this log. Please be patient.
              Windows 8 and Windows 10 dual boot with two SSD's

              SuperDave

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: computer infectd here are the logs requested
              « Reply #11 on: March 23, 2010, 07:49:36 PM »
              Please go VirusTotal.com. Browse for this file:

              c:\windows\system32\user32.DLL

              Do the same for these two files:

              C:\windows\system32\userinit.exe
              C:\windows\explorer.exe


              Then click submit.

              If a pop-up appears saying the file has been scanned already, please select the ReScan button.

              Please post the results (URL) to your next reply.
              Windows 8 and Windows 10 dual boot with two SSD's


              Dr Jay

              • Malware Removal Specialist


              • Specialist
              • Moderator emeritus
              • Thanked: 119
              • Experience: Guru
              • OS: Windows 10
              Re: computer infectd here are the logs requested
              « Reply #13 on: March 24, 2010, 07:30:37 PM »
              Your computer is infected with a dangerous infection:
              http://www.helpmyos.com/malware-threat-removal-f6/virut-information-t879.htm

              We have hit a dead end. Please tell me when you have completed a reformat and reinstall.

              I am sorry for the bad news. I do not understand why these mean people make such harsh viruses, and I wish there was a way to clean your system without everything being damaged. But, the problem is, cleaning the system, most files will be damaged. It is like trying to clean up a city that just had a tornado or hurricane run through it. Takes rebuilding, and time to set back up.
              ~Dr Jay

              alyoob

                Topic Starter


                Intermediate

                Thanked: 1
                • Experience: Experienced
                • OS: Windows 8
                Re: computer infectd here are the logs requested
                « Reply #14 on: March 24, 2010, 11:28:08 PM »
                Your computer is infected with a dangerous infection:
                http://www.helpmyos.com/malware-threat-removal-f6/virut-information-t879.htm

                We have hit a dead end. Please tell me when you have completed a reformat and reinstall.

                I am sorry for the bad news. I do not understand why these mean people make such harsh viruses, and I wish there was a way to clean your system without everything being damaged. But, the problem is, cleaning the system, most files will be damaged. It is like trying to clean up a city that just had a tornado or hurricane run through it. Takes rebuilding, and time to set back up.


                I am sorry DragonMaster Jay I have to go with what SuperDave Jay has to say my computer runs fine.