I need help!- Spybot found Command Service!

Status
Not open for further replies.
That fixed my problem installing Java and also with Internet Explorer not working! I think all problems are solved now!

Thanks a bunch!

If I ever experience problems again with this computer or a different one, should I start a new thread or continue in this one?
 
That`s good news.

If you have spyware/virus problems with that computer again, then post in this thread.

If it`s a different computer, then a new thread would be more appropriate.

Regards Howard :)

This thread is for the use of nikoanime only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
I'm Back!

Hi...
I'm experiencing a different type of problem now with this same computer. When attempting to shut down or restart, I receive a "blue screen of death" message... This started happening yesterday from what I can remember...

Page_fault_in_nonpaged area
Caused by following file: dump_wmimmc.sys
*** Stop 0x00000050 (0xFFFFFFD8, 0x00000000, 0xED7dEA39, 0x00000000)
*** dump_wmimmc.sys -Address ED7DEA39 base at ED7DC000, Datestamp 4701ede7

What can I do?
I'm running AVG right now...
Thanks again!
 
DUMP_WMIMMC.SYS is considered nasty.

Please post fresh HJT, Combofix and AVG Antispyware logs. Alos, please run the Panda Antirootkit programme and let me know the results.

Regards Howard :)

This thread is for the use of nikoanime only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Can`t you read? I asked you for the results of the Panda Antirootkit scan.

Delete all files in AVG Antispyware quarantine.

Your HJT log is clean.

Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..

Pay particular attention to this :-

Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:


File::
C:\Program Files\Wizet\MapleStory\GameGuard\dump_wmimmc.sys
C:\WINDOWS\system32\drivers\htbooprdeauj.sys

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{51dd198c-2dc0-11dc-98b3-0012f04d0efe}]
Save this as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.

CFScript.gif


This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply together with the results of the Panda Antirootkit scan.

Regards Howard :)

This thread is for the use of nikoanime only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Sorry for my neglect to fully post. I admit I was in a rush running out the door last night before posting. Panda didn't find anything in rootkits.

Following second set of instructions that were posted now.
 
Howard, I hadn't come across the 'Dump_wmi mmc' before so I went looking for it Didn't get far. Most sites are foreign, a good indication of a 'nasty'. It looks like it might be some kind of hacker's tool. I couldn't find anything else. 'Course, WMI and MMC are legit, but have no doubt the string dump_wmimmc.sys is a nasty, but wondered if you had any more info on it? I found some indication associates with the game portal gPotato, but the McAfee Site Advisor declares that site clean.

Thanks
 
Here's a fresh HJT log from today along with the requested ComboFix (the first 2 logs it created were completely blank, nothing in them at all) And as I said, the Panda software didn't find anything.
 
That all looks clean.

Turn off system restore.(XP/ME only) See how HERE.

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.


If you have any further virus/spyware problems, please post in this thread.

Regards Howard :)

This thread is for the use of nikoanime only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Status
Not open for further replies.
Back