Jump to content

ShadowPuterDude

Emsisoft Employee
  • Posts

    20164
  • Joined

  • Last visited

  • Days Won

    214

Everything posted by ShadowPuterDude

  1. Thread Closed Reason: Lack of Response PM either ShadowPuterDude or Lynx to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  2. Using Add or Remove Programs in the Control Panel; uninstall the following: ----------------------------------------------------------- Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*). REGEDIT4 [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\browser helper objects\{A057A204-BACC-4D26-C4DC-6BA49CE16884}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{A057A204-BACC-4D26-C4DC-6BA49CE16884}"=- "{CCC7A320-B3CA-4199-B1A6-9F516DD69829}"=- Close Notepad. Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry. ----------------------------------------------------------- Attach fresh logs for: a-squared Free/Anti-Malware HiJackFree Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  3. Close all windows then double click on AVZ.exe Click File > Custom scripts Copy & paste the contents of the following codebox in the box in the program begin SetAVZGuardStatus(True); SearchRootkit(true, true); DeleteFile('pujadoli.dll'); BC_ImportDeletedList; ExecuteSysClean; RebootWindows(true); end. Note: When you run the script, your PC will be restarted Click Run Restart your PC if it doesn't do it automatically, and post back with a new HijackThis log. ----------------------------------------------------------- Attach fresh logs for: a-squared Free/Anti-Malware ISeeYouXP HiJackFree Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  4. Now we need to use ComboFix to remove some stuff. Make sure that the copy of combofix.exe that you downloaded earlier is on your Desktop but Do not run it! If it is not on your Desktop, the below will not work. Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ): KILLALL:: Driver:: BtwSrv NetSvc:: BtwSrv File:: c:\windows\system32\btwsrv.dll Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe At this point, you MUST EXIT ALL BROWSERS NOW before continuing! You should have both the ComboFix.exe and CFScript.txt icons on your Desktop. Now use your mouse to drag CFscript.txt on top of ComboFix.exe Follow the prompts. When it finishes, a log will be produced named c:\combofix.txt I will ask for this log below Note: DO NOT mouseclick combofix's window while it is running. That may cause it to stall. The ComboFix folder should not be renamed since ComboFix and even we would have suspicions about it. Also when you uninstall CF, the folder would not be removed since it does not look for that folder name. ----------------------------------------------------------- Attach fresh logs for: ComboFix (C:\combofix.txt) ISeeYouXP Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  5. Download ComboFix from one of these locations: Save as Combo-Fix.exe during the download. ComboFix must be renamed before you download to your Desktop Link 1 Link 2 Link 3 * IMPORTANT !!! Save Combo-Fix to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See HERE for help Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, ComboFix will produce a log. Note: 1. Do not mouseclick combofix's window while it's running. That may cause it to stall! 2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet. ----------------------------------------------------------- Attach fresh logs for: ComboFix (C:\combofix.txt) a-squared Free/Anti-Malware ISeeYouXP HiJackFree Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  6. Download ComboFix from one of these locations: Save as Combo-Fix.exe during the download. ComboFix must be renamed before you download to your Desktop Link 1 Link 2 Link 3 * IMPORTANT !!! Save Combo-Fix to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See HERE for help Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, ComboFix will produce a log. Note: 1. Do not mouseclick combofix's window while it's running. That may cause it to stall! 2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet. ----------------------------------------------------------- Attach fresh logs for: ComboFix (C:\combofix.txt) a-squared Free/Anti-Malware Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  7. Win32kDiag still failed to run completely. This may not work, but we are going to try anyway. ----------------------------------------------------------- Download ComboFix from one of these locations: Save as Combo-Fix.exe during the download. ComboFix must be renamed before you download to your Desktop Link 1 Link 2 Link 3 * IMPORTANT !!! Save Combo-Fix to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See HERE for help Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, ComboFix will produce a log. Note: 1. Do not mouseclick combofix's window while it's running. That may cause it to stall! 2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet. ----------------------------------------------------------- Attach fresh logs for: ComboFix (C:\combofix.txt) a-squared Free/Anti-Malware Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  8. Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*). Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager] "BootExecute"=hex(7):61,00,75,00,74,00,6f,00,63,00,68,00,65,00,63,00,6b,00,20,\ 00,61,00,75,00,74,00,6f,00,63,00,68,00,6b,00,20,00,2a,00,00,00,00,00 Close Notepad. Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry. ----------------------------------------------------------- Repair permissions: Download to your Desktop -->> Repair Permissions.exe <<-- self-extracting archive (117,015 bytes) - MD5: f4666e8f2acf6e1a12c655d56030d9e4 Double-click Repair Permissions.exe to install Repair Permissions Double-click on !RUNME.BAT You can safely ignore all errors. ----------------------------------------------------------- Attach fresh logs for: a-squared Free/Anti-Malware HiJackFree Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  9. Thread Closed Reason: Lack of Response PM either ShadowPuterDude or Lynx to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  10. Thread Closed Reason: Lack of Response PM either ShadowPuterDude or Lynx to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  11. Thread Closed Reason: Resolved The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  12. Thread Closed Reason: Lack of Response PM either ShadowPuterDude or Lynx to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  13. Download ComboFix from one of these locations: Save as Combo-Fix.exe during the download. ComboFix must be renamed before you download to your Desktop Link 1 Link 2 Link 3 * IMPORTANT !!! Save Combo-Fix to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools See HERE for help Double click on ComboFix.exe & follow the prompts. As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware. Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console. **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: Click on Yes, to continue scanning for malware. When finished, ComboFix will produce a log. Note: 1. Do not mouseclick combofix's window while it's running. That may cause it to stall! 2. Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet. ----------------------------------------------------------- Attach logs for: ComboFix (C:\combofix.txt) HiJackFree Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  14. Where is AVG finding msa.exe? Your a-squared log shows that it is no longer present in the Windows folder.
  15. Thread Closed Reason: Lack of Response PM either ShadowPuterDude or Lynx to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  16. Thread Closed Reason: Lack of Response PM either ShadowPuterDude or Lynx to have this thread reopened. The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  17. The installed version of Java on this computer is out-dated. Install Java Runtime Environment (JRE) 6u16 available from Sun Microsystems. ----------------------------------------------------------- Using Add or Remove Programs in the Control Panel; uninstall the following: ----------------------------------------------------------- We need to use ComboFix to remove some stuff. Make sure that the copy of combofix.exe that you downloaded earlier is on your Desktop but Do not run it! If it is not on your Desktop, the below will not work. Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ): KILLALL:: Registry:: [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "winntR1"=- File:: c:\winnt_\winntR1.exe Folder:: C:\winnt_ Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe At this point, you MUST EXIT ALL BROWSERS NOW before continuing! You should have both the ComboFix.exe and CFScript.txt icons on your Desktop. Now use your mouse to drag CFscript.txt on top of ComboFix.exe Follow the prompts. When it finishes, a log will be produced named c:\combofix.txt I will ask for this log below CAUTION: do NOT mouseclick combofix's window while it is running. That may cause it to stall. Note: The above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system. The ComboFix folder should NOT be renamed since ComboFix and even we would have suspicions about it. Also when you uninstall CF, the folder would not be removed since it does not look for that folder name. ----------------------------------------------------------- Attach fresh logs for: ComboFix (C:\combofix.txt) a-squared Free/Anti-Malware ISeeYouXP Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
  18. Copy the contents of the below quote box to Notepad; Save As FixReg.reg to your Desktop; make sure File Type: is set to All Files (*.*). REGEDIT4 [-HKEY_USERS\S-1-5-21-61316282-4026043858-3930591723-1000\software\NordBull] [-HKEY_USERS\S-1-5-21-61316282-4026043858-3930591723-1000\software\PopRock] [-HKEY_USERS\S-1-5-21-61316282-4026043858-3930591723-1000\Software\Monopod] [-HKEY_LOCAL_MACHINE\software\Classes\XML.XML] [-HKEY_USERS\S-1-5-21-61316282-4026043858-3930591723-1000\software\Microsoft\Windows\CurrentVersion\Ext\Stats\{500BCA15-57A7-4EAF-8143-8C619470B13D}] [-HKEY_USERS\S-1-5-21-61316282-4026043858-3930591723-1000\software\XML] Close Notepad. Locate FixReg.reg on your Desktop. Double-click on it and answer 'Yes' when asked if you want to merge with the registry. ----------------------------------------------------------- Reboot Attach a fresh a-squared log.
  19. Your friend is right. The problem is being created by something that is installed on your system. Uninstall: ZoneAlarm Spy Blocker Toolbar What's that do for system performance?
  20. Thread Closed Reason: Resolved The procedures contained in this thread are for this user and this user only. Attempting to use the instructions in this thread on your system could result in damaging the Operating System beyond repair. Do Not use any of the tools mentioned in this thread without the supervision of a Malware Removal Specialist. All posters requesting Malware Removal assistance are required to follow all procedures in the thread titled START HERE, if you don't we are just going to send you back to this thread
  21. OK, use this OTL fix instead: :OTL PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation) PRC - C:\WINDOWS\System32\spider.exe (Microsoft Corporation) SRV - (i1dinie0aa6iu6 [Auto | Stopped]) -- File not found SRV - (SDService [Auto | Stopped]) -- File not found O2 - BHO: (no name) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - No CLSID value found. O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0C6DD65A-F36B-4AC8-89EB-6175AEE6BB8C} - No CLSID value found. O33 - MountPoints2\{6bbb0dde-ba1f-11dd-b1ea-001aa00d76f7}\Shell\AutoRun\command - "" = setupSNK.exe O33 - MountPoints2\{7e2a9f8a-ddfc-11db-b160-001aa00d76f7}\Shell\AutoRun\command - "" = fppg1.exe O33 - MountPoints2\{7e2a9f8a-ddfc-11db-b160-001aa00d76f7}\Shell\explore\Command - "" = fppg1.exe O33 - MountPoints2\{7e2a9f8a-ddfc-11db-b160-001aa00d76f7}\Shell\open\Command - "" = fppg1.exe O34 - HKLM BootExecute: (SDEarlyDelete) - File not found O34 - HKLM BootExecute: (\??\C:\Program) - File not found O34 - HKLM BootExecute: (Files\SpywareDetector) - File not found :Files @C:\Documents and Settings\All Users\Application Data\TEMP:409C3BF5 @C:\Documents and Settings\All Users\Application Data\TEMP:4BB26BE9 @C:\Documents and Settings\All Users\Application Data\TEMP:FA5F15C4 @C:\Documents and Settings\All Users\Application Data\TEMP:44DAF2F1 @C:\Documents and Settings\All Users\Application Data\TEMP:9DA44E6B @C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2 @C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9 :Commands [purity] [emptytemp] [start explorer] [Reboot]
  22. Attach a fresh a-squared log. Be sure to tell me how things are running.
  23. Your Win32kDiag report is incomplete. Go to start > run and copy and paste the following command in the field: "%userprofile%\desktop\win32kdiag.exe" -f -r This should restore permissions on locked files. It will save a report on the Desktop (Win32kDiag.txt). Attach that report on your next reply.
  24. Download -->> OTL <<-- to your desktop. Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted. When the window appears, underneath Output at the top change it to Minimal Output. Check the boxes beside LOP Check and Purity Check. Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. Note: These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically. Attach both logs with your next reply.
×
×
  • Create New...