Really don't know what it is, but it sure is wierd.

Status
Not open for further replies.
And at the moment it's doing well, no more wierd CPU increases as far as I know. Internets no more lagging.muha:

:thanks:
I am very thank full for your assistance, :D:

Although I have a few (small) questions left, which i'd like to ask :)


1. Is there a way to tell if I really, really, really am clear of all Mal-/spyware and/or virus thingies ?
2. There's alot of wierd named maps in my hdd, some empty doing pretty much nothing at all.. whats with them?:P
3. There's 2 more computers wich regularly log on the home-network(just a nothing-special Lan), one is my mom's PC, she checks msn everyday, does some surfing etc, but thats pretty much it. The other one is my laptop, which I need for school.

Are they worth making a topic for? Since my mom's pc only has like a hdd of like.. 3-4gb max :') and the laptop doesn't "directly" connect that much anyway, most likely Ill WiFi on my neighbours connection.

Lot's of thanks! :):thanks::rockon:
 
Hi. :)

And at the moment it's doing well, no more wierd CPU increases as far as I know. Internets no more lagging.
Good to know.

I am very thank full for your assistance,

Although I have a few (small) questions left, which i'd like to ask
You're welcome and by all means you may ask.

1. Is there a way to tell if I really, really, really am clear of all Mal-/spyware and/or virus thingies ?
My research of the last ComboFix log and other scans I asked for do indeed appear to confirm your computer to be malware free.

2. There's alot of wierd named maps in my hdd, some empty doing pretty much nothing at all.. whats with them?:
I'm sorry I do not understand what you mean. Could you elaborate further please.

3. There's 2 more computers wich regularly log on the home-network(just a nothing-special Lan), one is my mom's PC, she checks msn everyday, does some surfing etc, but thats pretty much it. The other one is my laptop, which I need for school.

Are they worth making a topic for? Since my mom's pc only has like a hdd of like.. 3-4gb max :') and the laptop doesn't "directly" connect that much anyway, most likely Ill WiFi on my neighbours connection.
There was no indication of the type of malware that would spread via a network. For peace of mind I suggest if a Router in use, reset it and apply a admin password. You could run a online scan on both also as a further precaution. When I post my all clean speech to remove the tools we have used, it also includes advice about online safety, you could implement the measures I will mention on these computers also.
 
Hi. :)

Do you still require assistance with this issue?
2. There's alot of wierd named maps in my hdd, some empty doing pretty much nothing at all.. whats with them?:

I'm sorry I do not understand what you mean. Could you elaborate further please.
If not let myself know and I will post the relevant information I mentioned prior about removing the tools we have used during the malware removal process and provide some advice about online safety etc.
 
Hey Hey,

Sorry for the long time lapse here, weekends/alcohol/etc. :alien:

But I've did some looking around and most maps that I found wierd are indeed gone. Although there are a few which I still find.. suspecious;

ba48ca1b01ae6718069416
6,12mb size on HDD

In it are "amd64" "I386", also maps..

Config.Msi (Maybe a combofix related map?)

and the map "temp" has a submap named ext18866.. in it are;
"install.exe"
"install.res.dll"

and in C:\Documents and Settings\Administrator ;

dd_dotnetfx35error_lp.txt
dd_NET_Framework35_LangPack_MSI10A7.txt
DelDC6.bat
DelDC6.tmp
NTUSER.DAT

just a random pick of name's.. I believe the, sort off, same file(names) I can find in pretty much every documents & settings account.

and for example in the C:\WINDOWS

Maps:
ie8(hidden)
ie8updates
ie7updates
Downloaded Program Files
WinSxS
twain_32
security
Registration
RegisteredPackages
Microsoft.NET
ERDNT
ehome
assembly
and (alot) more.

Loose files in C:\WINDOWS ;

clock.avi
bootstat.dat
Ascd_tmp.ini
_delis32.ini
atiogl.xml
NIRCMD.exe
twunk_16.exe
twunk_32.exe
And ALOT more..

And the, as far as I know, normal $NtUninstallKBetcetc.$

greetings, and very, very, very, very much thanks.:rockon::thanks:
 
Hi. :)

Sorry for the long time lapse here, weekends/alcohol/etc.
OK no problem, do not over do it eh. ;).......:laugh:

OK levity aside.

What you have mentioned is fine and actual legitimate files and others created during the malware removal process which will be removed in due course with my below instructions.

Next:

Congratulations your computer now appears to be malware free!

Now I have some tasks for your good self to carry out as part of a clean up process and some advice about online safety.

Importance of Regular System Maintenance:

I advice you read both of the below listed topics as this will go a long way to keeping your Computer performing well.

Help! My computer is slow!

Also so is this:

What to do if your Computer is running slowly

I advice you also fun a ChkDsk at some point as outlined in this tuturial of mine.

Uninstall ComboFix:
  • Click on Start >> Run...
  • Now type in Combofix /u in the and click OK.
  • Note the space between the X and the U, it needs to be there.
  • CF_Cleanup.png
OTC:

Please download OTC and save it to desktop. This tool will remove all the tools we used to clean your pc.
  • Double-click OTC.exe.
  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes, if not delete it by yourself.
Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

Now some advice for on-line safety:

Malwarebyte's Anti-Malware:

This is a excellent application and I advise you keep this installed. Check for updates and run a scan once a week.

Other installed security software:

Your presently installed Anti-Virus application, Avira AntiVir automatically checks for updates and downloads/installs them with every system reboot and or periodically if the machine is left running providing a internet connection is active.

I advise you also run a complete scan with this also once per week.

Keep your system updated:

Microsoft releases patches for Windows and other products regularly:
Be careful when opening attachments and downloading files:
  • Never open email attachments, not even if they are from someone you know. If you need to open them, scan them with your antivirus program before opening.
  • Never open emails from unknown senders.
  • Beware of emails that warn about viruses that are spreading, especially those from antivirus vendors. These email addresses can be easily spoofed. Check the antivirus vendor websites to be sure.
  • Be careful of what you download. Only download files from known sources. Also, avoid cracked programs. If you need a particular program that costs too much for you, try finding free alternatives on Sourceforge or Pricelessware.
Stop malicious scripts:

Windows by default allow scripts (which is VBScript and JavaScript) to run and some of these scripts are malicious. Use Noscript by Symantec or Script Defender by AnalogX to handle these scripts.

Make your Internet Explorer safer:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialise and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
Avoid Peer to Peer software:

P2P may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. My advice avoid these types of software applications.

Enable Spybot S&D TeaTimer:

You can start Resident TeaTimer by clicking on Tools ? Resident on the left navigation bar (therefore Spybot-S&D has to run in Advanced Mode). There you can tick the checkboxes next to Resident "TeaTimer" (Protection of over-all system settings) active in order to activate TeaTimer.

Further information on how to use this application can be found here.

Advised Optional Installation:

There is no sign of a software firewall installed on your system. Regardless if using a hardware type and or using the inbuilt Windows Service Pack 3 firewall this is a necessary application as it will also provide outbound protection where as the aforementioned do not.

I highly advise you download ONE of the following firewalls and install it. Restart the computer for changes to take effect.
This article is a excellent resource regarding the aforementioned firewalls: Understanding and Using Firewalls

Finally a educational source:

To learn more about how to protect yourself while on the internet read this article by Tony Klein(updated by tashi):

So how did I get infected in the first place?

Any questions, feel free to ask. If not stay safe!
 
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required.
 
Status
Not open for further replies.
Back
Top