Thanks so much for all your help, really appreciate it!
Type: Posts; User: mattc; Keyword(s):
Thanks so much for all your help, really appreciate it!
OTMoveIt Log
========== FILES ==========
C:\autorun.inf moved successfully.
OTMoveIt3 by OldTimer - Version 1.0.2.2 log created on 10202008_224529
HiJackThis Log
Logfile of Trend Micro...
sorry abotu the delay, was away from my computer for the past couple of days.
I installed the first Antivirus you listed and here is the Kaspersky log
...
There was no Limewire folder to remove. Here are the logs.
Malwarebytes'
Malwarebytes' Anti-Malware 1.28
Database version: 1240
Windows 5.1.2600 Service Pack 3
10/7/2008 4:49:25 PM...
(continued Look32)
04/14/2008 06:39 AM 6,656 kbdinmal.dll
04/14/2008 06:39 AM 7,168 kbdno1.dll
04/14/2008 06:39 AM 7,168 kbdukx.dll
04/14/2008 06:39 AM ...
Look32
Volume in drive C has no label.
Volume Serial Number is 70D4-A8BA
Directory of C:\WINDOWS\system32
10/06/2008 04:45 PM 182,441 nvapps.xml
10/06/2008 04:44 PM ...
Extras
OTViewIt Extras logfile created on: 10/6/2008 4:49:29 PM - Run 4
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\Matthew\Desktop
Windows XP Professional...
OTViewIt logfile
OTViewIt logfile created on: 10/6/2008 4:49:29 PM - Run 4
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\Matthew\Desktop
Windows XP Professional...
HiJackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:56:21 PM, on 10/6/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot...
HiJackThis Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:56:21 PM, on 10/6/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20861)
Boot...
Ok, so I was able to reset the modem and put a password. And I was able to change the DNS setting to automatic. So far, everything seems back to normal. Here are the logs.
Username "Matthew" -...
I have a D-Link DIR-615 N-Router
Acrobat.com
Acrobat.com
Add or Remove Adobe Creative Suite 3 Master Collection
Add or Remove Adobe Creative Suite 3 Master Collection
Adobe After Effects CS3...
OTMoveit3
========== FILES ==========
File/Folder C:\WINDOWS\system32\kdkfs.exe not found.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows...
EXTRAS
OTViewIt Extras logfile created on: 10/2/2008 9:33:33 PM - Run 2
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\Matthew\Desktop
Windows XP Professional...
I couldn't find the dll.dll file within the system32 folder. I also did a search on my entire system and couldnt find that file. All files and folders including protected operating files are being...
Removed Limewire and here is the uninstall list:
Acrobat.com
Acrobat.com
Add or Remove Adobe Creative Suite 3 Master Collection
Add or Remove Adobe Creative Suite 3 Master Collection
Adobe...
EXTRAS
OTViewIt Extras logfile created on: 10/30/2008 5:33:43 PM - Run
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\Matthew\Desktop
Windows XP Professional...
OTViewIt logfile
OTViewIt logfile created on: 10/30/2008 5:33:43 PM - Run
OTViewIt by OldTimer - Version 1.0.9.2 Folder = C:\Documents and Settings\Matthew\Desktop
Windows XP Professional...
OK so here are the log files you asked for:
GMER log:
GMER 1.0.14.14536 - http://www.gmer.net
Rootkit scan 2008-10-30 17:25:58
Windows 5.1.2600 Service Pack 3
---- User code sections -...
OK, so here is the fixwareout.exe log below.
However when I ran RSIT.exe I got an error saying : Error parsing function call, and then the program just quit. Also when I go to change the Internet...
Thanks so much. If it helps spybot points to this file as one of the problems. But I can't find it in this location even by unhiding protected operating system files, and it just reappears if I have...
I've looked at a ton of forums and tried solving the problem myself following instructions, but SpyBot is still finding the Zlob.dnschanger and Zlob.dnschanger.rtk
Here is the HijackThis log
...