Search:

Type: Posts; User: IndiGenus; Keyword(s):

Page 1 of 10 1 2 3 4

Search: Search took 0.01 seconds.

  1. Replies
    11
    Views
    4,615

    1. Open Notepad 2. Now copy/paste the entire...

    1. Open Notepad

    2. Now copy/paste the entire content of the codebox below into the Notepad window:



    RegLockDel::...
  2. Replies
    11
    Views
    4,615

    Okay let's try combofix again. No need to attach...

    Okay let's try combofix again. No need to attach log. Just post in your reply here.
  3. Replies
    11
    Views
    4,615

    Looks like the TDL rootkit is running. Let's do...

    Looks like the TDL rootkit is running. Let's do this...

    Please read carefully and follow these steps.

    Download TDSSKiller and save it to your Desktop.
    Extract its contents to your desktop....
  4. Replies
    11
    Views
    4,615

    AVG does not play nice with combofix. My advice...

    AVG does not play nice with combofix. My advice is to completly uninstall it then try combofix again.
  5. Replies
    11
    Views
    4,615

    Hello atapene and welcome to the forums here at...

    Hello atapene and welcome to the forums here at Safer Networking.

    :snwelcome:

    Sorry for the delay in getting to your post here. It appears the malware has done some significant damage to your...
  6. Replies
    39
    Views
    15,568

    Yes, we should be all set. I'll leave the thread...

    Yes, we should be all set. I'll leave the thread open a few days in case you have questions or issues.

    You're welcome, and good luck.
    Dave
  7. Replies
    39
    Views
    15,568

    Now that you are clean please take some time to...

    Now that you are clean please take some time to read through TonyKlein's So how did I get infected in the first place?
  8. Replies
    39
    Views
    15,568

    Have you run a full scan with AVG? If not I'd...

    Have you run a full scan with AVG? If not I'd suggest that.

    Uninstall OTL and related files/folders

    Make sure you have an Internet Connection.
    Double-click OTL.exe to run it.
    Click on the...
  9. Replies
    39
    Views
    15,568

    Okay so how's everything running now? Download...

    Okay so how's everything running now?

    Download Security Check by screen317 from here or here.
    Save it to your Desktop.
    Double click SecurityCheck.exe and follow the onscreen instructions...
  10. Replies
    39
    Views
    15,568

    They can go. Run OTL.exe Under the Custom...

    They can go.

    Run OTL.exe

    Under the Custom Scans/Fixes box at the bottom, paste in the following


    :Files
    C:\Windows\SysWow64\drivers\f
    C:\Windows\SysWow64\webe
  11. Replies
    39
    Views
    15,568

    Ya what I figured. Looks like it came in with the...

    Ya what I figured. Looks like it came in with the safesurf junk. Looks like a bunch of stuff created in folders too. Need to check.


    Please download SystemLook from one of the links below and...
  12. Replies
    39
    Views
    15,568

    That's part of the Safe Surf junk and can be...

    That's part of the Safe Surf junk and can be removed.

    Did you install something from Skybound Software called Stylelyzer? Some kind off .css editor or something?

    Let's run another scanner too....
  13. Replies
    39
    Views
    15,568

    Interesting that OTL did not find the 3 files in...

    Interesting that OTL did not find the 3 files in the SysWOW folder.

    C:\Windows\SysWOW64\drivers\up.exe
    C:\Windows\SysWOW64\Help64.exe
    C:\Windows\SysWOW64\webe\Updater3.exe

    Can you take a...
  14. Replies
    39
    Views
    15,568

    Run OTL.exe Under the Custom Scans/Fixes box...

    Run OTL.exe

    Under the Custom Scans/Fixes box at the bottom, paste in the following



    :Files
    C:\Windows\System32\drivers\up.exe
    C:\Windows\System32\Help64.exe ...
  15. Replies
    39
    Views
    15,568

    It's a time consuming/deep scan, so they can take...

    It's a time consuming/deep scan, so they can take a while.

    It is also known to produce false positives, so post the log and let us review before deleting anything.
  16. Replies
    39
    Views
    15,568

    Good point. :red: Looks like HJT took care of...

    Good point. :red: Looks like HJT took care of those startup items anyway, so I think we're good there. Just need to check on the file.
  17. Replies
    39
    Views
    15,568

    Run HijackThis.Click Do a System Scan Only. Put a...

    Run HijackThis.Click Do a System Scan Only. Put a Check in the box on the left side on these:


    O4 - HKUS\S-1-5-18\..\Run: [YXE7DXCQ37] C:\Windows\TEMP\Stm.exe (User 'SYSTEM')
    O4 -...
  18. Replies
    39
    Views
    15,568

    While we wait for the Kaspersky scanner to run...

    While we wait for the Kaspersky scanner to run can you do the following please.

    Download and install HijackThis from the following link. You can just accept and use all the default settings to...
  19. Replies
    39
    Views
    15,568

    Delete Temp files Download TFC...

    Delete Temp files

    Download TFC to your desktop

    Open the file and close any other windows.
    It will close all programs itself when run, make sure to let it run uninterrupted.
    Click the Start...
  20. Replies
    39
    Views
    15,568

    Run OTL.exe Under the Custom Scans/Fixes box...

    Run OTL.exe

    Under the Custom Scans/Fixes box at the bottom, paste in the following


    :OTL
    PRC - [2010/09/02 11:55:05 | 000,211,968 | ---- | M] (JetSwap) --...
  21. Replies
    39
    Views
    15,568

    Hi zoniq and welcome to the forums. ...

    Hi zoniq and welcome to the forums.

    :snwelcome:

    Run OTL and post the logs
    http://www.geekstogo.com/misc/guide_icons/OTLI.gif OTL - Download or alternative link here and here

    Download OTL to...
  22. Replies
    52
    Views
    16,236

    You're very welcome and glad we were able to...

    You're very welcome and glad we were able to help. :bigthumb:
  23. Replies
    52
    Views
    16,236

    If all is still running well I think we can wrap...

    If all is still running well I think we can wrap it up.

    Uninstall Combofix

    Click START then RUN
    Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and...
  24. Replies
    52
    Views
    16,236

    Just need to clean out some leftovers. The items...

    Just need to clean out some leftovers. The items ESET found are the infected backup hosts files that were created when you used OTM to solve your HOSTS issue. They will be cleaned out when we clean...
  25. Replies
    52
    Views
    16,236

    Okay I will await the results from the ESET scan...

    Okay I will await the results from the ESET scan before we proceed.
  26. Replies
    52
    Views
    16,236

    Run OTL.exe Under the Custom Scans/Fixes box...

    Run OTL.exe

    Under the Custom Scans/Fixes box at the bottom, paste in the following



    :Files
    c:\windows\system32\drivers\tsk35.tmp

    :Commands
  27. Replies
    52
    Views
    16,236

    Okay good, please run TDSSKiller one more time...

    Okay good, please run TDSSKiller one more time and post the log.

    Let me know how it's running at this point too please.
  28. Replies
    52
    Views
    16,236

    Backup Your Registry with ERUNT * Please...

    Backup Your Registry with ERUNT

    * Please use the following link and scroll down to ERUNT and download it.
    http://aumha.org/freeware/freeware.php
    * For version with the Installer:
    ...
  29. Replies
    52
    Views
    16,236

    Okay while I'm looking into this and trying to...

    Okay while I'm looking into this and trying to get my head wrapped around it can you run TDSSKiller like you did earlier back here and post the log.
  30. Replies
    52
    Views
    16,236

    Some more investigating to do before we make any...

    Some more investigating to do before we make any changes. This could be tricky to remove if we need to.

    Please download SystemLook from one of the links below and save it to your Desktop....
  31. Replies
    52
    Views
    16,236

    Before moving on with the fix I would like you to...

    Before moving on with the fix I would like you to check something.

    Start Notepad and copy/paste in the following code:


    @echo off
    If exist SELECT.txt del /s/q SELECT.txt
    If exist peek*.txt...
  32. Replies
    52
    Views
    16,236

    1. Open Notepad 2. Now copy/paste the entire...

    1. Open Notepad

    2. Now copy/paste the entire content of the codebox below into the Notepad window:



    Folder::
    c:\documents and settings\Jonathan\Local Settings\Application Data\hrjamelec
    ...
  33. Replies
    52
    Views
    16,236

    Time for combofix: Please visit this webpage...

    Time for combofix:

    Please visit this webpage for download links, and instructions for running the tool:

    http://www.bleepingcomputer.com/combofix/how-to-use-combofix

    * Ensure you have...
  34. Replies
    52
    Views
    16,236

    Looks like the log is getting cut off for some...

    Looks like the log is getting cut off for some reason. But I can see that it did find the rootkit.

    How is it running now? Can you get to those sites now?
  35. Replies
    52
    Views
    16,236

    Okay that is clean. Download TDSSKiller...

    Okay that is clean.

    Download TDSSKiller and save it to your Desktop.
    Extract its contents to your desktop and make sure TDSSKiller.exe (the contents of the zipped file) is on the Desktop...
  36. :bigthumb::bigthumb:

    :bigthumb::bigthumb:
  37. Good enough. Just some final words of "wisdom"...

    Good enough. Just some final words of "wisdom" then.

    Now that you are clean please take some time to read through TonyKlein's So how did I get infected in the first place?
  38. Yes, you can remove 9. Probably you would...

    Yes, you can remove 9.


    Probably you would use this one:

    http://www.symantec.com/norton/support/kb/web_view.jsp?wv_type=public_web&docurl=20080828154508EN
  39. Yes, Java is up to date, must be a bug. The...

    Yes, Java is up to date, must be a bug.

    The rest do need updating. Let me know if you need help with that.

    So you do not have any Norton products on here any more? If so you should probably run...
  40. Uninstall Combofix Click START then RUN ...

    Uninstall Combofix

    Click START then RUN
    Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the /U, it needs to be there.

    The above procedure will:...
  41. Yes, that's a false positive. You shouldn't need...

    Yes, that's a false positive. You shouldn't need to disable anything else. Just Adwatch. I'll get back to you on the items Kaspersky found.
  42. Replies
    52
    Views
    16,236

    Sorry that is my fault. No need to run as Admin...

    Sorry that is my fault. No need to run as Admin as you're running XP. Thought it was Vista.

    Either way now that you've posted I would prefer you run this tool.

    Download MBRCheck.exe to your...
  43. Great, and I bet a simple re-install or repair...

    Great, and I bet a simple re-install or repair install if available will fix the problem.

    Now that you are clean please take some time to read through TonyKlein's So how did I get infected in the...
  44. Looks clean to me and right size now too. So no...

    Looks clean to me and right size now too. So no need to worry there. Sometimes just going through the process of looking for a file like that will trigger the AV that something is wrong. Which looks...
  45. Sorry need to make sure hidden files are showing,...

    Sorry need to make sure hidden files are showing, my bad.

    http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/hiddenfiles.mspx
  46. Let's make sure it was cleaned. The dllcache...

    Let's make sure it was cleaned. The dllcache folder essentially contains backups of system files, in case something happens to a system file it automatically gets replaced. Hate to have that happen...
  47. Okay no problem. We'll keep the thread open for...

    Okay no problem. We'll keep the thread open for you.
  48. Please download SystemLook from one of the links...

    Please download SystemLook from one of the links below and save it to your Desktop.
    Download Mirror #1
    Download Mirror #2

    Double-click SystemLook.exe to run it.
    Copy the content of the...
  49. One more virus scan in order I think. And a...

    One more virus scan in order I think. And a security update check.

    Go to Kaspersky website and perform an online antivirus scan.


    Read through the requirements and privacy statement and click...
  50. Looks like it did what we needed it to. One...

    Looks like it did what we needed it to.

    One more scan in order I think, unless there are any problems.

    Go to Kaspersky website and perform an online antivirus scan.


    Read through the...
Results 1 to 50 of 500
Page 1 of 10 1 2 3 4