This thread's last reply is from July 19, 2008, 12:32 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Gday yet again kind people, thanks for helping me with my other sons laptop especialy you katana much appreciated,my son has had a problem with the wmp not loading running so we did a system restore to an earlier date wmp is now working but unfotunately internet explorer is hijacked multiple pages gambling sites loading offers of anti virus scans pop ups etc really annoying,please help if you can along with stern instructions to my sons on how they can avoid reinfection in the future.
i enclose an hijack this log.
much obliged for your help.
bet regards.
kingdonger Roger...
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:31:52, on 12/07/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal
Hello, and to the Malware Removal forums.
My name is Michael I'll be glad to help you with your computer problems.
HijackThis logs can take some time to research, so please be patient with me. I know that you need
your computer working as quickly as possible, and I will work hard to help see that happen.
Please be patient and I'd be grateful if you would note the following:
I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
The fixes are specific to your problem and should only be used for this issue on this machine.
Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
It's often worth reading through these instructions and printing them for ease of reference.
If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
Please reply to this thread. Do not start a new topic.
Please note: All of my posts need to be checked by a teacher, so please be patient while I attempt to remove your malware.
Make an uninstall list using HijackThis
To access the Uninstall Manager you would do the following:
Start HijackThis
Click on the Config button
Click on the Misc Tools button
Click on the Open Uninstall Manager button.
Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Save the file to your desktop.
gday your help is much appreciated here is the log you required.
best regards roger..
Activation Assistant for the 2007 Microsoft Office suites
Adobe Flash Player ActiveX
Adobe Reader 8.1.0
Adobe Shockwave Player
AIM 6
AOL Toolbar 5.0
Atheros Driver Installation Program
Compatibility Pack for the 2007 Office system
Conexant HD Audio
CyberLink YouCam
DVD Suite
EA Link
ESU for Microsoft Vista
HDAUDIO Soft Data Fax Modem with SmartCP
Hewlett-Packard Active Check
Hewlett-Packard Asset Agent for Health Check
HP Customer Experience Enhancements
HP Doc Viewer
HP DVD Play 3.6
HP Easy Setup - Frontend
HP Help and Support
HP Quick Launch Buttons 6.30 D2
HP Total Care Advisor
HP Update
HP User Guides 0091
HP Wireless Assistant
Java(TM) 6 Update 2
LabelPrint
Microsoft Office Excel MUI (English) 2007
Microsoft Office Home and Student 2007
Microsoft Office Home and Student 2007
Microsoft Office OneNote MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office PowerPoint Viewer 2007 (English)
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
MSCU for Microsoft Vista
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB941833)
muvee autoProducer 6.1
My HP Games
NetWaiting
NVIDIA Drivers
Power2Go
PowerDirector
QuickPlay SlingPlayer 0.4.4
Revo Uninstaller 1.71
SpywareBlaster 4.1
Synaptics Pointing Device Driver
The Shield Deluxe 2008
The Sims™ Life Stories
Update for Office 2007 (KB934528)
Viewpoint Media Player
ps i'm pretty sure that the shield deluxe is an virus as i have seen refrence to this elseware on this forum,unsure how to get rid though,,,,
awaiting your reply..
best regards Roger
Note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.
My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).
If you wish to keep them, please do not use them until your computer is cleaned.
Download and Run DSS
Download Deckard's System Scanner (DSS) to your Desktop. You must be logged onto an account with administrator privileges.
Close all applications and windows.
Double-click on dss.exe to run it, and follow the prompts.
When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<- this one will be minimized.
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your reply.
Thanks for your help here are the scan results you asked for.
best regards Roger...
Deckard's System Scanner v20071014.68
Run by [redacted] on 2008-07-14 20:25:32
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
20: 2008-07-14 19:20:16 UTC - RP28 - Windows Update
19: 2008-07-12 10:47:47 UTC - RP27 - Restore Operation
18: 2008-07-10 19:41:39 UTC - RP26 - Windows Update
17: 2008-07-10 18:01:19 UTC - RP25 - Installed OpenOffice.org Installer 1.0
16: 2008-07-10 17:58:57 UTC - RP24 - Installed Java(TM) 6 Update 7
-- First Restore Point --
1: 2008-07-04 16:20:19 UTC - RP4 - First_User_Boot
Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-07-14 20:29:59
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.00.6000.16386)
Boot mode: Normal
R2 HP Health Check Service - "c:\program files\hewlett-packard\hp health check\hphc_service.exe" <Not Verified; Hewlett-Packard; HP Health Check Service>
S3 Com4Qlb - "c:\program files\hewlett-packard\hp quick launch buttons\com4qlb.exe" <Not Verified; Hewlett-Packard Development Company, L.P.; HP Quick Launch Buttons>
-- End of Deckard's System Scanner: finished at 2008-07-14 20:31:07 ------------
Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft® Windows Vista™ Home Premium (build 6000)
Architecture: X86; Language: English
Event Record #/Type1324 / Error
Event Submitted/Written: 07/14/2008 08:21:28 PM
Event ID/Source: 5007 / WerSvc
Event Description:
The target file for the Windows Feedback Platform (a DLL file containing the list of problems on this computer that require additional data collection for diagnosis) could not be parsed. The error code was 8014FFF9.
Event Record #/Type1321 / Error
Event Submitted/Written: 07/14/2008 08:19:29 PM
Event ID/Source: 1002 / Application Hang
Event Description:
The program Explorer.EXE version 6.0.6000.16549 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 718
Start Time: 01c8e5e60608cc08
Termination Time: 0
Event Record #/Type1318 / Error
Event Submitted/Written: 07/14/2008 08:18:29 PM
Event ID/Source: 1002 / Application Hang
Event Description:
The program WinMail.exe version 6.0.6000.16480 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel.
Process ID: 134
Start Time: 01c8e5e637533488
Termination Time: 6
-- System Event Log ------------------------------------------------------------
Event Record #/Type9874 / Warning
Event Submitted/Written: 07/14/2008 08:30:16 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%David-Laptop27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %David-Laptop27 can't undo changes that you allow.
For more information please see the following:
%David-Laptop275
Scan ID: {AB46BEF5-5DE9-48A9-B10E-78F77D14A178}
User: David-Laptop\David
Name: %David-Laptop271
ID: %David-Laptop272
Severity ID: %David-Laptop273
Category ID: %David-Laptop274
Path Found: %David-Laptop276
Alert Type: %David-Laptop278
Detection Type: 1.1.1505.02
Event Record #/Type9873 / Warning
Event Submitted/Written: 07/14/2008 08:30:16 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%David-Laptop27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %David-Laptop27 can't undo changes that you allow.
For more information please see the following:
%David-Laptop275
Scan ID: {3243D8CC-F7EC-43C7-A95E-A286B832BEF2}
User: David-Laptop\David
Name: %David-Laptop271
ID: %David-Laptop272
Severity ID: %David-Laptop273
Category ID: %David-Laptop274
Path Found: %David-Laptop276
Alert Type: %David-Laptop278
Detection Type: 1.1.1505.02
Event Record #/Type9872 / Warning
Event Submitted/Written: 07/14/2008 08:30:16 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%David-Laptop27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %David-Laptop27 can't undo changes that you allow.
For more information please see the following:
%David-Laptop275
Scan ID: {BCC2926F-DA08-4938-A7F1-A6E0E87C04BB}
User: David-Laptop\David
Name: %David-Laptop271
ID: %David-Laptop272
Severity ID: %David-Laptop273
Category ID: %David-Laptop274
Path Found: %David-Laptop276
Alert Type: %David-Laptop278
Detection Type: 1.1.1505.02
Event Record #/Type9871 / Warning
Event Submitted/Written: 07/14/2008 08:30:14 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%David-Laptop27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %David-Laptop27 can't undo changes that you allow.
For more information please see the following:
%David-Laptop275
Scan ID: {54CB5ACD-3CC1-44F3-BA00-6A024B99BDAF}
User: David-Laptop\David
Name: %David-Laptop271
ID: %David-Laptop272
Severity ID: %David-Laptop273
Category ID: %David-Laptop274
Path Found: %David-Laptop276
Alert Type: %David-Laptop278
Detection Type: 1.1.1505.02
Event Record #/Type9870 / Warning
Event Submitted/Written: 07/14/2008 08:30:14 PM
Event ID/Source: 3004 / WinDefend
Event Description:
%David-Laptop27 Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. %David-Laptop27 can't undo changes that you allow.
For more information please see the following:
%David-Laptop275
Scan ID: {76669C32-EC2B-47C4-89BC-281481D4D64B}
User: David-Laptop\David
Name: %David-Laptop271
ID: %David-Laptop272
Severity ID: %David-Laptop273
Category ID: %David-Laptop274
Path Found: %David-Laptop276
Alert Type: %David-Laptop278
Detection Type: 1.1.1505.02
-- End of Deckard's System Scanner: finished at 2008-07-14 20:31:07 ------------
Download and Run: OTMoveIt2
Please download OTMoveIt2 by OldTimer.
Save it to your desktop.
Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If you are not asked to reboot close OTMoveIt2.
A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform Full scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please copy and paste the log back into your next reply
Note:
The log can also be found here:
C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
Or via the Logs tab when Malwarebytes' Anti-Malware is started.
Run Kaspersky Online Scan
Please go to Kaspersky website and perform an online antivirus scan.
Read through the requirements and privacy statement and click on Accept button.
It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
When the downloads have finished, click on Settings.
Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
Spyware, Adware, Dialers, and other potentially dangerous programs
Archives
Mail databases
Click on My Computer under Scan.
Once the scan is complete, it will display the results. Click on View Scan Report.
You will see a list of infected items there. Click on Save Report As....
Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button.
Please post this log in your next reply.
Please post the OTMoveIt2 log, the MBAM log, and the Kaspersky online scan log.
once again many thanks for your help.
i have done everything you have recommended including the kaspersky online scan this showed i was infected but when i clicked on save report as it would not save i was logged on ie as administrator etc but the saved file showed up through kaspersky save pane but will not in explorer i have now done 4 scans and been unable to save them taking into account that each scan takes in excess of 1 and a half hours this is annoying,will try again here are the other logs you requested.
best regards-Roger..
File/Folder C:\Users\David\AppData\Local\Temp\ddcYqpoO.dll not found.
File/Folder C:\Users\David\AppData\Local\Temp\pmnljHwx.dll not found.
File/Folder C:\Users\David\AppData\Local\Temp\wyfawidu.dll not found.
File/Folder C:\Users\David\AppData\Local\Temp\pulrbsxm.dll not found.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MSServer >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\MSServer not found.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cmds >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\cmds not found.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BM0b433c09 >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\BM0b433c09 not found.
< HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\08700f95 >
Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\08700f95 not found.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07152008_142731
Malwarebytes' Anti-Malware 1.20
Database version: 951
Windows 6.0.6000
gday again eventualy managed to get the report off kaspersky doesnt make very good reading does it.
regards-Roger...
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Tuesday, July 15, 2008
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Tuesday, July 15, 2008 19:30:26
Records in database: 957023
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 124075
Threat name: 7
Infected objects: 23
Suspicious objects: 0
Duration of the scan: 01:34:14
File name / Threat name / Threats count
C:\Deckard\System Scanner\backup\Users\David\AppData\Local\Temp\eceywurk.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\Deckard\System Scanner\backup\Users\David\AppData\Local\Temp\krjthweg.dll Infected: Trojan.Win32.Monderc.gen 1
C:\Deckard\System Scanner\backup\Users\David\AppData\Local\Temp\ldxtmsmc.dll Infected: Trojan.Win32.Monderc.gen 1
C:\Deckard\System Scanner\backup\Users\David\AppData\Local\Temp\mcgfdahx.dll Infected: Trojan.Win32.Obfuscated.auw 1
C:\Deckard\System Scanner\backup\Users\David\AppData\Local\Temp\obtetiuu.dll Infected: Trojan.Win32.Monderc.gen 1
C:\Deckard\System Scanner\backup\Users\David\AppData\Local\Temp\yiohyeyk.dll Infected: Trojan.Win32.Monderc.gen 1
C:\ProgramData\BOC426\evidence.boc Infected: Trojan.Win32.Monderc.gen 1
C:\Users\All Users\BOC426\evidence.boc Infected: Trojan.Win32.Monderc.gen 1
C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CE37VL6A\kb111653[1] Infected: Trojan.Win32.Obfuscated.auw 1
C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDV31B0M\kb767887[1] Infected: Trojan.Win32.Monderc.gen 1
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\bitdefender_totalsecurity_2008_32b.exe Infected: Trojan.Win32.Monder.gen 1
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\bitdefender_totalsecurity_2008_32b.exe Infected: Trojan-Downloader.MSIL.Agent.ax 1
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\key.exe Infected: Trojan-Downloader.MSIL.Agent.ax 1
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\patch.exe Infected: Trojan-Downloader.MSIL.Agent.ax 1
C:\Users\David\Desktop\downloads bit torrent etc\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key].rar Infected: Trojan.Win32.Monder.gen 1
C:\Users\David\Desktop\downloads bit torrent etc\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key].rar Infected: Trojan-Downloader.MSIL.Agent.ax 3
C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked\WinRAR v3.80.1-Full Cracked\setup.exe Infected: Trojan-Downloader.Win32.Tiny.bqh 1
C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked\WinRAR v3.80.1-Full Cracked\setup.exe Infected: Trojan-Downloader.Win32.Agent.utw 1
C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked.zip Infected: Trojan-Downloader.Win32.Tiny.bqh 1
C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked.zip Infected: Trojan-Downloader.Win32.Agent.utw 1
C:\Users\David\Desktop\downloads bit torrent etc\WORKING Shield Deluxe 2008 Cracked\ShieldDeluxe2008Setup.exe Infected: not-a-virus:AdWare.Win32.Virtumonde.tso 1
I notice that you have some cracked programs on your computer, which is illegal. If you want me to continue helping you get clean, you need to remove them.
Remove Cracked Programs
Now we will uninstall some programs
click on start
then to settings
then to control panel
in control panel find add/remove programs and double click it
now search for and remove the programs below
BitDefender Pro Total Security 2008
WinRAR v3.80.1
Shield Deluxe 2008
Run: OTMoveIt2
Please double-click OTMoveIt2.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
C:\ProgramData\BOC426\evidence.boc
C:\Users\All Users\BOC426\evidence.boc
C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CE37VL6A\kb111653[1]
C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDV31B0M\kb767887[1]
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\bitdefender_totalsecurity_2008_32b.exe
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\key.exe
C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\patch.exe
C:\Users\David\Desktop\downloads bit torrent etc\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key].rar
C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked\WinRAR v3.80.1-Full Cracked\setup.exe
C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked.zip
C:\Users\David\Desktop\downloads bit torrent etc\WORKING Shield Deluxe 2008 Cracked\ShieldDeluxe2008Setup.exe
Return to OTMoveIt2, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
If you are not asked to reboot close OTMoveIt2.
A log C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log will be created (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
Please then re-run the Kaspersky online scan following the instruction in the previous post.
Please then post the OTMoveIt2 log and the Kaspersky log.
the cracked prorams you asked me to remove do not showw in add and remove programs but the shield deluxe shows in program files and i cannot delete here are the latest logs.
regards Roger..
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Wednesday, July 16, 2008
Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit (build 6000)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Wednesday, July 16, 2008 20:05:06
Records in database: 960465
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
E:\
Scan statistics:
Files scanned: 124213
Threat name: 7
Infected objects: 22
Suspicious objects: 0
Duration of the scan: 01:23:32
File/Folder C:\ProgramData\BOC426\evidence.boc not found.
File/Folder C:\Users\All Users\BOC426\evidence.boc not found.
< C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CE37VL6A\kb111653[1] >
File/Folder C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CE37VL6A\kb111653[1] not found.
< C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDV31B0M\kb767887[1] >
File/Folder C:\Users\David\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IDV31B0M\kb767887[1] not found.
< C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\bitdefender_totalsecurity_2008_32b.exe >
File/Folder C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\bitdefender_totalsecurity_2008_32b.exe not found.
< C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\key.exe >
File/Folder C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\key.exe not found.
< C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\patch.exe >
File/Folder C:\Users\David\Desktop\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key]\patch + keygen\patch.exe not found.
< C:\Users\David\Desktop\downloads bit torrent etc\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key].rar >
File/Folder C:\Users\David\Desktop\downloads bit torrent etc\BitDefender Pro Total Security 2008 [(Antivirus & Antispyware) + Key].rar not found.
File/Folder C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked\WinRAR v3.80.1-Full Cracked\setup.exe not found.
File/Folder C:\Users\David\Desktop\downloads bit torrent etc\WinRAR v3.80.1-Full Cracked.zip not found.
File/Folder C:\Users\David\Desktop\downloads bit torrent etc\WORKING Shield Deluxe 2008 Cracked\ShieldDeluxe2008Setup.exe not found.
OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07162008_201614
This is my normal post for when you are clear - which you now are - or seem to be.
Please advise of any problems you still have. If you think you're clean please give one more reply so that I can archive this topic.
Now that you are clean, I have some tips & tricks for you to keep your computer clean and secure. The first few (like removing dangerous tools and Windows Update) have to be done, the others are optional (beginning with Spybot S &D).
It may seem like your system will be too much protected with all these things installed, but a lot of programs aren't running always on the background so don't slow down your computer. Please take a look at the following things:
Delete Harmful tools with OTMoveIt2
Start OTMoveIt.exe
Click on CleanUp!
A list of tools will be downloaded from the internet
When a box pops up click Yes
You may delete any logs that any of the tools produced.
Clear Old System Restore Points
Turn System Restore off
On the Desktop, right click on the My Computer icon.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Turn System Restore on
On the Desktop, right click on the My Computer icon.
Click Properties.
Click the System Restore tab.
Uncheck *Turn off System Restore*.
Click Apply, and then click OK.
Note: only do this once,and not on a regular basis
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt
When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
Tutorail for Spybot S & D
Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. You can download it here: SpywareBlaster
Install WinPatrol - As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge. You can download it from this website: WinPatrol
The developer is a well-known man in the MalWare Removal business. If you really like WinPatrol think about upgrading to the PLUS version. It will give you additional features and you will only have to pay once, for your whole malware-free life.
Install MVPS HOSTS - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial here: WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.
Use an alternative Internet Browser - Many of the exploits are directed to users of Internet Explorer. Try using a different browser instead: Firefox << Most used, I use this one myself.
Opera
Bookmark general cleanup links - It could be that your computer is becoming slower and slower. This is not always the cause of malware. Most of the times it's malware when you're computer is suddenly getting slow or doing strange. When the slowdown increases slowly check (so now bookmark) these links for tips & tricks:
Help! My computer is slow
Slow Computer? Check here first; it may not be malware
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.
Stand Up and Be Counted!
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints called Malware Complaints.
Gday sir unable to delete pc security the shield 2008 i have reason to believe this is a virus as i have seen refrence to it elseware in your forum program is still starting up but is not shown in add and remove programs the program files are there and i cannot delete them program is showing in msconfig.
awaiting your reply...
Roger...
Download and Run Avenger
Download Avenger by Swandog46 from here.
Unzip/extract it to a folder on your desktop.
Double click on avenger.exe to run it.
Click OK.
Make sure that the box next to Scan for rootkits has a tick in it and that the box next to Automatically disable any rootkits found does not have a tick in it.
Copy all of the text in the below textbox to the clibpboard by highlighting it and then pressing Ctrl+C.
Drivers to delete:
AVP
Folders to delete:
C:\Program Files\PCSecurityShield\
In the avenger window, click the Paste Script from Clipboard, button.
Click the Execute button.
You will be asked Are you sure you want to execute the current script?.
Click Yes.
You will now be asked First step completed --- The Avenger has been successfully set up to run on next boot. Reboot now?.
Click Yes.
Your PC will now be rebooted.
Note: If the above script contains Drivers to delete: or Drivers to disable:, then Avenger will require two reboots to complete its operation. If that is the case, it will force a BSOD on the first reboot. This is normal & expected behaviour.
After your PC has completed the necessary reboots, a log should automatically open. If it does not automatically open, then the log can be found at %systemdrive%\avenger.txt (typically C:\avenger.txt).
Close the log for now.
Please post this log and a new Hijackthis log on your next reply.
Gday many thanks for your help here are the logs you requested.
regards
roger..
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:55:14, on 18/07/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16681)
Boot mode: Normal
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.