The rest of files
You may want to try Malwarebytes now, as i sendt the sample to them yesterday so it may be updated on it… ???
Malwarebytes Anti-Malware 1.46 http://filehippo.com/download_malwarebytes_anti_malware/
always run update so you have the latest database before you scan
click the remove selected button to quarantine anything found
post the scan log here
Hi do you recognise these two folders ? The names are nearly right but not quite. If you do not I will have a look inside
C:\WINDOWS\XSxS C:\WINDOWS\System32\winsRun OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:OTL [2010/07/30 09:07:07 | 000,000,774 | ---- | M] () -- C:\Documents and Settings\FS\Start Menu\Programs\Startup\TotalAntiSpyware.lnk:Files
ipconfig /flushdns /c:Commands
[purity]
[resethosts]
[emptytemp]
[EMPTYFLASH]
[CREATERESTOREPOINT]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
.
THEN
.
Please download SystemLook from one of the links below and save it to your Desktop.
Download Mirror #1
Download Mirror #2
[*]Double-click SystemLook.exe to run it.
[*]Copy the content of the following codebox into the main textfield:
:dir
C:\WINDOWS\XSxS
C:\WINDOWS\System32\wins
[*]Click the Look button to start the scan.
[*]When finished, a notepad window will open with the results of the scan. Please post this log in your next reply.
Note: The log can also be found on your Desktop entitled SystemLook.txt
All processes killed
========== OTL ==========
C:\Documents and Settings\FS\Start Menu\Programs\Startup\TotalAntiSpyware.lnk moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Documents and Settings\FS\My Documents\Downloads\cmd.bat deleted successfully.
C:\Documents and Settings\FS\My Documents\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: FS
->Temp folder emptied: 72598169 bytes
->Temporary Internet Files folder emptied: 10098210 bytes
->FireFox cache emptied: 48368478 bytes
->Flash cache emptied: 641 bytes
User: LocalService
->Temp folder emptied: 2052424 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 1985336 bytes
->Temporary Internet Files folder emptied: 33237 bytes
User: NN
->Temp folder emptied: 6788435 bytes
->Temporary Internet Files folder emptied: 29055413 bytes
->FireFox cache emptied: 52867552 bytes
->Flash cache emptied: 1095 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2162283 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 72798921 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 285.00 mb
[EMPTYFLASH]
User: All Users
User: Default User
User: FS
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
User: NN
->Flash cache emptied: 0 bytes
Total Flash Files Cleaned = 0.00 mb
Restore point Set: OTL Restore Point (0)
OTL by OldTimer - Version 3.2.10.0 log created on 08312010_182632
Files\Folders moved on Reboot...
C:\Documents and Settings\FS\Local Settings\Temp\~DF8717.tmp moved successfully.
C:\Documents and Settings\FS\Local Settings\Application Data\Mozilla\Firefox\Profiles\xp2qetkm.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\FS\Local Settings\Application Data\Mozilla\Firefox\Profiles\xp2qetkm.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\FS\Local Settings\Application Data\Mozilla\Firefox\Profiles\xp2qetkm.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\FS\Local Settings\Application Data\Mozilla\Firefox\Profiles\xp2qetkm.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\FS\Local Settings\Application Data\Mozilla\Firefox\Profiles\xp2qetkm.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\FS\Local Settings\Application Data\Mozilla\Firefox\Profiles\xp2qetkm.default\XUL.mfl moved successfully.
File\Folder C:\WINDOWS\temp\ZLT0527c.TMP not found!
Registry entries deleted on Reboot...
Hi,
This is the result of OTL Quick Scan for all user
Tnx
And this is the Systemlook log:
SystemLook v1.0 by jpshortstuff (11.01.10)
Log created at 18:51 on 31/08/2010 by FS (Administrator - Elevation successful)
========== dir ==========
C:\WINDOWS\XSxS - Parameters: "(none)"
---Files---
None found.
---Folders---
Manifests d----- [14:53 07/08/2010]
Microsoft.VC80.ATL@8.0.50727.4053 d----- [14:53 07/08/2010]
Microsoft.VC80.CRT@8.0.50727.4053 d----- [14:53 07/08/2010]
Microsoft.VC80.MFC@8.0.50727.4053 d----- [14:53 07/08/2010]
Microsoft.VC80.MFCLOC@8.0.50727.4053 d----- [14:53 07/08/2010]
Microsoft.VC80.OpenMP@8.0.50727.4053 d----- [14:53 07/08/2010]
Nullsoft.NSIS.exehead@1.0.0.0 d----- [14:53 07/08/2010]
Yahoo Auto Updater@1.0.0.0 d----- [14:53 07/08/2010]
C:\WINDOWS\System32\wins - Parameters: "(none)"
---Files---
None found.
---Folders---
None found.
-=End Of File=-
Nothing evident there - apart from two antiviru programmes Fprot and Avast. Did you set the proxy setting on Firefox ?
Download ComboFix from one of these locations:
* IMPORTANT !!! Save ComboFix.exe to your Desktop
[*]Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
[*]Double click on ComboFix.exe & follow the prompts.
[*]As part of it’s process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it’s strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
[*]Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it’s malware removal procedures.
http://img.photobucket.com/albums/v706/ried7/RcAuto1.gif
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
http://img.photobucket.com/albums/v706/ried7/whatnext.png
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
Nothing evident there - apart from two antiviru programmes Fprot and Avast.removal tool for F-prot can be found here #12a and #12b http://uninstallers.blogspot.com/
Combofix result
Hi the Flash player was infected - but not any more
What problems are you having now ?
I’m programing, PHP, sometimes my system has very little speed or goes hang and sometimes is ok
You may want to trim some of your start up programmes which will free some resources. At the end there is a small programme I use for this
Looking at that I am a happy bunny
I will remove my tools now and give some recommendations, but I would like you to run for 24 hours or so and come back if you have any problems
Now the best part of the day ----- Your log now appears clean
A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
:Commands [resethosts] [purity] [emptytemp] [EMPTYFLASH] [CLEARALLRESTOREPOINTS] [Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
Click Start > Run and copy/paste the following bolded text into the Run box and click OK:
ComboFix /Uninstall
Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself. MBAM can be uninstalled via control panel add/remove along with ERUNT. But they may be useful tools to keep
We will now confirm that your hidden files are set to that, as some of the tools I use will change that
[*]Click Start.
[*]Open My Computer.
[*]Select the Tools menu and click Folder Options.
[*]Select the View Tab.
[*]Under the Hidden files and folders heading select Do not show hidden files and folders.
[]Click Yes to confirm.
[]Click OK.
http://users.telenet.be/bluepatchy/miekiemoes/images/javaicon.gif
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems
Upgrading Java:
[*]Download the latest version of Java SE Runtime Environment (JRE)JRE 6 Update 21.
[*]Click the “Download” button to the right.
[*]Select your Platform and check the box that says: “I agree to the Java SE Runtime Environment 6 License Agreement.”.
[*]Click on Continue.
[*]Click on the link to download Windows Offline Installation (jre-6u21-windows-i586-p.exe) and save it to your desktop. Do NOT use the Sun Download Manager…
[*]Close any programs you may have running - especially your web browser.
[*]Go to Start > Control Panel, double-click on Add/Remove programs and remove all older versions of Java.
[*]Check any item with Java Runtime Environment (JRE or J2SE) in the name.
[*]Click the Remove or Change/Remove button.
[*]Repeat as many times as necessary to remove each Java version.
[*]Reboot your computer once all Java components are removed.
[*]Then from your desktop double-click on the download to install the newest version.(Vista users, right click on the jre-6u21-windows-i586-p.exe and select “Run as an Administrator.”)
SPRING CLEAN
Download and run Puran Disc Defragmenter
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
[*]SpywareBlaster to help prevent spyware from installing in the first place.
http://img233.imageshack.us/img233/7729/mbamicontw5.gif
Malwarebytes. Run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To keep your operating system up to date visit
[*]Microsoft Windows Update
To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?
Keep safe
To try and ease the startup try this
Download Startup Control Panel here
Instal and you will find a startup icon in the control panel - run this
[*] In the HKLM tab, you may disable (be careful → “disable”) all the entries except your security software
[*] In the HKCU tab, you may disable all entries.
[*] In the StartUp tab, you may disable all entries.
Note : if you notice that some programs no longer run, you can enable them again by running Startup Control Panel, selecting the entry and choosing Run Now.
If you are in doubt with something, don’t hesitate to ask
When I tried to download Java by clicking on the download link, I saw bellow message in next page:
File not found
Firefox can't find the file at http://cds-esd.sun.com/ESD6/JSCDL/jdk/6u21-b07/jre-6u21-windows-i586.exe?AuthParam=1283407101_61006f8aa25e38de83c8cb399321ff2c&TicketId=B/w8lhuGTVlOSxxHO1Nalg7q&GroupName=CDS&FilePath=/ESD6/JSCDL/jdk/6u21-b07/jre-6u21-windows-i586.exe&File=jre-6u21-windows-i586.exe.
Could you try IE as the link works for me