Page 1 of 6 12345 ... LastLast
Results 1 to 10 of 56

Thread: This System is Possessed

  1. #1
    Member
    Join Date
    Dec 2007
    Posts
    37

    Default This System is Possessed

    I purchased this computer from someone I know on the cheap, because he said it has a virus.
    THIS SYSTEM IS POSSESSED!
    1.About every 5 minutes this message pops up,
    Windows Security Alert!
    Warning! Potential Spyware Operation!
    You computer is making unauthorised copies of your System and
    Internet files. Run full scan now to prevent any unauthorised access
    to your files! Click YES to download Spyware Remover...
    Misspelling included.
    I've been clicking NO.
    2.I cannot Access the Control Panel. If you click on Start the Control Panel is not listed.
    If I Click Start>Run>Control.exe I get the message
    Restrictions
    The operation has been cancelled due to restrictions in effect on this computer. Please
    contact your system administrator.
    3.Cannot access properties from My Computer. Click Start>My Computer, right mouse click>
    Properties. Same message as item 2.
    4.My Home Page keeps getting changed to Google.
    5. I have to run Spybot, no luck. I can download it and start the installation. The
    installation runs to the point where the check boxes Run S&D, Run Teatimer are displayed.
    Click on OK and nothing happens
    6.Kaspersky Online Scanner,when I click on the link in "Before You Post" using the infected system
    it goes no where. No Error, It just stays on the "Before You Post, post. It works fine on
    my good system. I tried googling "Kaspersky Online Scanner" Following the Link, but after
    repeated tries all I get is "The page cannot be displayed. Works fine on my good sytem.
    7. HiJack This, I get the same result from the HiJack this Link. I went to a site and
    downloaded HiJack This 2.02 to the desktop. when I double-click on the desktop icon the
    System asks if I want to run it. When I click RUN nothing happens. No error, the
    program does not execute.
    8. The system has an outdated version of PC-cillin (Last update 6/4/2006). It won't update.
    The former owner says he ran SmitFruadFix in Safe Mode. It produced a report. I will post
    it, might help, it's about all I have.
    9. The system says it is booting Windows XP Media Edition. The Dell Support Center says it
    is running Windows XP Professional Service Pack 2.
    I will Be grateful for any help.
    SmitFraudFix Rapport:
    SmitFraudFix v2.296
    Scan done at 12:33:43.67, Mon 02/25/2008
    Run from C:\Documents and Settings\Henry Latour\Desktop\SmitFraudFix\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    10.18.250.4 ad.doubleclick.net
    10.18.250.4 ad.fastclick.net
    10.18.250.4 ads.fastclick.net
    10.18.250.4 ar.atwola.com
    10.18.250.4 atdmt.com
    10.18.250.4 avp.ch
    10.18.250.4 avp.com
    10.18.250.4 avp.ru
    10.18.250.4 awaps.net
    10.18.250.4 banner.fastclick.net
    10.18.250.4 banners.fastclick.net
    10.18.250.4 ca.com
    10.18.250.4 click.atdmt.com
    10.18.250.4 clicks.atdmt.com
    10.18.250.4 customer.symantec.com
    10.18.250.4 dispatch.mcafee.com
    10.18.250.4 download.mcafee.com
    10.18.250.4 downloads-us1.kaspersky-labs.com
    10.18.250.4 downloads-us2.kaspersky-labs.com
    10.18.250.4 downloads-us3.kaspersky-labs.com
    10.18.250.4 downloads1.kaspersky-labs.com
    10.18.250.4 downloads2.kaspersky-labs.com
    10.18.250.4 downloads3.kaspersky-labs.com
    10.18.250.4 downloads4.kaspersky-labs.com
    10.18.250.4 engine.awaps.net
    10.18.250.4 f-secure.com
    10.18.250.4 fastclick.net
    10.18.250.4 ftp.avp.ch
    10.18.250.4 ftp.downloads1.kaspersky-labs.com
    10.18.250.4 ftp.downloads2.kaspersky-labs.com
    10.18.250.4 ftp.downloads3.kaspersky-labs.com
    10.18.250.4 ftp.f-secure.com
    10.18.250.4 ftp.kasperskylab.ru
    10.18.250.4 ftp.sophos.com
    10.18.250.4 ids.kaspersky-labs.com
    10.18.250.4 kaspersky-labs.com
    10.18.250.4 kaspersky.com
    10.18.250.4 liveupdate.symantec.com
    10.18.250.4 liveupdate.symantecliveupdate.com
    10.18.250.4 mast.mcafee.com
    10.18.250.4 mcafee.com
    10.18.250.4 media.fastclick.net
    10.18.250.4 my-etrust.com
    10.18.250.4 nai.com
    10.18.250.4 networkassociates.com
    10.18.250.4 norton.com
    10.18.250.4 phx.corporate-ir.net
    10.18.250.4 rads.mcafee.com
    10.18.250.4 secure.nai.com
    10.18.250.4 securityresponse.symantec.com
    10.18.250.4 service1.symantec.com
    10.18.250.4 sophos.com
    10.18.250.4 spd.atdmt.com
    10.18.250.4 symantec.com
    10.18.250.4 trendmicro.com
    10.18.250.4 update.symantec.com
    10.18.250.4 updates.symantec.com
    10.18.250.4 updates1.kaspersky-labs.com
    10.18.250.4 updates2.kaspersky-labs.com
    10.18.250.4 updates3.kaspersky-labs.com
    10.18.250.4 updates4.kaspersky-labs.com
    10.18.250.4 updates5.kaspersky-labs.com
    10.18.250.4 us.mcafee.com
    10.18.250.4 vil.nai.com
    10.18.250.4 viruslist.com
    10.18.250.4 viruslist.ru
    10.18.250.4 virusscan.jotti.org
    10.18.250.4 virustotal.com
    10.18.250.4 www.avp.ch
    10.18.250.4 www.avp.com
    10.18.250.4 www.avp.ru
    10.18.250.4 www.awaps.net
    10.18.250.4 www.ca.com
    10.18.250.4 www.f-secure.com
    10.18.250.4 www.fastclick.net
    10.18.250.4 www.grisoft.com
    10.18.250.4 www.kaspersky-labs.com
    10.18.250.4 www.kaspersky.com
    10.18.250.4 www.kaspersky.ru
    10.18.250.4 www.mcafee.com
    10.18.250.4 www.my-etrust.com
    10.18.250.4 www.nai.com
    10.18.250.4 www.networkassociates.com
    10.18.250.4 www.sophos.com
    10.18.250.4 www.symantec.com
    10.18.250.4 www.trendmicro.com
    10.18.250.4 www.viruslist.com
    10.18.250.4 www.viruslist.ru
    10.18.250.4 www.virustotal.com

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

    S!Ri's WS2Fix: LSP not Found.


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\system32\ctfmona.exe Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{5449A36A-5B35-4799-9FB6-8AAAA2DF503E}: DhcpNameServer=10.129.1.65
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{5449A36A-5B35-4799-9FB6-8AAAA2DF503E}: DhcpNameServer=10.129.1.65
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{5449A36A-5B35-4799-9FB6-8AAAA2DF503E}: DhcpNameServer=10.129.1.65
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.129.1.65
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.129.1.65
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=10.129.1.65


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi coste

    Rename HijackThis.exe to coste.exe and let me know if it works now
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Member
    Join Date
    Dec 2007
    Posts
    37

    Smile That worked

    Hi Shaba
    Thank you for the help!
    Renaming HiJack.exe to Coste.exe worked. I am posting the Log.
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:36:05 AM, on 4/14/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 SP2 (7.00.6000.16574)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    C:\WINDOWS\system32\CTsvcCDA.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
    C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
    C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\WINDOWS\stsystra.exe
    C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
    C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\DOCUME~1\HENRYL~1\LOCALS~1\Temp\clclean.0001
    C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
    C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
    C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
    C:\WINDOWS\system32\bolenjx.exe
    C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
    C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    C:\Program Files\DellSupport\DSAgnt.exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    c:\program files\common files\installshield\updateservice\isuspm.exe
    C:\WINDOWS\system32\nod32se.exe
    C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
    C:\Documents and Settings\Henry Latour\Application Data\U3\0000187DA573904E\LaunchPad.exe
    C:\Documents and Settings\Henry Latour\Desktop\Coste.exe.exe

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
    O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
    O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [bolenja] bolenja.exe
    O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
    O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
    O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
    O4 - HKCU\..\Run: [NetSP - restore settings on power failure] "C:\Program Files\AT&T Global Network Client\NetSP.exe" -show
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1144071332203
    O20 - AppInit_DLLs: kus109.dat
    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
    O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\AT&TGL~1\NetCfgSv.EXE
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
    O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
    O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
    O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe

    --
    End of file - 8268 bytes

  4. #4
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    First create own folder for HijackThis to desktop and move it into that folder.

    After that:

    Download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)

    Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
      (Report.txt will also be copied to Clipboard ready for posting back on the forum).
    • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  5. #5
    Member
    Join Date
    Dec 2007
    Posts
    37

    Angry No Luck

    Hi Shaba

    First create own folder for HijackThis to desktop and move it into that folder.

    After that:

    Download SDFix and save it to your Desktop.

    Double click SDFix.exe and it will extract the files to %systemdrive%
    (Drive that contains the Windows Directory, typically C:\SDFix)
    First, when I click on the link for SDFix on my infected system it does'nt go to the site, it stays on the forum page.
    So, I follwed the link on my good system, downloaded SDFix to my memory stick, copied it to the desktop
    of the infected system and tried to run it. When I double-click it does not run, no error message, it just doesn't run.

  6. #6
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Then we use this:

    1. Download combofix from any of these links and save it to Desktop:
    Link 1
    Link 2
    Link 3

    **Note: It is important that it is saved directly to your desktop**

    2. Double click combofix.exe & follow the prompts.
    3. When finished, it shall produce a log for you (C:\ComboFix.txt). Post that log in your next reply

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall

    Combofix should never take more that 20 minutes including the reboot if malware is detected.
    If it does, open Task Manager then Processes tab (press ctrl, alt and del at the same time) and end any processes of findstr, find, sed or swreg, then combofix should continue.
    If that happened we want to know, and also what process you had to end.

    If you have problems with Combofix usage, see here

    Post:

    - a fresh HijackThis log
    - combofix report

    If it doesn't run either, try to run in safe mode.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  7. #7
    Member
    Join Date
    Dec 2007
    Posts
    37

    Angry Something is stopping the programs from running

    Hi Shaba

    **Note: It is important that it is saved directly to your desktop**
    I still have to use the memory stick.
    I tried running Combofix in both normal and safe mode same result
    the file would not run. No error message, it just won't run. I still
    have to use my good system to follow the links.
    Thanks for hanging in there!

  8. #8
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Did you copy it to Desktop before that?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  9. #9
    Member
    Join Date
    Dec 2007
    Posts
    37

    Angry Yes

    Sorry Shaba,
    Yes, I copied it from the memory stick to the desktop, before I tried running it.
    Thanks

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    This should work:

    Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
    1. Close all applications and windows.
    2. Double-click on dss.exe to run it, and follow the prompts.
    3. When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
    4. Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt to your post.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •