Welcome Guest ( Login | Register )
        

12»»

Removing behaveslike.win32.malware.wsc (mx-v)... Expand / Collapse
Author
Message
Posted 2/13/2012 3:31 PM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 6/23/2008 4:33 PM
Posts: 164, Visits: 90
Hi,

My mom's computer isn't running very fast so I ran a PC Tuneup test and it said she has a Trojan called behaveslike.win32.malware.wsc (mx-v). Can you please advise how to remove it?

Thanks,
Scott
  Post #263267
 
Posted 2/14/2012 4:03 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 36,777, Visits: 54,734
Hello Scott

Please download Malwarebytes Anti-Malware from Here or Here.
Double Click mbam-setup.exe to install the application.
(If using Windows Vista/Windows 7,be sure to "Run As Administrator").

* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select "Perform Full Scan",then click "Scan".
* Make sure ALL partitions/hard drives are selected in the opening box,then click "Start Scan".
* The scan will certainly take some time to finish so please be patient.
* When the scan is complete, click OK, then click Show Results to view the results.
* Make sure everything is checkmarked, and then click Remove Selected.
* When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
* The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
* Copy and paste the entire report into your next reply.

Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Now scan your machine with ESET OnlineScan
* Hold down Control and click on this link to open ESET OnlineScan in a new window.
* Click the button.
* For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
* Click on esetsmartinstaller_enu.exe to download the ESET Smart Installer. Save it to your desktop.
* Double click on the
icon on your desktop.
* Check "YES, I accept the Terms of Use."
* Click the Start button.
* Accept any security warnings from your browser.
* Under scan settings, check "Scan Archives" and "Remove found threats"
* Click Advanced settings and select the following:
* Scan potentially unwanted applications
* Scan for potentially unsafe applications
* Enable Anti-Stealth technology
* ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
* When the scan completes, click List Threats
* Click Export, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
* Click the Back button.
* Click the Finish button.


___________________________________________________________







  Post #263280
 
Posted 3/1/2012 11:39 AM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 6/23/2008 4:33 PM
Posts: 164, Visits: 90
ESET Found no threats so there was no log. Here's the MBAM log:

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.02.28.05

Windows XP Service Pack 3 x86 NTFS
Internet Explorer 8.0.6001.18702
MgrCA60 :: HOME [administrator]

2/28/2012 12:16:37 PM
mbam-log-2012-02-28 (12-16-37).txt

Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 263350
Time elapsed: 3 hour(s), 20 minute(s), 53 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\Program Files\eMusic Download Manager\winamp_plugin.exe (Adware.BHO) -> Quarantined and deleted successfully.

(end)
  Post #263416
 
Posted 3/1/2012 1:46 PM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 36,777, Visits: 54,734
Download ComboFix from Here or Here to your Desktop.

* Now temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
Click Here to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.

* Close any open browsers.
* WARNING: Combofix will disconnect your machine from the Internet as soon as it starts.
* Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
* If there is no internet connection after running Combofix, then restart your computer to restore back your connection.

* Double click on ComboFix.exe & follow the prompts,if you're running Windows Vista\Windows 7 right click on ComboFix.exe and click on "Run as Administrator".
* When finished, it will produce a report for you.
* Please post the contents of "C:\Combo-Fix.txt" into your next reply.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

**VERY IMPORTANT**
* As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
* Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures**



Once the Microsoft Windows Recovery Console is installed using ComboFix,you should see the following message:




Post the following in your next reply:
The contents of C:\ComboFix.txt


___________________________________________________________







  Post #263417
 
Posted 3/1/2012 6:39 PM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 6/23/2008 4:33 PM
Posts: 164, Visits: 90
ComboFix 12-03-01.02 - MgrCA60 03/01/2012 16:23:30.2.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.459 [GMT -8:00]
Running from: c:\documents and settings\MgrCA60\Desktop\ComboFix.exe
AV: Norton AntiVirus *Disabled/Updated* {E10A9785-9598-4754-B552-92431C1C35F8}
.
.
((((((((((((((((((((((((( Files Created from 2012-02-02 to 2012-03-02 )))))))))))))))))))))))))))))))
.
.
2012-02-29 00:36 . 2012-02-29 00:36 -------- d-----w- c:\windows\LastGood
2012-02-28 20:15 . 2012-02-28 20:16 40776 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2012-02-15 07:08 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\iacenc.dll
2012-02-15 07:08 . 2012-01-11 19:06 3072 ------w- c:\windows\system32\dllcache\iacenc.dll
2012-02-13 20:10 . 2012-02-13 20:21 -------- d-----w- c:\documents and settings\All Users\Application Data\PCPitstop
2012-02-13 20:10 . 2012-02-13 21:12 -------- d-----w- c:\program files\PCPitstop
2012-02-10 01:59 . 2012-02-10 01:59 -------- d-----w- c:\program files\AOL Toolbar
2012-02-10 01:59 . 2012-02-10 01:59 -------- d-----w- c:\documents and settings\All Users\Application Data\AOL Toolbar
2012-02-10 01:59 . 2012-02-10 01:59 -------- d-----w- c:\documents and settings\MgrCA60\Local Settings\Application Data\AOL Toolbar
2012-02-10 01:59 . 2012-02-10 01:59 -------- d-----w- c:\program files\Common Files\Software Update Utility
2012-02-10 01:55 . 2012-02-13 18:38 -------- d-----w- c:\program files\AOL Desktop 9.7
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-02-29 00:30 . 2011-12-20 21:26 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-02-10 01:31 . 2011-04-23 22:08 58696 ----a-w- c:\windows\system32\AOLParconLink.exe
2012-01-31 18:25 . 2012-01-31 18:25 348160 ----a-w- c:\windows\system32\msvcr71.dll
2012-01-31 18:25 . 2012-01-31 18:25 499712 ----a-w- c:\windows\system32\msvcp71.dll
2012-01-12 16:53 . 2003-09-25 15:35 1859968 ----a-w- c:\windows\system32\win32k.sys
2011-12-17 19:46 . 2005-04-27 17:54 916992 ----a-w- c:\windows\system32\wininet.dll
2011-12-17 19:46 . 2004-03-19 23:38 43520 ----a-w- c:\windows\system32\licmgr10.dll
2011-12-17 19:46 . 2004-03-19 23:38 1469440 ------w- c:\windows\system32\inetcpl.cpl
2011-12-16 12:22 . 2004-08-04 05:59 385024 ----a-w- c:\windows\system32\html.iec
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{9ee802e8-c931-47ab-b570-aa8f791598ca}"= "c:\program files\eMusic\prxtbeMu2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}]
2011-01-17 14:54 175912 ----a-w- c:\program files\ConduitEngine\prxConduitEngine.dll
.
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
2011-01-17 14:54 175912 ----a-w- c:\program files\eMusic\prxtbeMu2.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{9ee802e8-c931-47ab-b570-aa8f791598ca}"= "c:\program files\eMusic\prxtbeMu2.dll" [2011-01-17 175912]
"{30F9B915-B755-4826-820B-08FBA6BD249D}"= "c:\program files\ConduitEngine\prxConduitEngine.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
.
[HKEY_CLASSES_ROOT\clsid\{30f9b915-b755-4826-820b-08fba6bd249d}]
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{9EE802E8-C931-47AB-B570-AA8F791598CA}"= "c:\program files\eMusic\prxtbeMu2.dll" [2011-01-17 175912]
.
[HKEY_CLASSES_ROOT\clsid\{9ee802e8-c931-47ab-b570-aa8f791598ca}]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"AOL Fast Start"="c:\program files\AOL Desktop 9.7\AOL.EXE" [2012-01-31 42320]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2010-07-13 70720]
"HostManager"="c:\program files\Common Files\AOL\1161130004\ee\AOLSoftware.exe" [2010-03-08 41800]
"Pure Networks Port Magic"="c:\progra~1\PURENE~1\PORTMA~1\PortAOL.exe" [2004-05-07 99480]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-10-07 111856]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-06-15 141624]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-02 843712]
"Info Center"="c:\program files\PCPitstop\Info Center\InfoCenter.exe" [2012-02-01 26264]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-19 421888]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0SsiEfr.ex
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Acrobat Assistant.lnk
backup=c:\windows\pss\Acrobat Assistant.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HP Image Zone Fast Start.lnk
backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^UPS WorldShip PLD Reminder Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\UPS WorldShip PLD Reminder Utility.lnk
backup=c:\windows\pss\UPS WorldShip PLD Reminder Utility.lnkCommon Startup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2012-01-04 06:51 37296 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2010-06-10 03:55 49208 ----a-w- c:\program files\HP\HP Software Update\hpwuschd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 23:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-19 05:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-10-17 23:57 26112 ----a-w- c:\program files\Real\RealPlayer\realplay.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"FirewallOverride"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\America Online 9.0\\waol.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Common Files\\AOL\\1161130004\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\AOL Desktop 9.6\\waol.exe"=
"c:\\Program Files\\AOL Desktop 9.7\\waol.exe"=
"c:\\Program Files\\AOL Desktop 9.7\\AOLBrowser\\aolbrowser.exe"=
.
R0 SymEFA;Symantec Extended File Attributes;c:\windows\SYSTEM32\DRIVERS\NAV\1008030.006\SymEFA.sys [10/11/2011 4:11 PM 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\SYSTEM32\DRIVERS\NAV\1008030.006\BHDrvx86.sys [10/11/2011 4:11 PM 259632]
R1 ccHP;Symantec Hash Provider;c:\windows\SYSTEM32\DRIVERS\NAV\1008030.006\cchpx86.sys [10/11/2011 4:10 PM 467592]
R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20120229.002\IDSXpx86.sys [2/29/2012 4:00 PM 356280]
R2 Norton AntiVirus;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\16.8.3.6\ccSvcHst.exe [10/11/2011 4:10 PM 117648]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2/8/2012 10:14 AM 106104]
R4 MBAMProtector;MBAMProtector;\??\c:\windows\system32\drivers\mbam.sys --> c:\windows\system32\drivers\mbam.sys [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/15/2012 11:27 AM 136176]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/15/2012 11:27 AM 136176]
S3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\SYSTEM32\DRIVERS\mbamswissarmy.sys [2/28/2012 12:15 PM 40776]
.
Contents of the 'Scheduled Tasks' folder
.
2012-02-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 20:34]
.
2012-03-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-15 19:26]
.
2012-03-01 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2012-01-15 19:26]
.
2012-02-29 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAEXEC.exe [2009-08-03 23:07]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://www.yahoo.com
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycdict.htm
TCP: DhcpNameServer = 192.168.1.1 192.168.1.1
DPF: PackageCab - hxxp://ak.imgag.com/imgag/cp/install/AxCtp2.cab
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-PC Pitstop PC Matic Reminder - c:\program files\PCPitstop\PC Matic\Reminder-PCMatic.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-03-01 16:33
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet003\Services\Norton AntiVirus]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\16.8.3.6\ccSvcHst.exe\" /s \"Norton AntiVirus\" /m \"c:\program files\Norton AntiVirus\Engine\16.8.3.6\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'explorer.exe'(2652)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
Completion time: 2012-03-01 16:38:06
ComboFix-quarantined-files.txt 2012-03-02 00:38
ComboFix2.txt 2010-04-27 18:23
.
Pre-Run: 20,103,024,640 bytes free
Post-Run: 20,242,587,648 bytes free
.
- - End Of File - - 7530676D2D29AF00F7BC428B547C5B52
  Post #263421
 
Posted 3/2/2012 1:38 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 36,777, Visits: 54,734
Click on Start/Run,copy and paste ComboFix /uninstall into the 'Open:' space,then press OK [see image below]
This will remove Combofix.



Find and delete if still present:
C:\ComboFix.txt
C:\QOOBOX
C:\ComboFix


Download TFC by OldTimer to your Desktop.
* Please double-click TFC.exe to run it,if you're running Windows Vista right click on TFC.exe and click on "Run as Administrator".
* It will close all programs when run, so make sure you have saved all your work before you begin.
* Click the Start button to begin the process. Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Let it run uninterrupted until it's finished.
* Once it's finished it should reboot your machine.If it doesn't,please manually restart the pc to ensure a complete cleanup.


Download Security Check by screen317 and save it to your Desktop.
Double-click on SecurityCheck.exe and follow the on-screen instructions inside the black box.
Notepad should open a file named checkup.txt.
Copy and paste the entire contents of that file into your next reply.


Run SUPERAntiSpyware by following the steps in the link below,please post the log into your next reply when you're finished.
How to use SUPERAntiSpyware:
http://www.bleepingcomputer.com/virus-removal/how-to-use-superantispyware-tutorial

Obtain the SuperAntiSpyware log as follows:
Click on 'Preferences'.
Click on the 'Statistics/Logs' tab.
Under 'Scanner Logs' double click on 'SuperAntiSpyware Scan Log'.
It will then open in your default text editor,such as Notepad.
Copy and paste the contents of that report into your next reply.

Also let me know how your pc is running now.


___________________________________________________________







  Post #263426
 
Posted 3/2/2012 1:44 PM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 6/23/2008 4:33 PM
Posts: 164, Visits: 90
Results of screen317's Security Check version 0.99.31
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Disabled!
Norton AntiVirus
Antivirus up to date!
```````````````````````````````
Anti-malware/Other Utilities Check:

Yahoo! Anti-Spy
CCleaner
Java(TM) 6 Update 29
[color=red]Java version out of date![/color]
Adobe Reader 9 [color=red]Adobe Reader out of date![/color]
Adobe Reader 8 [color=red]Adobe Reader out of date![/color]
````````````````````````````````
Process Check:
objlist.exe by Laurent

Norton ccSvcHst.exe
``````````End of Log````````````

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 03/02/2012 at 10:26 AM

Application Version : 5.0.1144

Core Rules Database Version : 8298
Trace Rules Database Version: 6110

Scan type : Quick Scan
Total Scan Time : 00:08:48

Operating System Information
Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
Administrator

Memory items scanned : 562
Memory threats detected : 0
Registry items scanned : 29283
Registry threats detected : 0
File items scanned : 6893
File threats detected : 48

Adware.Tracking Cookie
C:\Documents and Settings\MgrCA60\Cookies\CTG73464.txt [ /doubleclick.net ]
C:\Documents and Settings\MgrCA60\Cookies\V0CE5574.txt [ /sexyforever.com ]
C:\Documents and Settings\MgrCA60\Cookies\BMON4VI8.txt [ /ads.livenation.com ]
C:\Documents and Settings\MgrCA60\Cookies\ZYT2BRTK.txt [ /kontera.com ]
C:\Documents and Settings\MgrCA60\Cookies\GM15A0IX.txt [ /zedo.com ]
C:\Documents and Settings\MgrCA60\Cookies\UZSLNJMJ.txt [ /fastclick.net ]
C:\Documents and Settings\MgrCA60\Cookies\F93BX0OB.txt [ /a1.interclick.com ]
C:\Documents and Settings\MgrCA60\Cookies\3V9XUXS1.txt [ /atwola.com ]
C:\Documents and Settings\MgrCA60\Cookies\JY6H31FE.txt [ /ar.atwola.com ]
C:\Documents and Settings\MgrCA60\Cookies\14318YP6.txt [ /imrworldwide.com ]
C:\Documents and Settings\MgrCA60\Cookies\RGXB5449.txt [ /adserver.zonemedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\HLULRBI0.txt [ /apmebf.com ]
C:\Documents and Settings\MgrCA60\Cookies\I7N2LXR3.txt [ /accounts.google.com ]
C:\Documents and Settings\MgrCA60\Cookies\7TZALKIX.txt [ /lucidmedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\PEDUVP1F.txt [ /www.googleadservices.com ]
C:\Documents and Settings\MgrCA60\Cookies\7SZTDO8M.txt [ /at.atwola.com ]
C:\Documents and Settings\MgrCA60\Cookies\HY5TH21D.txt [ /pointroll.com ]
C:\Documents and Settings\MgrCA60\Cookies\2XUIWQA4.txt [ /adxpose.com ]
C:\Documents and Settings\MgrCA60\Cookies\3V1GJ55F.txt [ /mediaplex.com ]
C:\Documents and Settings\MgrCA60\Cookies\KQ0L8DZK.txt [ /openads2.sportsvite.com ]
C:\Documents and Settings\MgrCA60\Cookies\PE3HTB28.txt [ /www.sexyforever.com ]
C:\Documents and Settings\MgrCA60\Cookies\HPC4GI1B.txt [ /2o7.net ]
C:\Documents and Settings\MgrCA60\Cookies\MWYRFLC9.txt [ /interclick.com ]
C:\Documents and Settings\MgrCA60\Cookies\CE4HBUTC.txt [ /c.gigcount.com ]
C:\Documents and Settings\MgrCA60\Cookies\KSZK1OYO.txt [ /www.googleadservices.com ]
C:\Documents and Settings\MgrCA60\Cookies\T1EHXVW7.txt [ /casalemedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\O3KQO0RQ.txt [ /amazon-adsystem.com ]
C:\Documents and Settings\MgrCA60\Cookies\JUSE6NV8.txt [ /andomedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\XK58RN9X.txt [ /ads.undertone.com ]
C:\Documents and Settings\MgrCA60\Cookies\1Z2G5IYZ.txt [ /atdmt.com ]
C:\Documents and Settings\MgrCA60\Cookies\EJS7W4WB.txt [ /media6degrees.com ]
C:\Documents and Settings\MgrCA60\Cookies\GXMPALRT.txt [ /cdn.at.atwola.com ]
C:\Documents and Settings\MgrCA60\Cookies\UJO9HHP5.txt [ /ad.wsod.com ]
C:\Documents and Settings\MgrCA60\Cookies\B0WNZU4D.txt [ /stats.paypal.com ]
C:\Documents and Settings\MgrCA60\Cookies\VM1741ZV.txt [ /collective-media.net ]
C:\Documents and Settings\MgrCA60\Cookies\3TEBNKX3.txt [ /tacoda.at.atwola.com ]
C:\Documents and Settings\MgrCA60\Cookies\21CI0JHX.txt [ /summitbusinessmedia.112.2o7.net ]
C:\Documents and Settings\MgrCA60\Cookies\E984ZQIP.txt [ /ad.yieldmanager.com ]
C:\Documents and Settings\MgrCA60\Cookies\181E409P.txt [ /stats.ebay.com ]
C:\Documents and Settings\MgrCA60\Cookies\MHMV1RM4.txt [ /invitemedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\35H7Y2YI.txt [ /advertising.com ]
C:\Documents and Settings\MgrCA60\Cookies\X8JJJPVD.txt [ /ads.pubmatic.com ]
C:\Documents and Settings\MgrCA60\Cookies\RAXKCW1Y.txt [ /questionmarket.com ]
C:\Documents and Settings\MgrCA60\Cookies\TS6TSD3B.txt [ /realmedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\YP7X2VDR.txt [ /intermundomedia.com ]
C:\Documents and Settings\MgrCA60\Cookies\FD57RAE2.txt [ /www.googleadservices.com ]
C:\DOCUMENTS AND SETTINGS\MGRCA60\Cookies\XZWD2AON.txt [ Cookie:[email protected]/adserving ]
C:\DOCUMENTS AND SETTINGS\MGRCA60\Cookies\I42R9WU5.txt [ Cookie:[email protected]/search/people/find-google-pre/ ]

When the computer boots I get the following error:

Infocenter.exe - .NET Framework
To run this application, you first must install one of the following versions of the .NET Framework: V2.0.50727

Contact your application publisher for instructions about obtaining the proper version.

Also, I cannot delete the folder Qoobox (specifically the folder Backenv that's located inside of it).

Thanks,
Scott
  Post #263430
 
Posted 3/2/2012 2:38 PM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 36,777, Visits: 54,734
When the computer boots I get the following error:
Infocenter.exe - .NET Framework
To run this application, you first must install one of the following versions of the .NET Framework: V2.0.50727

Contact your application publisher for instructions about obtaining the proper version.

Click on Start/Run,type msconfig into the Open: space,then press Enter.
Under the Startup tab,uncheck the box relating to Infocenter.exe - .NET Framework
Press Apply/OK

If the issue persists uninstall/remove PCPitstop,then reboot,let me know what happens.

Also, I cannot delete the folder Qoobox (specifically the folder Backenv that's located inside of it).

Delete it in Safe Mode.
How to start Windows in Safe Mode:
http://goo.gl/gPQUT


Java version out of date!
Your version of Sun Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Follow these steps to remove older version of Java components and update to the latest version:
Download the latest version of Java Runtime Environment [JRE].
Click the Download JRE button to the right.
Click to enable the box that says:
"Accept License Agreement",the page will then refresh.
Click on the link to download the Windows Offline installation and save to your desktop.
Close any programs you may have running - especially your web browser.
Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
If running Win Vista/Win 7,go to Control Panel > Programs and Features.
Check any item with Java Runtime Environment (JRE or J2SE) in the name.
Click the Remove/Uninstall or Change/Remove button.
Repeat as many times as necessary to remove all out of date versions of Java.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-7u3-windows-i586.exe to install the newest version.
If running Win Vista/Win 7,right click on jre-7u3-windows-i586.exe [jre-7u3-windows-x64.exe if running Vista/Win 7 64bit] and select Run as Administrator.

Verify your installation of Java:
[urlhttp://www.java.com/en/download/help/testvm.xml[/url


Adobe Reader out of date!
Launch Adobe Reader,click on Help->Check for Updates...,to update to the latest version.


___________________________________________________________







  Post #263432
 
Posted 3/2/2012 7:31 PM
Junior Member

Junior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior MemberJunior Member

Group: Forum Members
Last Login: 6/23/2008 4:33 PM
Posts: 164, Visits: 90
Adobe Reader said this computer has the most recent version.

I still cannot delete Qoobox.. The error message was Cannot Remove Folder: BackEnv: Access Denied. Make sure disk is not full...

I tried in Safe Mode as an Administrator.

Java updated without issue and the .NET Framework was fixed.

Thanks,
Scott
  Post #263437
 
Posted 3/3/2012 1:38 AM


Senior Forum Moderator

Senior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum ModeratorSenior Forum Moderator

Group: Moderators
Last Login: 8/9/2008 10:14 AM
Posts: 36,777, Visits: 54,734
Please download OTM by OldTimer,save it to your desktop.
* Double-click OTM.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
* Copy ALL the text in the code box below to the clipboard by highlighting ALL of it and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes

:Services

:Reg

:Files
C:\QOOBOX

:Commands
[purity]
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[EMPTYFLASH]
[Reboot]

* Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
* Click the red Moveit! button.
* Close OTM

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.
If you are asked to reboot the machine choose Yes.


___________________________________________________________







  Post #263439
 
« Prev Topic | Next Topic »


12»»

All times are GMT -6:00, Time now is 1:38am

Powered By InstantForum.NET v4.1.4 © 2014
Execution: 0.076. 9 queries. Compression Disabled.
Terms of Service - Privacy Policy - Contact    © 2014 Advanced PC Media LLC, all rights reserved.