Spybot Logo
Go Back   Safer-Networking Forums > General Malware > Archives
Register ProjectsBlogs FAQ Search Today's Posts Mark Forums Read Home Support Download Donate

 
 
Thread Tools Display Modes
Old 2008-12-08, 00:13   #11
Gntea
Junior Member
 
Join Date: Nov 2008
Posts: 11
Default

Combofix is in that folder.

I'm now currently running a virus scan and I will post the results later.
Gntea is offline  
Old 2008-12-08, 17:11   #12
Blade81
Security Expert
 
Blade81's Avatar
 
Join Date: Oct 2006
Location: Finland
Posts: 20,805
Default

Hi

Let's try removing with a batch file.

Open notepad and then copy and paste the bolded lines below into it. Go to File > save as and name the file fixes.bat, change the Save as type to all files and save it to your desktop. (If you are still unsure on how to do this there is a little tutorial with pictures here)
@echo off
c:
cd\documents and settings\Emily\Desktop
ComboFix /u

Double-click on fixes.bat file to execute it.
__________________
Microsoft MVP Consumer Security 2008 2009 2010
ASAP & UNITE member since 2006

I don't help with logs thru PM. If you have problems create a thread in the forum, please.

Malware removal instructions are for the correspondent user's case only.
Blade81 is online now  
Old 2008-12-10, 10:14   #13
Gntea
Junior Member
 
Join Date: Nov 2008
Posts: 11
Default

My virus scan did not find any more viruses in my computer. My spyware scan did find some spyware it could not automatically delete:
KaZaA
Bifrost
Loadtrex A
Vundo BHW

I did delete them with my anti-spyware program. Although they aren't doing anything to harm my computer to my knowledge, I am wondering if I should worry about them if they keep popping up on my spyware scans but do not seem to harm my computer.

For the ComboFix, I did the batch file but it seems to be taking a long time to uninstall so I'm going to leave my computer on and go off to bed. I will check in the morning if it is still trying to uninstall.
Gntea is offline  
Old 2008-12-10, 17:01   #14
Blade81
Security Expert
 
Blade81's Avatar
 
Join Date: Oct 2006
Location: Finland
Posts: 20,805
Default

Quote:
My spyware scan did find some spyware it could not automatically delete:
KaZaA
Bifrost
Loadtrex A
Vundo BHW
Hi

Could you post results of your antispyware scan? I need to know what objects exactly it flagged with those detections.
__________________
Microsoft MVP Consumer Security 2008 2009 2010
ASAP & UNITE member since 2006

I don't help with logs thru PM. If you have problems create a thread in the forum, please.

Malware removal instructions are for the correspondent user's case only.
Blade81 is online now  
Old 2008-12-11, 03:22   #15
Gntea
Junior Member
 
Join Date: Nov 2008
Posts: 11
Default

ComboFix did not uninstall even after I left it for 14 hours.

Okay here is my spyware scan report:

Spyware Report (12/8/2008 12:11:03 PM)
Scan Target Scanned Items Detected Spyware Items
Local Disk (C 181920 1
RESTORE (D 10 0
Local Disk (G 4659 0
Local Disk (K 23304 0
Cookies 148 48
Registry 32404 3
Memory 17 0
Total 242462 52



Spyware Type Item Action
WebTrends Spyware cookie C:\Documents and Settings\Emily\cookies\emily@statse.webtrendslive[1].txt Delete
KaZaA Registry hkey_users \S-1-5-21-3646181656-1281075794-927890586-1009\software\kazaa Quarantine
DoubleClick Spyware cookie C:\Documents and Settings\Emily\cookies\emily@doubleclick[1].txt Delete
DoubleClick Spyware cookie C:\Documents and Settings\Emily\cookies\emily@doubleclick[2].txt Delete
DoubleClick Spyware cookie C:\Documents and Settings\Emily\cookies\emily@doubleclick[3].txt Delete
DoubleClick Spyware cookie C:\Documents and Settings\Emily\cookies\emily@doubleclick[4].txt Delete
DoubleClick Spyware cookie C:\Documents and Settings\Emily\cookies\emily@doubleclick[5].txt Delete
DoubleClick Spyware cookie C:\Documents and Settings\Emily\cookies\emily@doubleclick[6].txt Delete
Mediaplex.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@mediaplex[2].txt Delete
QuestionMarket.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@questionmarket[2].txt Delete
QuestionMarket.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@questionmarket[3].txt Delete
AtlasDMT.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@atdmt[1].txt Delete
AtlasDMT.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@atdmt[3].txt Delete
Zedo Spyware cookie C:\Documents and Settings\Emily\cookies\emily@zedo[2].txt Delete
Ads.SpecificClick.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@specificclick[2].txt Delete
PointRoll.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@ads.pointroll[1].txt Delete
PointRoll.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@ads.pointroll[2].txt Delete
TribalFusion.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@tribalfusion[1].txt Delete
TribalFusion.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@tribalfusion[2].txt Delete
TribalFusion.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@tribalfusion[4].txt Delete
2o7.net Spyware cookie C:\Documents and Settings\Emily\cookies\emily@msnportal.112.2o7[1].txt Delete
2o7.net Spyware cookie C:\Documents and Settings\Emily\cookies\emily@msnportal.112.2o7[2].txt Delete
2o7.net Spyware cookie C:\Documents and Settings\Emily\cookies\emily@msnportal.112.2o7[3].txt Delete
Com.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@com[1].txt Delete
BS.Serving-Sys Spyware cookie C:\Documents and Settings\Emily\cookies\emily@bs.serving-sys[1].txt Delete
Casalemedia Spyware cookie C:\Documents and Settings\Emily\cookies\emily@casalemedia[2].txt Delete
Serving-Sys Spyware cookie C:\Documents and Settings\Emily\cookies\emily@serving-sys[2].txt Delete
Ad.YieldManager.com Cookie Spyware cookie C:\Documents and Settings\Emily\cookies\emily@ad.yieldmanager[1].txt Delete
Ad.YieldManager.com Cookie Spyware cookie C:\Documents and Settings\Emily\cookies\emily@ad.yieldmanager[2].txt Delete
Ad.YieldManager.com Cookie Spyware cookie C:\Documents and Settings\Emily\cookies\emily@ad.yieldmanager[3].txt Delete
Tacoda cookie Spyware cookie C:\Documents and Settings\Emily\cookies\emily@tacoda[1].txt Delete
Tacoda cookie Spyware cookie C:\Documents and Settings\Emily\cookies\emily@tacoda[3].txt Delete
Bifrost Registry hkey_users \S-1-5-21-3646181656-1281075794-927890586-1009\software\wget Quarantine
rambler.ru Spyware cookie C:\Documents and Settings\Emily\cookies\emily@rambler[2].txt Delete
revsci.net Spyware cookie C:\Documents and Settings\Emily\cookies\emily@revsci[2].txt Delete
adlegend.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@adlegend[2].txt Delete
adrevolver.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@adrevolver[2].txt Delete
adrevolver.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@media.adrevolver[2].txt Delete
easyad.info Spyware cookie C:\Documents and Settings\Emily\cookies\emily@adserver.easyad[1].txt Delete
euroclick.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@adopt.euroclick[1].txt Delete
interclick.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@interclick[1].txt Delete
quantserve.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@quantserve[2].txt Delete
quantserve.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@quantserve[3].txt Delete
quantserve.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@quantserve[4].txt Delete
adecn.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@adecn[1].txt Delete
cpmstar.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@server.cpmstar[2].txt Delete
turn.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@turn[2].txt Delete
adriver.ru Spyware cookie C:\Documents and Settings\Emily\cookies\emily@adriver[1].txt Delete
eyereturn.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@eyereturn[1].txt Delete
eyereturn.com Spyware cookie C:\Documents and Settings\Emily\cookies\emily@eyereturn[3].txt Delete
Loadtrex A Registry hkey_local_machine \software\xpre Quarantine
Vundo BHW Application C:\Qoobox\Quarantine\C\WINDOWS\system32\urqNEXOh.dll.vir Quarantine
Gntea is offline  
Old 2008-12-11, 16:12   #16
Blade81
Security Expert
 
Blade81's Avatar
 
Join Date: Oct 2006
Location: Finland
Posts: 20,805
Default

Hi

Report looks ok Could you download ComboFix.exe again and then try uninstalling it with the batch file making sure that the file is saved on desktop?
__________________
Microsoft MVP Consumer Security 2008 2009 2010
ASAP & UNITE member since 2006

I don't help with logs thru PM. If you have problems create a thread in the forum, please.

Malware removal instructions are for the correspondent user's case only.
Blade81 is online now  
Old 2008-12-15, 05:51   #17
Gntea
Junior Member
 
Join Date: Nov 2008
Posts: 11
Default

I tried to download it again but it was trying to remove the other one that is saved on my desktop. It tried to remove it but the progress bar stopped at 10/13. This is what always happens when I try to remove ComboFix.
Gntea is offline  
Old 2008-12-15, 16:17   #18
Blade81
Security Expert
 
Blade81's Avatar
 
Join Date: Oct 2006
Location: Finland
Posts: 20,805
Default

Hi

In that case delete following ComboFix related items manually

1) files:
ComboFix.exe on your desktop

2) folders (if found):
c:\ComboFix
c:\QooBox
__________________
Microsoft MVP Consumer Security 2008 2009 2010
ASAP & UNITE member since 2006

I don't help with logs thru PM. If you have problems create a thread in the forum, please.

Malware removal instructions are for the correspondent user's case only.
Blade81 is online now  
Old 2008-12-17, 09:15   #19
Gntea
Junior Member
 
Join Date: Nov 2008
Posts: 11
Default

I have successfully deleted ComboFix as well as the files.
Gntea is offline  
Old 2008-12-17, 16:55   #20
Blade81
Security Expert
 
Blade81's Avatar
 
Join Date: Oct 2006
Location: Finland
Posts: 20,805
Default

Good

In that case I believe your case is ready. Unless there's something else please follow the final instructions in post #8 of this thread.
__________________
Microsoft MVP Consumer Security 2008 2009 2010
ASAP & UNITE member since 2006

I don't help with logs thru PM. If you have problems create a thread in the forum, please.

Malware removal instructions are for the correspondent user's case only.
Blade81 is online now  
 

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +2. The time now is 16:38.


Copyright © 2000-2010 Safer-Networking Limited. All rights reserved.