Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: My Logs  (Read 5245 times)

0 Members and 1 Guest are viewing this topic.

roco

    Topic Starter


    Rookie

    My Logs
    « on: September 14, 2010, 01:37:55 PM »
    Hello, I have been having issues with my desktop for a while now.I believe it started with crush alert popups out of no where. Even if I leave and come back there is this pop up alert and I never even visited that site before. Second my computer started to get this RUN DLL error,then would shut down without warning. Then I did a system restore hoping this would fix the issue then I got some security suite virus that totally took over my computer. I could not do anything like see control panel, run virus scan,every tab I clicked it would say that DLL is lost and to run that security suite. So I ran the virus scanner "Norton and AVG" in safe mode and that seems like a temp fix and this is why I am here. I have read and followed the directions of the "Read the before questioning" Forum and I have attached my logs  from Super Antispy, Snyper /HJT,and Malware..Thanks in advance





    [recovering disk space - old attachment deleted by admin]

    roco

      Topic Starter


      Rookie

      Re: My Logs
      « Reply #1 on: September 14, 2010, 10:25:08 PM »
      Ok here is the requested update of my mbam scan. If you need me to do anything else just let me know thanks!!

      Malwarebytes' Anti-Malware 1.46
      www.malwarebytes.org

      Database version: 4615

      Windows 5.1.2600 Service Pack 2
      Internet Explorer 7.0.5730.13

      9/14/2010 10:51:38 PM
      mbam-log-2010-09-14 (22-51-38).txt

      Scan type: Full scan (C:\|)
      Objects scanned: 248819
      Time elapsed: 1 hour(s), 13 minute(s), 50 second(s)

      Memory Processes Infected: 0
      Memory Modules Infected: 0
      Registry Keys Infected: 0
      Registry Values Infected: 0
      Registry Data Items Infected: 0
      Folders Infected: 0
      Files Infected: 1

      Memory Processes Infected:
      (No malicious items detected)

      Memory Modules Infected:
      (No malicious items detected)

      Registry Keys Infected:
      (No malicious items detected)

      Registry Values Infected:
      (No malicious items detected)

      Registry Data Items Infected:
      (No malicious items detected)

      Folders Infected:
      (No malicious items detected)

      Files Infected:
      C:\System Volume Information\_restore{5AEE0E5E-8117-4BE9-93C7-F3FF94160628}\RP533\A0106925.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: My Logs
      « Reply #2 on: September 17, 2010, 12:42:50 PM »
        Hello and welcome to
      Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

      1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
      2. The fixes are specific to your problem and should only be used for this issue on this machine.
      3. If you don't know or understand something, please don't hesitate to ask.
      4. Please DO NOT run any other tools or scans while I am helping you.
      5. It is important that you reply to this thread. Do not start a new topic.
      6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
      7. Absence of symptoms does not mean that everything is clear.

      I see you are running Poker Stars. Poker Stars has a history of distributing spyware in their products. However, security experts still question this program as good or bad. I recommend to remove it to prevent spyware, but it is up to you to decide if you want to keep it.

      If you would like to uninstall it, do so as follows:

      Press Start, and navigate to the Control Panel. When in the control panel enter Add or Remove programs. Search for and locate PokerStars, and either click Change/Remove or Remove.

      *******************************
      Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

      Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

      Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

      Exit out of MessengerDisable then delete the two files that were put on the desktop.

      *********************************************
      Open HijackThis and select Do a system scan only

      Place a check mark next to the following entries: (if there)

      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6092
      R3 - URLSearchHook: (no name) -  - (no file)
      O4 - HKLM\..\Run: [Qzujelapelepixo] rundll32.exe "C:\WINDOWS\usefoqesoda.dll",Startup
      O4 - HKCU\..\Run: [Hvatececisuwa] rundll32.exe "C:\WINDOWS\kbvcta.dll",Startup
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


      Important: Close all open windows except for HijackThis and then click Fix checked.

      Once completed, exit HijackThis.

      ***********************************
      Please download ComboFix from BleepingComputer.com

      Alternate link: GeeksToGo.com

      Rename ComboFix.exe to commy.exe before you save it to your Desktop
      Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
      Click Start>Run then copy paste the following command into the Run box & click OK "%userprofile%\desktop\commy.exe" /stepdel
      As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
      Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console[/list]

      Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

      Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


      Click on Yes, to continue scanning for malware.
      When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

      If you have problems with ComboFix usage, see How to use ComboFix

      ***********************************
      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
      * Open the Security Check folder and double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
      Windows 8 and Windows 10 dual boot with two SSD's