Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: question about quarantined files/programs  (Read 11118 times)

0 Members and 1 Guest are viewing this topic.

geeray

    Topic Starter


    Rookie

    question about quarantined files/programs
    « on: January 21, 2009, 09:48:24 PM »
    just went through the steps in the pinned topic to update my antivirus and antispyware stuff.. when i have files that are quarantined should i delete them afterwards or leave them in the quarantined "area" or folder.  in my anit virus it asks if i want to delete them or quarantine them.. it also suggest to just quarantine them. 
    I guess my question is do i delete them or leave them in the quarantine folder?  I guess its a newbie question but oh well.

    thanks

    Hunter484



      Rookie

    • I soar free.
    • Thanked: 2
      Re: question about quarantined files/programs
      « Reply #1 on: January 21, 2009, 09:50:54 PM »
      I probably depends on the files and the anti-virus software you're using.  Details?
        

      geeray

        Topic Starter


        Rookie

        Re: question about quarantined files/programs
        « Reply #2 on: January 21, 2009, 10:07:03 PM »
        well i'm at home so i dont have the details of the files. but they were definite infected files.  i know that they need to be gone or not use.  i just wondered what the difference was from quarantined and me just deleting them alltogether. it looks like the antivirus cleared them from my drives.. it was a little confusing when it asked if i should delete or quarantine them.. not sure if i am making sense..

        oh, i use AntiVir Personal for my antivirus.  and what i mean is the AntiVir is detecting infected files and suggesting me delete them or quarantine them.  I quarantined them because that was what they suggested.  It says they have fixed the problem and blocked its usage.  I am just curious if i should delete the quarantine folder now that it is fixed. make sense

        Hunter484



          Rookie

        • I soar free.
        • Thanked: 2
          Re: question about quarantined files/programs
          « Reply #3 on: January 21, 2009, 10:13:06 PM »
          Well, I've never heard of AntiVir Personal, but when Avast sees an infection, it has a quarantine/clean/delete function.  You can quarantine an infected file (which just locks it up someplace where it can't hurt your computer), you can try to clean the rotten little bug out of the infected file, or you can just delete the whole thing.  The file it nabs is usually just the raw virus executable, so I usually pick the safe route, and delete the offending object.  I keep physical backups of my really important stuff anyway, so I don't have much to fear from viruses.  Avast also generates a virus recovery database, so if something important gets infected and you delete it, or a virus starts deleting stuff by itself, Avast can undo the damage.

          I would imagine your virus scanner treats the quarantine mode similarly.
            

          geeray

            Topic Starter


            Rookie

            Re: question about quarantined files/programs
            « Reply #4 on: January 21, 2009, 10:18:29 PM »
            yeah sounds like the same type of program. It was one of the three suggested on this forum (pinned topic at the top of viruses/spyware). 

            So in a nutshell quarantined files are protected (which i knew) and can be recovered.  I guess they suggest that so I can choose which one's i delete in case i need the file for something later.  thanks

            Hunter484



              Rookie

            • I soar free.
            • Thanked: 2
              Re: question about quarantined files/programs
              « Reply #5 on: January 21, 2009, 10:25:26 PM »
              Glad to help.  :)
                

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: question about quarantined files/programs
              « Reply #6 on: January 21, 2009, 10:32:48 PM »
              The rule of thumb is usually to leave them in quarantine for a day or two. If the computer is still running fine then delete them whenever you want. Sometimes a legitimate file is flagged/removed (false positive). It's easy to restore it from quarantine.

              geeray

                Topic Starter


                Rookie

                Re: question about quarantined files/programs
                « Reply #7 on: January 21, 2009, 10:34:27 PM »
                thanks alot

                geeray

                  Topic Starter


                  Rookie

                  Re: question about quarantined files/programs
                  « Reply #8 on: January 22, 2009, 07:11:44 AM »
                  MY LOGS WILL BE BELOW THIS......DOES ANYTHING LOOK UNUSUAL??

                  geeray

                    Topic Starter


                    Rookie

                    Re: question about quarantined files/programs
                    « Reply #9 on: January 22, 2009, 07:12:18 AM »
                    MY LOGS WILL BE BELOW THIS......DOES ANYTHING LOOK UNUSUAL??

                    MBAM

                    Malwarebytes' Anti-Malware 1.33
                    Database version: 1675
                    Windows 5.1.2600 Service Pack 3

                    1/22/2009 8:47:42 AM
                    mbam-log-2009-01-22 (08-47-42).txt

                    Scan type: Full Scan (C:\|D:\|)
                    Objects scanned: 108288
                    Time elapsed: 1 hour(s), 32 minute(s), 0 second(s)

                    Memory Processes Infected: 0
                    Memory Modules Infected: 0
                    Registry Keys Infected: 0
                    Registry Values Infected: 0
                    Registry Data Items Infected: 0
                    Folders Infected: 0
                    Files Infected: 5

                    Memory Processes Infected:
                    (No malicious items detected)

                    Memory Modules Infected:
                    (No malicious items detected)

                    Registry Keys Infected:
                    (No malicious items detected)

                    Registry Values Infected:
                    (No malicious items detected)

                    Registry Data Items Infected:
                    (No malicious items detected)

                    Folders Infected:
                    (No malicious items detected)

                    Files Infected:
                    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP773\A0068282.exe (Adware.PlayMP3Z) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787\A0068934.exe (Adware.Agent) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787\A0068935.exe (Adware.Agent) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787\A0068943.exe (Adware.Agent) -> Quarantined and deleted successfully.
                    C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP787\A0068944.exe (Adware.Agent) -> Quarantined and deleted successfully.

                    geeray

                      Topic Starter


                      Rookie

                      Re: question about quarantined files/programs
                      « Reply #10 on: January 22, 2009, 07:14:13 AM »
                      SUPERAntiSpyware Scan Log
                      http://www.superantispyware.com

                      Generated 01/22/2009 at 08:32 AM

                      Application Version : 4.25.1012

                      Core Rules Database Version : 3716
                      Trace Rules Database Version: 1690

                      Scan type       : Complete Scan
                      Total Scan Time : 01:24:11

                      Memory items scanned      : 551
                      Memory threats detected   : 0
                      Registry items scanned    : 5524
                      Registry threats detected : 0
                      File items scanned        : 21412
                      File threats detected     : 11

                      Malware.Installer-Pkg/Gen
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6B6A7665-DB48-4762-AB5D-BEEB9E1CD7FA}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{26D2C2C3-CF14-4ED7-B1FC-0BE64AFBA3B3}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{3C48F877-A164-45E9-B9DA-26A049FFC207}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{6293BC00-4EB8-4C65-8548-53E2FC3BF937}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{651956B7-1969-42AA-9453-E0B813019D54}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{989E4C3B-B2C9-4486-9A09-D5A8F953837C}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C0A0AA4D-C79B-48CA-8843-2B02B626C9E6}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{C2D8F0E2-6978-4409-8351-BA8785DA11EE}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{D1A6F3FD-7B40-443F-8767-BADB25A0D222}.EXE
                         C:\PROGRAM FILES\WILDTANGENT\APPS\DELL GAME CONSOLE\DOWNLOADS\INSTALLERS\{E0814F95-5380-4892-B8C8-7FA4B349EF46}.EXE

                      Trojan.Unclassified/SmartEnhancer-M
                         C:\SYSTEM VOLUME INFORMATION\_RESTORE{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP791\A0069564.DLL

                      geeray

                        Topic Starter


                        Rookie

                        Re: question about quarantined files/programs
                        « Reply #11 on: January 22, 2009, 07:16:56 AM »
                        Hijack--

                        Logfile of Trend Micro HijackThis v2.0.2
                        Scan saved at 9:16:36 AM, on 1/22/2009
                        Platform: Windows XP SP3 (WinNT 5.01.2600)
                        MSIE: Internet Explorer v7.00 (7.00.6000.16762)
                        Boot mode: Normal

                        Running processes:
                        C:\WINDOWS\System32\smss.exe
                        C:\WINDOWS\system32\winlogon.exe
                        C:\WINDOWS\system32\services.exe
                        C:\WINDOWS\system32\lsass.exe
                        C:\WINDOWS\system32\Ati2evxx.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\spoolsv.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        C:\WINDOWS\eHome\ehRecvr.exe
                        C:\WINDOWS\eHome\ehSched.exe
                        C:\Program Files\Linksys\WMP110\gtwpssrv.exe
                        C:\WINDOWS\Explorer.EXE
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                        C:\Program Files\Java\jre6\bin\jqs.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\WINDOWS\system32\slserv.exe
                        C:\WINDOWS\system32\svchost.exe
                        C:\Program Files\Linksys\WMP110\WLSngS.exe
                        C:\WINDOWS\ehome\ehtray.exe
                        C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                        C:\WINDOWS\stsystra.exe
                        C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                        C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                        C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
                        C:\Program Files\Napster\napster.exe
                        C:\Program Files\QuickTime\qttask.exe
                        C:\Program Files\Java\jre6\bin\jusched.exe
                        C:\Program Files\Linksys\WMP110\WMP110.exe
                        C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
                        C:\Program Files\Messenger\msmsgs.exe
                        C:\Program Files\MySpace\IM\MySpaceIM.exe
                        C:\Program Files\DellSupport\DSAgnt.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        C:\WINDOWS\system32\ctfmon.exe
                        C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
                        C:\Program Files\MySpace\IM\MySpaceIM.exe
                        C:\Program Files\Mozilla Firefox\firefox.exe
                        C:\WINDOWS\system32\dllhost.exe
                        C:\WINDOWS\eHome\ehmsas.exe
                        C:\WINDOWS\System32\svchost.exe
                        C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
                        C:\Program Files\Trend Micro\sniper.exe\sniper.exe.exe

                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.wildblue.net
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
                        R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us
                        R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com
                        O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
                        O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
                        O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                        O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                        O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                        O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
                        O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                        O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                        O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                        O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
                        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                        O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
                        O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
                        O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
                        O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
                        O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
                        O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                        O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                        O4 - HKLM\..\Run: [WMP110] C:\Program Files\Linksys\WMP110\WMP110.exe
                        O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                        O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
                        O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
                        O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\GARYHA~1\LOCALS~1\Temp\200912116312_mcappins.exe /v=3 /cleanup
                        O4 - HKLM\..\Run: [msci] C:\DOCUME~1\GARYHA~1\LOCALS~1\Temp\20091211638_mcinfo.exe /insfin
                        O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
                        O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
                        O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
                        O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
                        O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
                        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                        O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')
                        O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
                        O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                        O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
                        O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
                        O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
                        O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
                        O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
                        O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                        O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
                        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                        O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                        O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                        O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
                        O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                        O15 - Trusted Zone: http://www.partypoker.com
                        O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
                        O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
                        O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
                        O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cab
                        O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
                        O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
                        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
                        O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
                        O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                        O23 - Service: GTWPSSRV (GTWPSService) - Unknown owner - C:\Program Files\Linksys\WMP110\gtwpssrv.exe
                        O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                        O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                        O23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\Linksys\WMP110\jswpsapi.exe
                        O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
                        O23 - Service: SmartLinkService (SLService) -   - C:\WINDOWS\SYSTEM32\slserv.exe
                        O23 - Service: WLSng Service - TODO: <Company name> - C:\Program Files\Linksys\WMP110\WLSngS.exe

                        --
                        End of file - 11780 bytes

                        geeray

                          Topic Starter


                          Rookie

                          Re: question about quarantined files/programs
                          « Reply #12 on: January 22, 2009, 07:47:12 AM »
                          also not sure why but when i check my myspace page from firefox it brings up some weird log in page now. where before it didnt.. IE worked fine and page looked normal... any thoughts on that too

                          evilfantasy

                          • Malware Removal Specialist
                          • Moderator


                          • Genius
                          • Calm like a bomb
                          • Thanked: 493
                          • Experience: Experienced
                          • OS: Windows 11
                          Re: question about quarantined files/programs
                          « Reply #13 on: January 22, 2009, 11:45:18 AM »
                          Disable Spybot's TeaTimer

                          While TeaTimer is an excellent tool for the prevention of spyware, it can also interfere with HijackThis fixes. Please disable TeaTimer for now until you are clean.

                          1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident
                          2. Run Spybot S&D
                          3. Go to the Mode menu, and make sure Advanced Mode is selected.
                          4. On the left hand side, choose Tools > Resident
                          uncheck Resident TeaTimer and OK any prompt and Restart your computer.

                          Note:
                          If TeaTimer gives you a warning afterwards that some changes were made, allow this instead of blocking it.

                          If TeaTimer will not turn off then uninstall Spybot until we are done cleaning.

                          ----------

                          Open HijackThis and select Do a system scan only.

                          Place a check mark next to the following entries: (if there)

                          - O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\GARYHA~1\LOCALS~1\Temp\200912116312_mcappins.exe /v=3 /cleanup
                          - O4 - HKLM\..\Run: [msci] C:\DOCUME~1\GARYHA~1\LOCALS~1\Temp\20091211638_mcinfo.exe /insfin


                          Important: Close all windows except for HijackThis and then click Fix checked.

                          Exit HijackThis.

                          ----------

                          Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

                          Go to Start > Run and type notepad.exe then click OK

                          Copy and paste the below into Notepad and save as fixme.reg to Your Desktop

                          Code: [Select]
                          REGEDIT4

                          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
                          "Cleanup"=-
                          "msci"=-

                          Locate fixme.reg on your Desktop and double-click it. Answer Yes when prompted to merge with the Registry.

                          Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work.

                          Delete the fixme.reg from the Desktop.

                          ----------

                          Download ComboFix© by sUBs from one of the below links. Be sure top save it to the Desktop.

                          Link #1
                          Link #2

                          **Note:  It is important that it is saved directly to your Desktop

                          Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

                          Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
                           
                          Double click combofix.exe & follow the prompts.
                          When finished ComboFix will produce a log for you.
                          Post the ComboFix log in your next reply.

                          Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

                          Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

                          If you have problems with ComboFix usage, see How to use ComboFix

                          geeray

                            Topic Starter


                            Rookie

                            Re: question about quarantined files/programs
                            « Reply #14 on: January 22, 2009, 05:17:44 PM »
                            Disable Spybot's TeaTimer



                            1. Right click Spybot in the System Tray (looks like a calendar with a padlock symbol). Choose Exit Spybot S&D Resident
                            2. Run Spybot S&D
                            3. Go to the Mode menu, and make sure Advanced Mode is selected.
                            4. On the left hand side, choose Tools >Resident
                            uncheck Resident TeaTimer
                            and OK
                            any prompt and Restart your computer.

                            I omitted this in my first step because at the point of unchecking Resident Teatimer i only saw "Resident".  So I thought I did not have Teatimer.  I wasnt familar with what teatimer was.  I am not at my home computer at the moment so I cannot go back and verify.  I will however do so in the morning 7am EST.  If i only see resident like i remember should I uncheck that??

                            Thanks for the help so far