Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virus removal  (Read 10183 times)

0 Members and 1 Guest are viewing this topic.

SteveT

    Topic Starter


    Rookie

    Virus removal
    « on: March 07, 2010, 07:07:08 PM »
    i apparently have a virus on my system, I have followed the steps in the "Read this before requesting malware removal help" the logs follow.

    Thank you in advance for any assitance.

    [Saving space, attachment deleted by admin]

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Virus removal
    « Reply #1 on: March 08, 2010, 01:22:43 PM »
    I will check your logs and will be back in a little while. ;D
    Windows 8 and Windows 10 dual boot with two SSD's

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Virus removal
    « Reply #2 on: March 08, 2010, 01:43:34 PM »
    Hello SteveT and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

    Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

    Exit out of MessengerDisable then delete the two files that were put on the desktop.

    =============================================
    Open HijackThis and select Open the Misc Tools section. Select open process manager. select
    C:\2020v8\mswin\60\scbar.exe

    and click on kill process.
    Close HJT.

    ================================
    Download OTM by OldTimer to your desktop.

    Note: If you are running on Vista, right-click on OTM.exe and choose Run As Administrator.

    * Save it to your Desktop.
    * Double-click OTM.exe to run it.
    * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

    Code: [Select]
    :Processes
    explorer.exe

    :services

    :reg

    :files
    C:\2020v8\mswin\60\scbar.exe

    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]

    * Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
    * Click the red Moveit! button.
    * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    Close OTM

    Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

    =============================================

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    (Description: Intel hotkey applet. Unnecessary. Removing this will free up a small amount of system resources.)
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    (Description: HP software update checker and wizard launcher.)
    O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
    (Description: HP software update checker and wizard launcher.)
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] \"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe\"
    (Description: Adobe reader startup - unnecessarily uses system resources.)
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    (Description: Nvidia system tray applet. Not necessary. Removing this entry will free up a small amount of system resources.)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] \"C:\Program Files\Common Files\Java\Java Update\jusched.exe\"
    (Description: Sun Java update scheduler. Checks for updates. Not necessary. Removing this entry will free up a small amount of system resources.)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.

    ======================================

    Download ComboFix by sUBs from one of the below links.  Be sure to save it to the Desktop.

    link # 1
    link #2

    Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.

    Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

    Vista users Right-click combofix.exe and select Run as Administrator and follow the prompts. (you will receive a UAC prompt, please allow it)

    Double-click combofix.exe and follow the prompts.
    When finished, ComboFix will produce a log for you.
    Post the ComboFix log and a new HijackThis log in your next reply.

    NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

    Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.

    If you have problems with ComboFix usage, see How to use ComboFix

    Windows 8 and Windows 10 dual boot with two SSD's

    SteveT

      Topic Starter


      Rookie

      Re: Virus removal
      « Reply #3 on: March 14, 2010, 06:47:19 AM »
      Here are the logs



      [Saving space, attachment deleted by admin]

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Virus removal
      « Reply #4 on: March 14, 2010, 11:23:24 AM »
      Please go to Jotti's malware scan
      (If more than one file needs scanned they must be done separately and logs posted for each one)

      * Copy the file path in the below Code box:

      Code: [Select]
      c:\windows\system32\dllcache\moviemk.exe
      * At the upload site, click once inside the window next to Browse.
      * Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window.
      * Next click Submit file
      * Your file will possibly be entered into a queue which normally takes less than a minute to clear.
      * This will perform a scan across multiple different virus scanning engines.
      * Important: Wait for all of the scanning engines to complete.
      * Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.
       
      ===================================
      I noticed in your HJT log that you are running a P2P file-sharing program (Limewire ) on your computer. While the program itself is probably safe, the files you download with this program are a major source of infections. Therefore, I strongly urge you to uninstall it.


      Windows 8 and Windows 10 dual boot with two SSD's

      SteveT

        Topic Starter


        Rookie

        Re: Virus removal
        « Reply #5 on: March 14, 2010, 07:34:25 PM »
        http://virusscan.jotti.org/en/scanresult/f510a378582e4da24545e9fc873e4a260645b942/
        00aab9e6b596a0be8a72bc21579fc89f1b400bb e


        I have also uninstalled lime wire thanks for the advise
        « Last Edit: March 15, 2010, 08:44:23 AM by SuperDave »

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Virus removal
        « Reply #6 on: March 15, 2010, 08:46:42 AM »
        Could you please run ComboFix again and post the log?
        Windows 8 and Windows 10 dual boot with two SSD's

        SteveT

          Topic Starter


          Rookie

          Re: Virus removal
          « Reply #7 on: March 15, 2010, 08:05:13 PM »
          Here you go

          [Saving space, attachment deleted by admin]

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: Virus removal
          « Reply #8 on: March 16, 2010, 01:33:31 PM »
          ESET Online Scan

          Scan your computer with the ESET FREE Online Virus Scan

          * Click the ESET Online Scanner button.

          * For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
          * Click on the esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop
          * Double click on the esetsmartinstaller_enu.exe icon on your desktop.
          * Place a check mark next to YES, I accept the Terms of Use.

          * Click the Start button.
          * Accept any security warnings from your browser.
          * Leave the check mark next to Remove found threats and place a check next to Scan archives.
          * Click the Start button.
          * ESET will then download updates, install, and begin scanning your computer. Please be patient as this can take some time.
          * When the scan completes, click List of found threats.
          * Next click Export to text file and save the file to your desktop using a name such as ESETScan. Include the contents of this report in your next reply.
          * Click the Back button then click Finish.

          In your next reply please include the ESET Online Scan Log
          Windows 8 and Windows 10 dual boot with two SSD's

          SteveT

            Topic Starter


            Rookie

            Re: Virus removal
            « Reply #9 on: March 29, 2010, 04:51:37 PM »
            BUsy couple of weeks, thanks for you patience

            [recovering disk space - old attachment deleted by admin]

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Re: Virus removal
            « Reply #10 on: March 29, 2010, 08:00:35 PM »
            Everything looks ok now. If there are no other issues, it's time for some cleanup. You can uninstall HTJ and delete ESET. You may keep SAS and MBAM. Update them and run them regularly.

            To uninstall ComboFix

            • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
            • In the field, type in ComboFix /uninstall


            (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

            • Then, press Enter, or click OK.
            • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
            1.Double click OTM to launch it.
            Vista users right click and choose Run As Administrator
            2. Click on the CleanUp! button.
            3. OTM will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access.
            4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
            5. When finished exit out of OTM.

            Clean out your temporary internet files and temp files.

            Download TFC by OldTimer to your desktop.

            Double-click TFC.exe to run it.

            Note: If you are running on Vista, right-click on the file and choose Run As Administrator

            TFC will close all programs when run, so make sure you have saved all your work before you begin.

            * Click the Start button to begin the cleaning process.
            * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
            * Please let TFC run uninterrupted until it is finished.

            Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

            Use the Secunia Software Inspector to check for out of date software.

            •Click Start Now

            •Check the box next to Enable thorough system inspection.

            •Click Start

            •Allow the scan to finish and scroll down to see if any updates are needed.
            •Update anything listed.
            .
            ----------

            Go to Microsoft Windows Update and get all critical updates.

            ----------

            I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

            SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware
            * If you don't know what ActiveX controls are, see here

            Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
            Safe Surfing! ;D
            Windows 8 and Windows 10 dual boot with two SSD's