Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Lots of problems with Laptop, Windowx XP  (Read 22586 times)

0 Members and 1 Guest are viewing this topic.

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Lots of problems with Laptop, Windowx XP
« Reply #15 on: December 21, 2008, 08:43:19 PM »
It is a rootkit and spybot isn't powerful enough to remove it. It takes specialized tools like ComboFix.

slafa23

    Topic Starter


    Beginner

    Re: Lots of problems with Laptop, Windowx XP
    « Reply #16 on: December 21, 2008, 08:45:05 PM »
    Should I fix that selected problem?

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Lots of problems with Laptop, Windowx XP
    « Reply #17 on: December 21, 2008, 08:47:03 PM »
    Please just follow the directions I posted here http://www.computerhope.com/forum/index.php/topic,72640.msg474754.html#msg474754

    If you start doing other things it will just make the whole process more difficult and time consuming :)

    slafa23

      Topic Starter


      Beginner

      Re: Lots of problems with Laptop, Windowx XP
      « Reply #18 on: December 21, 2008, 08:50:20 PM »
      Yes, I am about to. I was just finishing the scan and it appeared.

      slafa23

        Topic Starter


        Beginner

        Re: Lots of problems with Laptop, Windowx XP
        « Reply #19 on: December 21, 2008, 09:11:35 PM »
        ComboFix 08-12-21.04 - localadmin 2008-12-21 22:56:21.1 - NTFSx86
        Microsoft Windows XP Professional  5.1.2600.3.1252.1.1033.18.1014.526 [GMT -5:00]
        Running from: c:\documents and settings\localadmin\Desktop\ComboFix.exe
         * Created a new restore point
         * Resident AV is active


        WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
        .

        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        c:\documents and settings\localadmin\Local Settings\Temporary Internet Files\fbk.sts
        c:\windows\system\oeminfo.ini
        c:\windows\system32\AutoRun.inf
        c:\windows\system32\ddcCRLFx.dll
        c:\windows\system32\I775B4lw.exe.a_a
        c:\windows\system32\isukitil.ini
        c:\windows\system32\nnnllKBR.dll
        c:\windows\system32\nwplti.dll
        c:\windows\system32\oqmutk.dll
        c:\windows\system32\ovubuluw.ini
        c:\windows\system32\pezatehe.dll
        c:\windows\system32\pmxhmdgg.ini
        c:\windows\system32\prunnet.exe
        c:\windows\system32\qkckhnaq.dll
        c:\windows\system32\rljgwouo.dll
        c:\windows\system32\roblvvkg.ini
        c:\windows\system32\sawubiyi.dll
        c:\windows\system32\tagusoka.dll
        c:\windows\system32\TDSSbukt.dat

        .
        (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
        .

        -------\Legacy_TDSSSERV.SYS
        -------\Service_TDSSserv.sys


        (((((((((((((((((((((((((   Files Created from 2008-11-22 to 2008-12-22  )))))))))))))))))))))))))))))))
        .

        2008-12-21 22:52 . 2008-12-21 22:53   <DIR>   d--------   C:\32788R22FWJFW
        2008-12-21 13:22 . 2008-12-21 13:22   <DIR>   d--------   c:\program files\Alwil Software
        2008-12-21 03:23 . 2008-12-21 03:31   1,393   --a------   c:\windows\imsins.BAK
        2008-12-21 03:22 . 2008-12-21 03:32   2,973   --a------   c:\windows\system32\spupdsvc.inf
        2008-12-21 03:16 . 2006-12-29 00:31   19,569   --a------   c:\windows\000001_.tmp
        2008-12-21 01:04 . 2008-12-21 01:07   <DIR>   d--------   C:\267e3c904bc660664a57bf439b109f
        2008-12-19 22:20 . 2008-12-19 22:20   <DIR>   d--------   c:\documents and settings\localadmin\Application Data\VirusRemover2008
        2008-12-19 22:10 . 2008-12-21 12:59   2,710   --a------   c:\windows\system32\TDSSnnpa.dll
        2008-12-15 11:40 . 2008-04-13 22:57   79,872   -----c---   c:\windows\system32\dllcache\msxml6r.dll
        2008-12-15 11:40 . 2008-04-14 00:15   46,592   ---------   c:\windows\system32\drivers\irbus.sys
        2008-12-15 11:40 . 2008-04-14 05:42   10,752   --a------   c:\windows\system32\smtpapi.dll
        2008-12-15 11:40 . 2008-04-14 05:42   9,728   --a------   c:\windows\system32\rwnh.dll
        2008-12-15 11:40 . 2008-04-14 00:13   9,728   --a------   c:\windows\system32\comsdupd.exe
        2008-12-15 11:36 . 2008-12-15 11:40   <DIR>   d--------   c:\windows\ServicePackFiles
        2008-12-15 11:30 . 2006-12-29 00:31   19,569   --a------   c:\windows\003044_.tmp
        2008-12-15 10:38 . 2008-12-15 11:08   <DIR>   d--------   c:\program files\Spybot - Search & Destroy
        2008-12-15 10:38 . 2008-12-21 14:07   <DIR>   d--------   c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
        2008-12-15 10:37 . 2008-12-15 10:37   <DIR>   d--------   c:\program files\CCleaner
        2008-12-15 10:18 . 2008-06-10 02:32   73,728   --a------   c:\windows\system32\javacpl.cpl
        2008-12-14 17:12 . 2008-12-14 17:13   <DIR>   d--------   c:\program files\iTunes
        2008-12-14 17:12 . 2008-12-14 17:12   <DIR>   d--------   c:\program files\iPod
        2008-12-14 17:12 . 2008-12-14 17:13   <DIR>   d--------   c:\documents and settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
        2008-12-14 17:10 . 2008-12-14 17:10   <DIR>   d--------   c:\program files\QuickTime
        2008-12-01 23:25 . 2008-12-01 23:25   998   --a------   c:\windows\system32\SiteList.xml
        2008-11-28 12:43 . 2001-08-17 22:36   324,608   --a------   c:\windows\system32\hpojwia.dll
        2008-11-28 12:43 . 2001-08-17 22:36   324,608   --a--c---   c:\windows\system32\dllcache\hpojwia.dll
        2008-11-28 12:43 . 2001-07-21 20:27   18,411   --a------   c:\windows\system32\hpo5500a.aio
        2008-11-28 12:43 . 2001-07-21 20:27   18,411   --a------   c:\windows\system32\hpo5400a.aio
        2008-11-28 12:43 . 2001-07-21 20:27   18,411   --a------   c:\windows\system32\hpo5300a.aio
        2008-11-28 12:43 . 2001-08-17 13:47   12,928   --a------   c:\windows\system32\drivers\Dot4Prt.sys
        2008-11-28 12:43 . 2001-08-17 13:47   12,928   --a--c---   c:\windows\system32\dllcache\dot4prt.sys
        2008-11-28 12:43 . 2001-08-17 13:47   8,704   --a------   c:\windows\system32\drivers\Dot4scan.sys
        2008-11-28 12:43 . 2001-08-17 13:47   8,704   --a--c---   c:\windows\system32\dllcache\dot4scan.sys
        2008-11-28 12:42 . 2008-04-14 00:09   206,976   --a------   c:\windows\system32\drivers\dot4.sys
        2008-11-28 12:42 . 2001-08-17 13:47   23,808   --a------   c:\windows\system32\drivers\Dot4usb.sys
        2008-11-28 12:42 . 2001-08-17 13:47   23,808   --a--c---   c:\windows\system32\dllcache\dot4usb.sys
        2008-11-25 19:35 . 2008-11-29 20:32   <DIR>   d--------   c:\documents and settings\localadmin\Application Data\LimeWire
        2008-11-25 15:14 . 2008-11-25 15:14   <DIR>   d--hs----   c:\windows\ftpcache
        2008-11-24 17:01 . 2008-11-25 15:27   <DIR>   d--------   c:\documents and settings\localadmin\Application Data\Skype
        2008-11-24 16:58 . 2008-11-24 16:58   <DIR>   d--------   c:\program files\Skype
        2008-11-24 16:58 . 2008-11-24 16:58   <DIR>   d--------   c:\program files\Common Files\Skype
        2008-11-24 16:58 . 2008-11-24 16:58   <DIR>   d--------   c:\documents and settings\All Users\Application Data\Skype

        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2008-12-21 22:24   ---------   d-----w   c:\documents and settings\All Users\Application Data\Google Updater
        2008-12-15 15:27   ---------   d-----w   c:\program files\Viewpoint
        2008-12-15 15:27   ---------   d-----w   c:\documents and settings\localadmin\Application Data\Viewpoint
        2008-12-15 15:17   ---------   d-----w   c:\program files\Java
        2008-12-14 22:12   ---------   d-----w   c:\program files\Common Files\Apple
        2008-12-09 19:03   ---------   d-----w   c:\documents and settings\localadmin\Application Data\goombah
        2008-12-09 16:25   ---------   d-----w   c:\documents and settings\localadmin\Application Data\Ruckus Network
        2008-12-09 03:40   ---------   d--h--w   c:\documents and settings\localadmin\Application Data\Move Networks
        2008-10-24 11:21   455,296   ----a-w   c:\windows\system32\drivers\mrxsmb.sys
        .

        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4

        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "McAfeeUpdaterUI"="c:\program files\Network Associates\Common Framework\udaterui.exe" [2008-03-14 136512]
        "SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
        "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-03-11 49152]
        "ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-05-12 111952]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
        "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
        "avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2008-11-26 81000]

        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
        path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
        backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup

        [HKEY_LOCAL_MACHINE\software\microsoft\security center]
        "UpdatesDisableNotify"=dword:00000001

        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\AIM\\aim.exe"=
        "c:\\Program Files\\Network Associates\\Common Framework\\FrameworkService.exe"=
        "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
        "c:\\Program Files\\Ruckus Player\\Ruckus.exe"=
        "c:\\Program Files\\AIM6\\aim6.exe"=
        "c:\\WINDOWS\\system32\\dpvsetup.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
        "c:\\Program Files\\Skype\\Phone\\Skype.exe"=
        "c:\\Program Files\\iTunes\\iTunes.exe"=

        R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [2008-12-21 111184]
        R2 aswFsBlk;aswFsBlk;c:\windows\system32\DRIVERS\aswFsBlk.sys [2008-12-21 20560]
        R3 Eacfilt;Eacfilt Miniport;c:\windows\system32\DRIVERS\eacfilt.sys [2006-07-20 24521]
        S3 ExtranetAccess;Contivity VPN Service;"c:\program files\Nortel Networks\Extranet_serv.exe" [2006-07-20 811008]
        S3 IPSECEXT;Nortel Extranet Access Protocol;c:\windows\system32\DRIVERS\ipsecw2k.sys [2006-07-20 155184]

        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        hpdevmgmt   REG_MULTI_SZ      hpqcxs08 hpqddsvc
        .
        Contents of the 'Scheduled Tasks' folder

        2008-12-15 c:\windows\Tasks\AppleSoftwareUpdate.job
        - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

        2008-12-21 c:\windows\Tasks\At1.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-20 c:\windows\Tasks\At10.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-19 c:\windows\Tasks\At11.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-19 c:\windows\Tasks\At12.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-19 c:\windows\Tasks\At13.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At14.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At15.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At16.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At17.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At18.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At19.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At2.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-22 c:\windows\Tasks\At20.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-22 c:\windows\Tasks\At21.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-22 c:\windows\Tasks\At22.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-22 c:\windows\Tasks\At23.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At24.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At3.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At4.job
        - c:\windows\system32\I775B4lw.exe []

        2008-12-21 c:\windows\Tasks\At5.job
        - c:\windows\system32\I775B4lw.exe []

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Lots of problems with Laptop, Windowx XP
        « Reply #20 on: December 21, 2008, 09:24:55 PM »
        The bottom of the log is cut off. I need all of it.

        slafa23

          Topic Starter


          Beginner

          Re: Lots of problems with Laptop, Windowx XP
          « Reply #21 on: December 21, 2008, 09:27:04 PM »
          2008-12-21 c:\windows\Tasks\At6.job
          - c:\windows\system32\I775B4lw.exe []

          2008-12-21 c:\windows\Tasks\At7.job
          - c:\windows\system32\I775B4lw.exe []

          2008-12-21 c:\windows\Tasks\At8.job
          - c:\windows\system32\I775B4lw.exe []

          2008-12-21 c:\windows\Tasks\At9.job
          - c:\windows\system32\I775B4lw.exe []

          2008-12-22 c:\windows\Tasks\ujwctinm.job
          - c:\windows\system32\rundll32.exe [2008-04-14 05:42]
          .
          - - - - ORPHANS REMOVED - - - -

          BHO-{31e238aa-a2d4-4f9b-b4e4-70ddd27581b7} - c:\windows\system32\tagusoka.dll
          BHO-{386A2108-507B-40A6-BEAF-E1AF6E04974F} - c:\windows\system32\ddcCRLFx.dll
          BHO-{80b152d3-bb8d-4385-943c-6ea4029929a0} - c:\windows\system32\oqmutk.dll
          HKCU-Run-Aim6 - (no file)
          HKLM-Run-kuyesizadi - c:\windows\system32\sawubiyi.dll


          .
          ------- Supplementary Scan -------
          .
          uStart Page = hxxp://www.unh.edu/
          uDefault_Search_URL = hxxp://www.google.com/ie
          uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
          uInternet Connection Wizard,ShellNext = iexplore
          uInternet Settings,ProxyOverride = *.local
          uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
          IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
          Trusted Zone: *.amaena.com
          Trusted Zone: *.avsystemcare.com
          Trusted Zone: *.onerateld.com
          Trusted Zone: *.safetydownload.com
          Trusted Zone: *.trustedantivirus.com
          Trusted Zone: *.virusremover2008.com
          Trusted Zone: *.virusschlacht.com
          Trusted Zone: *.amaena.com
          Trusted Zone: *.avsystemcare.com
          Trusted Zone: *.onerateld.com
          Trusted Zone: *.safetydownload.com
          Trusted Zone: *.trustedantivirus.com
          Trusted Zone: *.virusremover2008.com
          Trusted Zone: *.virusschlacht.com
          FF - ProfilePath - c:\documents and settings\localadmin\Application Data\Mozilla\Firefox\Profiles\zfe0ojw5.default\
          FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-twc&p=
          FF - prefs.js: browser.search.selectedEngine - AIM Search
          FF - prefs.js: browser.startup.homepage - hxxp://www.unh.edu/
          FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&query=
          FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
          FF - plugin: c:\documents and settings\localadmin\Application Data\Mozilla\Firefox\Profiles\zfe0ojw5.default\extensions\[email protected]\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npmozax.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npnul32.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\NPOFFICE.DLL
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin2.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin3.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin4.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin5.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin6.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npqtplugin7.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npViewpoint.dll
          FF - plugin: c:\progra~1\Mozilla Firefox\plugins\npyaxmpb.dll
          FF - plugin: c:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
          FF - plugin: c:\program files\Microsoft Silverlight\2.0.31005.0\npctrl.dll
          FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
          FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
          FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll

          ATTENTION: FIREFOX POLICES IS IN FORCE
          c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("general.useragent.vendorComment", "ax");
          c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.xpconnect.activex.global.hosti ng_flags", 9);
          c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("security.classID.allowByDefault", false);
          c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID6B F52A52-394A-11D3-B153-00C04F79FAA6", "AllAccess");
          c:\program files\Mozilla Firefox\defaults\pref\activex.js - pref("capability.policy.default.ClassID.CID22 D6F312-B0F6-11D0-94AB-0080C74C7E95", "AllAccess");
          .

          **************************************************************************

          catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2008-12-21 23:05:36
          Windows 5.1.2600 Service Pack 3 NTFS

          scanning hidden processes ...

          scanning hidden autostart entries ...

          scanning hidden files ...

          scan completed successfully
          hidden files:

          **************************************************************************
          .
          ------------------------ Other Running Processes ------------------------
          .
          c:\program files\Alwil Software\Avast4\aswUpdSv.exe
          c:\program files\Alwil Software\Avast4\ashServ.exe
          c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          c:\program files\Bonjour\mDNSResponder.exe
          c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe
          c:\program files\Network Associates\Common Framework\FrameworkService.exe
          c:\program files\McAfee\VirusScan Enterprise\mcshield.exe
          c:\program files\McAfee\VirusScan Enterprise\vstskmgr.exe
          c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          c:\program files\Network Associates\Common Framework\naPrdMgr.exe
          c:\program files\Network Associates\Common Framework\Mctray.exe
          c:\program files\iPod\bin\iPodService.exe
          .
          **************************************************************************
          .
          Completion time: 2008-12-21 23:09:09 - machine was rebooted
          ComboFix-quarantined-files.txt  2008-12-22 04:09:02

          Pre-Run: 17,969,004,544 bytes free
          Post-Run: 17,763,332,096 bytes free

          277   --- E O F ---   2008-12-16 17:01:15

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Lots of problems with Laptop, Windowx XP
          « Reply #22 on: December 21, 2008, 09:30:36 PM »
          Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

          Delete these files/folders, as follows:

          1. Go to Start > Run > type Notepad.exe and click OK to open Notepad.
          It must be Notepad, not Wordpad.
          2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C

          Code: [Select]
          KillAll::

          Driver::
          -------\Legacy_TDSSSERV.SYS
          -------\Service_TDSSserv.sys

          File::
          c:\windows\000001_.tmp
          c:\windows\system32\TDSSnnpa.dll
          c:\windows\003044_.tmp
          c:\windows\Tasks\At1.job
          c:\windows\system32\I775B4lw.exe
          2008-12-20 c:\windows\Tasks\At10.job
          2008-12-19 c:\windows\Tasks\At11.job
          2008-12-19 c:\windows\Tasks\At12.job
          c:\windows\Tasks\At13.job
          c:\windows\Tasks\At14.job
          c:\windows\Tasks\At15.job
          c:\windows\Tasks\At16.job
          c:\windows\Tasks\At17.job
          c:\windows\Tasks\At18.job
          c:\windows\Tasks\At19.job
          c:\windows\Tasks\At2.job
          c:\windows\Tasks\At20.job
          c:\windows\Tasks\At21.job
          c:\windows\Tasks\At22.job
          c:\windows\Tasks\At23.job
          c:\windows\Tasks\At24.job
          c:\windows\Tasks\At3.job
          c:\windows\Tasks\At4.job
          c:\windows\Tasks\At5.job
          c:\windows\Tasks\At6.job
          c:\windows\Tasks\At7.job
          c:\windows\Tasks\At8.job
          c:\windows\Tasks\At9.job
          c:\windows\Tasks\ujwctinm.job

          Folder::
          c:\documents and settings\localadmin\Application Data\VirusRemover2008

          3. Go to the Notepad window and click Edit > Paste
          4. Then click File > Save
          5. Name the file CFScript.txt - Save the file to your Desktop
          6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!



          ComboFix will begin to execute, just follow the prompts.
          After reboot (in case it asks to reboot), it will produce a log for you.
          Post that log (Combofix.txt) in your next reply.

          Note: Do not mouseclick ComboFix's window while it is running. That may cause your system to freeze

          ----------

          After posting the ComboFix log.

          Download Malwarebytes' Anti-Malware (MBAM)

          • Double-click mbam-setup.exe and follow the prompts to install the program.
          • At the end, be sure a checkmark is placed next to the following:
            • Update Malwarebytes' Anti-Malware
            • Launch Malwarebytes' Anti-Malware
            • Then click Finish.
            • If an update is found, it will download and install the latest version.
            • Once the program has loaded, select Perform quick scan, then click Scan.
            • When the scan is complete, click OK, then Show Results to view the results.
            • Be sure that everything is checked, and click Remove Selected.
            • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
            • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
            • Copy and Paste the entire report in your next reply.
            Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

            ----------

            Download TrendMicro HijackThis.exe (HJT) to the Desktop.

            • Double-click on HJTInstall.
            • Click on the Install button.
            • It will automatically place HJT in C:\Program Files\TrendMicro\HijackThis\HijackThis.exe.
            • Upon install, HijackThis should open for you.
            • Click on the Do a system scan and save a log file button
            • HijackThis will scan and then a log will open in notepad.
            • Copy and then paste the entire contents of the log in your post.
            • Do not have HijackThis fix anything yet. Most of what it finds will be harmless or even required.

            slafa23

              Topic Starter


              Beginner

              Re: Lots of problems with Laptop, Windowx XP
              « Reply #23 on: December 21, 2008, 09:38:05 PM »
              I was doing the first part and I got an error message- "Were you trying to run CFScript? The name, CFScript appears to be incorrectly spelt."

              slafa23

                Topic Starter


                Beginner

                Re: Lots of problems with Laptop, Windowx XP
                « Reply #24 on: December 21, 2008, 09:43:28 PM »
                I'm assuming I just press Ok...

                slafa23

                  Topic Starter


                  Beginner

                  Re: Lots of problems with Laptop, Windowx XP
                  « Reply #25 on: December 21, 2008, 09:44:18 PM »
                  I did then the ComboFix screen went away.

                  evilfantasy

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Calm like a bomb
                  • Thanked: 493
                  • Experience: Experienced
                  • OS: Windows 11
                  Re: Lots of problems with Laptop, Windowx XP
                  « Reply #26 on: December 21, 2008, 09:47:28 PM »
                  Do this instead please.

                  Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system

                  Now download The Avenger by Swandog46 and save it to your Desktop.
                  • Extract avenger.exe from the Zip file and save it to your Desktop
                  • Run avenger.exe by double-clicking on it.
                  • Do not change any check box options!!
                  • Copy everything in the Code box below, and paste it into the Input script here window:
                  Code: [Select]
                  Comment:

                  Files to delete:
                  c:\windows\000001_.tmp
                  c:\windows\system32\TDSSnnpa.dll
                  c:\windows\003044_.tmp
                  c:\windows\Tasks\At1.job
                  c:\windows\system32\I775B4lw.exe
                  2008-12-20 c:\windows\Tasks\At10.job
                  2008-12-19 c:\windows\Tasks\At11.job
                  2008-12-19 c:\windows\Tasks\At12.job
                  c:\windows\Tasks\At13.job
                  c:\windows\Tasks\At14.job
                  c:\windows\Tasks\At15.job
                  c:\windows\Tasks\At16.job
                  c:\windows\Tasks\At17.job
                  c:\windows\Tasks\At18.job
                  c:\windows\Tasks\At19.job
                  c:\windows\Tasks\At2.job
                  c:\windows\Tasks\At20.job
                  c:\windows\Tasks\At21.job
                  c:\windows\Tasks\At22.job
                  c:\windows\Tasks\At23.job
                  c:\windows\Tasks\At24.job
                  c:\windows\Tasks\At3.job
                  c:\windows\Tasks\At4.job
                  c:\windows\Tasks\At5.job
                  c:\windows\Tasks\At6.job
                  c:\windows\Tasks\At7.job
                  c:\windows\Tasks\At8.job
                  c:\windows\Tasks\At9.job
                  c:\windows\Tasks\ujwctinm.job

                  Folders to delete:
                  c:\documents and settings\localadmin\Application Data\VirusRemover2008

                  Drivers to delete:
                  TDSSSERV
                  TDSSserv


                  • Now click the Execute button.
                  • Click Yes to the prompt to confirm you want to execute.
                  • Click Yes to the "Reboot now?" question that will appear when Avenger finishes running.
                  • Your PC should reboot, if not, reboot it yourself.
                  • A log file from Avenger will be produced at C:\avenger.txt and it will pop-up for you to view when you login after reboot.
                  • Add the Avenger log in your next post.

                  slafa23

                    Topic Starter


                    Beginner

                    Re: Lots of problems with Laptop, Windowx XP
                    « Reply #27 on: December 21, 2008, 09:57:34 PM »
                    Logfile of The Avenger Version 2.0, (c) by Swandog46
                    http://swandog46.geekstogo.com

                    Platform:  Windows XP

                    *******************

                    Script file opened successfully.
                    Script file read successfully.

                    Backups directory opened successfully at C:\Avenger

                    *******************

                    Beginning to process script file:

                    Rootkit scan active.
                    No rootkits found!

                    File "c:\windows\000001_.tmp" deleted successfully.
                    File "c:\windows\system32\TDSSnnpa.dll" deleted successfully.
                    File "c:\windows\003044_.tmp" deleted successfully.
                    File "c:\windows\Tasks\At1.job" deleted successfully.

                    Error:  file "c:\windows\system32\I775B4lw.exe" not found!
                    Deletion of file "c:\windows\system32\I775B4lw.exe" failed!
                    Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
                      --> the object does not exist


                    Error:  could not open file "2008-12-20 c:\windows\Tasks\At10.job"
                    Deletion of file "2008-12-20 c:\windows\Tasks\At10.job" failed!
                    Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
                      --> bad path / the parent directory does not exist


                    Error:  could not open file "2008-12-19 c:\windows\Tasks\At11.job"
                    Deletion of file "2008-12-19 c:\windows\Tasks\At11.job" failed!
                    Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
                      --> bad path / the parent directory does not exist


                    Error:  could not open file "2008-12-19 c:\windows\Tasks\At12.job"
                    Deletion of file "2008-12-19 c:\windows\Tasks\At12.job" failed!
                    Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
                      --> bad path / the parent directory does not exist

                    File "c:\windows\Tasks\At13.job" deleted successfully.
                    File "c:\windows\Tasks\At14.job" deleted successfully.
                    File "c:\windows\Tasks\At15.job" deleted successfully.
                    File "c:\windows\Tasks\At16.job" deleted successfully.
                    File "c:\windows\Tasks\At17.job" deleted successfully.
                    File "c:\windows\Tasks\At18.job" deleted successfully.
                    File "c:\windows\Tasks\At19.job" deleted successfully.
                    File "c:\windows\Tasks\At2.job" deleted successfully.
                    File "c:\windows\Tasks\At20.job" deleted successfully.
                    File "c:\windows\Tasks\At21.job" deleted successfully.
                    File "c:\windows\Tasks\At22.job" deleted successfully.
                    File "c:\windows\Tasks\At23.job" deleted successfully.
                    File "c:\windows\Tasks\At24.job" deleted successfully.
                    File "c:\windows\Tasks\At3.job" deleted successfully.
                    File "c:\windows\Tasks\At4.job" deleted successfully.
                    File "c:\windows\Tasks\At5.job" deleted successfully.
                    File "c:\windows\Tasks\At6.job" deleted successfully.
                    File "c:\windows\Tasks\At7.job" deleted successfully.
                    File "c:\windows\Tasks\At8.job" deleted successfully.
                    File "c:\windows\Tasks\At9.job" deleted successfully.
                    File "c:\windows\Tasks\ujwctinm.job" deleted successfully.
                    Folder "c:\documents and settings\localadmin\Application Data\VirusRemover2008" deleted successfully.

                    Error:  registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSSERV" not found!
                    Deletion of driver "TDSSSERV" failed!
                    Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
                      --> the object does not exist


                    Error:  registry key "\Registry\Machine\System\CurrentControlSet\Services\TDSSserv" not found!
                    Deletion of driver "TDSSserv" failed!
                    Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
                      --> the object does not exist


                    Completed script processing.

                    *******************

                    Finished!  Terminate.

                    evilfantasy

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Calm like a bomb
                    • Thanked: 493
                    • Experience: Experienced
                    • OS: Windows 11
                    Re: Lots of problems with Laptop, Windowx XP
                    « Reply #28 on: December 21, 2008, 10:02:15 PM »
                    We are getting closer, it missed a few files.

                    Download the OTMoveIt3 by OldTimer

                    Note: If you are running on Vista, right-click on OTMoveIt3.exe and choose Run As Administrator.

                    * Save it to your Desktop.
                    * Double-click OTMoveIt3.exe to run it.
                    * Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy)

                    Code: [Select]
                    :Processes
                    explorer.exe

                    :services

                    :reg

                    :files
                    c:\windows\Tasks\At10.job
                    c:\windows\Tasks\At11.job
                    c:\windows\Tasks\At12.job

                    :Commands
                    [purity]
                    [emptytemp]
                    [start explorer]
                    [Reboot]

                    * Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
                    * Click the red Moveit! button.
                    * Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
                    Close OTMoveIt3

                    Note: If a file or folder cannot be moved immediately you may be asked to reboot your computer in order to finish the move process. If asked to reboot, choose Yes. If not, reboot anyway.

                    slafa23

                      Topic Starter


                      Beginner

                      Re: Lots of problems with Laptop, Windowx XP
                      « Reply #29 on: December 21, 2008, 10:11:48 PM »
                      ========== PROCESSES ==========
                      Process explorer.exe killed successfully.
                      ========== SERVICES/DRIVERS ==========
                      ========== REGISTRY ==========
                      ========== FILES ==========
                      c:\windows\Tasks\At10.job moved successfully.
                      c:\windows\Tasks\At11.job moved successfully.
                      c:\windows\Tasks\At12.job moved successfully.
                      ========== COMMANDS ==========
                      User's Temp folder emptied.
                      User's Temporary Internet Files folder emptied.
                      User's Internet Explorer cache folder emptied.
                      Local Service Temp folder emptied.
                      Local Service Temporary Internet Files folder emptied.
                      File delete failed. C:\WINDOWS\temp\_avast4_\Webshlock.txt scheduled to be deleted on reboot.
                      File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7a8.dat scheduled to be deleted on reboot.
                      File delete failed. C:\WINDOWS\temp\WFV1.tmp scheduled to be deleted on reboot.
                      Windows Temp folder emptied.
                      Java cache emptied.
                      FireFox cache emptied.
                      Temp folders emptied.
                      Explorer started successfully
                       
                      OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12222008_000416

                      Files moved on Reboot...
                      File C:\WINDOWS\temp\_avast4_\Webshlock.txt not found!
                      C:\WINDOWS\temp\Perflib_Perfdata_7a8.dat moved successfully.
                      File C:\WINDOWS\temp\WFV1.tmp not found!