|
|
|||||||
| Register | Projects | Blogs | FAQ | Search | Today's Posts | Mark Forums Read |
|
|
#11 |
|
Junior Member
Join Date: Jan 2008
Posts: 14
|
Oh my bad. I did not post the complete uninstall list. Here is the complete list.
5 Card Slingo from Compaq (remove only) Adobe Reader 7.0 Agere Systems PCI-SV92PP Soft Modem Apple Mobile Device Support Apple Software Update AstroPop Deluxe from Compaq (remove only) Barnyard Invasion from Compaq (remove only) Bejeweled 2 Deluxe from Compaq (remove only) Blackhawk Striker 2 from Compaq (remove only) Blasterball 2 from Compaq (remove only) Blasterball 2 Remix from Compaq (remove only) Boggle Supreme from Compaq (remove only) Bookworm Deluxe from Compaq (remove only) Bounce Symphony from Compaq (remove only) CC_ccProxyExt ccCommon ccPxyCore Chuzzle Deluxe from Compaq (remove only) Compaq Connections (remove only) Compaq Organize Creative Software AutoUpdate Creative System Information Crystal Maze from Compaq (remove only) Customer Experience Enhancement Easy Internet Sign-up Family Feud FATE from Compaq (remove only) Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Windows XP (KB893357) Hotfix for Windows XP (KB906569) HP Boot Optimizer HP DVD Play 1.0 HP Game Console and games HP Imaging Device Functions 6.0 HP Photosmart Premier Software 6.0 HP Rhapsody HP Software Update HP Support Overview HP Web Helper Insaniquarium Deluxe from Compaq (remove only) iTunes J2SE Runtime Environment 5.0 Update 5 Lemonade Tycoon 2 from Compaq (remove only) Lexibox Deluxe from Compaq (remove only) LimeWire 4.14.12 LiveUpdate 2.7 (Symantec Corporation) Mah Jong Quest from Compaq (remove only) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft Money 2006 Microsoft Office 2003 Edition 60 Days Trial Welcome Tour Microsoft Office Standard Edition 2003 Microsoft Works Mozilla Firefox (2.0.0.11) MSRedist Netscape Browser (remove only) Norton AntiSpam Norton AntiVirus 2006 Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security 2006 (Symantec Corporation) Norton Protection Center Norton WMI Update Norton WMI Update NVIDIA Drivers PC-Doctor 5 for Windows Polar Bowler from Compaq (remove only) Polar Golfer from Compaq (remove only) Puzzle Express from Compaq (remove only) Python 2.2 pywin32 extensions (build 203) Python 2.2.3 RealPlayer Realtek High Definition Audio Driver Remove WeatherBug Installer Ricochet Lost Worlds from Compaq (remove only) SCRABBLE from Compaq (remove only) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB912919) Shooting Stars Pool from Compaq (remove only) Shrek 2 Ogre Bowler from Compaq (remove only) Slingo Deluxe from Compaq (remove only) Snowboard SuperJam from Compaq (remove only) Sonic Express Labeler Sonic MyDVD Plus Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Sound Blaster Audigy SPBBC Super Granny from Compaq (remove only) SymNet Tradewinds from Compaq (remove only) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB883667 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888239 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB892050 Windows XP Hotfix - KB893066 Zuma Deluxe from Compaq (remove only) |
|
|
|
|
#12 |
|
Junior Member
Join Date: Jan 2008
Posts: 14
|
This may have altered your instructions. I await what to do next after you have seen the complete uninstall list.
|
|
|
|
|
#13 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Hi
Uninstall also these: Norton entries PC-Doctor 5 for Windows Sound Blaster Audigy Norton reinstallation is highly recommended of those (and the ones listed in my previous post). Other programs can be reinstalled after fixing process is finished.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
#14 |
|
Junior Member
Join Date: Jan 2008
Posts: 14
|
ComboFix log as follows:
ComboFix 08-01-18.5 - Compaq_Owner 2008-01-19 19:10:32.2 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.733 [GMT -5:00] Running from: C:\Documents and Settings\Compaq_Owner\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Compaq_Owner\Desktop\CFScript.txt * Created a new restore point FILE C:\WINDOWS\mrofinu11.exe.tmp C:\WINDOWS\system32\cfkdhaak.ini C:\WINDOWS\system32\jqkuyvds.ini . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\mrofinu11.exe.tmp C:\WINDOWS\system32\cfkdhaak.ini C:\WINDOWS\system32\jqkuyvds.ini . ((((((((((((((((((((((((( Files Created from 2007-12-20 to 2008-01-20 ))))))))))))))))))))))))))))))) . 2008-01-19 13:32 . 2000-08-31 08:00 51,200 --a------ C:\WINDOWS\NirCmd.exe 2008-01-06 07:40 . 2008-01-19 19:10 <DIR> d-------- C:\Program Files\QuickTime 2008-01-06 07:31 . 2008-01-06 07:37 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Shared 2008-01-06 07:31 . 2008-01-06 07:44 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Incomplete 2008-01-06 07:29 . 2008-01-06 07:44 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\LimeWire 2008-01-06 02:03 . 2008-01-19 11:36 <DIR> d-------- C:\Program Files\Trend Micro 2008-01-06 00:54 . 2006-02-22 06:04 <DIR> d-------- C:\Documents and Settings\Administrator\WINDOWS 2008-01-06 00:54 . 2006-02-22 06:29 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Symantec 2008-01-06 00:54 . 2006-02-22 06:05 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Intuit 2008-01-03 05:04 . 2004-08-04 03:56 21,504 --a------ C:\WINDOWS\system32\hidserv.dll 2008-01-03 05:04 . 2001-08-17 16:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys 2008-01-03 05:04 . 2001-08-17 17:02 9,600 --a------ C:\WINDOWS\system32\drivers\hidusb.sys 2008-01-03 03:15 . 2008-01-19 13:34 <DIR> dr-hs---- C:\WINDOWS\system32\dllcache 2008-01-03 02:43 . 2008-01-03 02:43 584 --a------ C:\WINDOWS\system32\settingsbkup.sfm 2008-01-03 02:43 . 2008-01-03 02:43 584 --a------ C:\WINDOWS\system32\settings.sfm 2008-01-03 02:36 . 2000-05-21 19:58 647,872 --a------ C:\WINDOWS\system32\Mscomct2.ocx 2008-01-03 02:36 . 2003-06-12 23:25 7,062 --a------ C:\WINDOWS\system32\audiopid.vxd 2008-01-03 02:32 . 2008-01-03 02:32 <DIR> d-------- C:\WINDOWS\system32\Data 2008-01-03 02:32 . 2000-12-12 21:21 7,572,224 --a------ C:\WINDOWS\system32\CT8MGM.SF2 2008-01-03 02:32 . 2000-12-04 20:11 4,174,814 --a------ C:\WINDOWS\system32\CT4MGM.SF2 2008-01-03 02:32 . 1999-09-22 02:18 2,167,684 -ra------ C:\WINDOWS\system32\ct2mgm.sf2 2008-01-03 02:32 . 2005-06-27 05:37 133,632 -ra------ C:\WINDOWS\system32\CtDvInst.dll 2008-01-03 02:32 . 2005-07-07 04:26 5,627 -ra------ C:\WINDOWS\system32\Ludap17.ini 2008-01-03 02:32 . 2005-03-08 01:14 39 -ra------ C:\WINDOWS\system32\ctzapxx.ini 2008-01-03 02:24 . 2008-01-03 02:24 <DIR> d-------- C:\Program Files\iPod 2008-01-03 02:24 . 2008-01-03 02:24 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Apple Computer 2008-01-03 02:22 . 2008-01-03 02:22 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE 2008-01-03 02:16 . 2008-01-03 02:16 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Talkback 2008-01-03 02:13 . 2004-08-04 06:00 221,184 --a------ C:\WINDOWS\system32\wmpns.dll 2008-01-03 02:13 . 2008-01-03 02:13 1,842 -rahs---- C:\WINDOWS\system32\drivers\103C_HP_CPC_ER919AA-ABA SR1820NX NA620_YC_0Pres_QCNH615_E62NAheREA2_48_INAGAMI_SASUSTek Computer INC._V1.01_B3.01_T060209_WXH2_L409_M1023_J160_7AMD_8Athlon 64_92.2_#060529_N_Z11C10620_G10DE0322.MRK 2008-01-03 02:10 . 2006-02-22 06:04 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\WINDOWS 2008-01-03 02:10 . 2006-02-22 06:29 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Symantec 2008-01-03 02:10 . 2006-02-22 06:05 <DIR> d-------- C:\Documents and Settings\Compaq_Owner\Application Data\Intuit 2008-01-03 02:09 . 2006-02-22 06:04 <DIR> d-------- C:\WINDOWS\system32\config\systemprofile\WINDOWS 2007-12-28 11:45 . 2007-12-29 22:42 <DIR> d-------- C:\Program Files\Elf Online 2007-12-26 19:19 . 2007-12-29 18:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! 2007-12-25 05:27 . 2007-12-26 19:14 <DIR> d-------- C:\USERDATA . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 06:00 15360] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [2006-01-11 19:23 15961088 C:\WINDOWS\RTHDCPL.EXE] "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [ ] "PCDrProfiler"="" [] "ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [ ] "IS CfgWiz"="c:\Program Files\Norton Internet Security\cfgwiz.exe" [ ] "SSC_UserPrompt"="c:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe" [ ] "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp .exe" [ ] "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [ ] "CTSysVol"="C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [ ] "P17Helper"="P17.dll" [2005-05-03 06:38 64512 C:\WINDOWS\system32\P17.dll] "UpdReg"="C:\WINDOWS\UpdReg.EXE" [ ] *Newly Created Service* - COMHOST . Contents of the 'Scheduled Tasks' folder "2008-01-19 21:53:05 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" - C:\Program Files\Apple Software Update\SoftwareUpdate.exe "2008-01-03 07:11:30 C:\WINDOWS\Tasks\Easy Internet Sign-up.job" - C:\Program Files\Hewlett-Packard\SDP\HPSdpApp.exef/remind /LaunchPoint reminder /App C:\Program Files\Hewlett-Packard\Easy Internet signup\StartEIS.aml "2006-02-22 11:25:05 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . ************************************************************************** catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-01-19 19:14:47 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2008-01-19 19:15:14 ComboFix-quarantined-files.txt 2008-01-20 00:15:06 ComboFix2.txt 2008-01-19 18:46:53 |
|
|
|
|
#15 |
|
Junior Member
Join Date: Jan 2008
Posts: 14
|
I think I got the kaspersky log right.
It was too large to post here, so heres a link to Rapidshare! http://rs6.rapidshare.com/files/8507...ersky_log.html Norton cannot be uninstalled. It gives me a message: A norton Security account with supervisor must be logged in to uninstall this product. If norton internet security is not running, click the start menu, select norton internet security and log in. To be honest, I have never trusted this program. I won't be using this computer for surfing the web, but I do want to keep my passwords theft free and my Internet Games popup free... as a popup can kill my party of 39 other players if it happens to myself in a critical moment. In short: Once my computer goes back to normal I will not need virus protection on this computer. Thank you! I will co-op with you however, even if that means reinstalling it or something. I want this problem to be healed so I wont have to worry anymore. |
|
|
|
|
#16 |
|
Junior Member
Join Date: Jan 2008
Posts: 14
|
I went to the website and had to download an uninstaller to uninstall Norton.
Uninstall Complete. |
|
|
|
|
#17 | |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Quote:
Clear Spybot recovery (first aid kit icon in Spybot program). Well congrats, it appears your system is all clean Are you still noticing any problems? If not, it's time to secure your system to prevent against further intrusions. THESE STEPS ARE VERY IMPORTANT Let's reset system restore Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: You will lose all previous restore points which are likely to be infected. Please note you need Administrator Access to do clean the restore points. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Reboot. 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK. NOTE: only do this ONCE,NOT on a regular basis Next we remove all used tools. Please download OTMoveIt and save it to desktop.
Note: If you receive a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet, please allow it to do so. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update to the latest version... Updating Java:
UPDATING WINDOWS AND INTERNET EXPLORER IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site to get the critical updates. If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the critical updates installed (Free) Microsoft Office Update. Make your Internet Explorer more secure This can be done by following these simple instructions: From within Internet Explorer click on the Tools menu and then click on Options. Click once on the Security tab Click once on the Internet icon so it becomes highlighted. Click once on the Custom Level button. Change the Download signed ActiveX controls to Prompt Change the Download unsigned ActiveX controls to Disable Change the Initialize and script ActiveX controls not marked as safe to Disable Change the Installation of desktop items to Prompt Change the Launching programs and files in an IFRAME to Prompt Change the Navigate sub-frames across different domains to Prompt When all these settings have been made, click on the OK button. If it prompts you as to whether or not you want to save the settings, press the Yes button. Next press the Apply button and then the OK to exit the Internet Properties page. The following are recommended third party programs that are designed to keep your computer clean. A link as well as a brief description is included with each item.
Just a final reminder for you. I am trying to stress these two points. UPDATE UPDATE UPDATE!!! Make sure you do this about every 1-2 weeks. Make sure all of your security programs are up to date. Run the spybot and adaware regularly. (Once or twice a week minimum.) Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates. Once again, please post and tell me how things are going with your system... problems etc. Have a great day, Blade
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
|
#18 |
|
Junior Member
Join Date: Jan 2008
Posts: 14
|
Things seem to be in tip top shape. I have decided to download AVG free Edition for my Anti-Virus program.
I didn't even know what Java was, so I will be sure to update that today as well. If anything seems weird or strange, do I PM you or make a new post? You have my thanks, Thanes Anderson |
|
|
|
|
#19 | |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
You're welcome
![]() Quote:
If nothing comes up I'll close the topic. When closed you can ask topic opened when you do it within 5 days of closing time. If it's longer than that topic won't be reopened and you have to create a new one.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
|
|
|
#20 |
|
Security Expert
Join Date: Oct 2006
Location: Finland
Posts: 20,805
|
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help.
![]() Note:If it has been five days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread. If it has been less than five days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
__________________
Microsoft MVP Consumer Security 2008 2009 2010 ASAP & UNITE member since 2006 I don't help with logs thru PM. If you have problems create a thread in the forum, please. Malware removal instructions are for the correspondent user's case only. |
|
|
| Thread Tools | |
| Display Modes | |
|
|