TechSpot

Logs attached - just need confirmation

By wallywimple
Dec 7, 2007
  1. A computer on my home network was infected, these are from another computer.
    PANDA reported no rootkits found.
     
  2. momok

    momok TS Rookie Posts: 2,265

    Hi,

    You may wish to copy and paste these instructions on notepad for easier reference later.

    1. Boot into safe mode under your normal user name. See how HERE
    2. Next turn on "Show all files and folders, including hidden and system". See how HERE

    3. Go to start > run and type services.msc. Press the enter key.
      Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

      Viewpoint Manager Service

    4. Go to start > Control Panel > Add and Remove Programs.
      Remove anything related to the following:

      Viewpoint Manager/Player/etc
      Freecorder Toolbar


    5. After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

      R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
      O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
      O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
      O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

      Close HJT.
    6. Check this folder C:\sj675, was it created by you? What are its contents? Let me know in your next reply.
    7. Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

    8. Save this as CFScript on the desktop.
    9. Referring to the image below, drag CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe.
      [​IMG]
    10. ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.

      Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang

    11. Reboot into normal mode and rehide your protected OS files.
    Thereafter, please post a fresh HJT log from normal mode as an attachment into this thread.


    Regards,
    momok =)

    This thread is for the use of wallywimple only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  3. wallywimple

    wallywimple TS Rookie Topic Starter

    All Done

    C:\sj675 is an installation folder created by HP Scanket 6300 installation program. It is fine.

    John
     
  4. momok

    momok TS Rookie Posts: 2,265

    Hi,

    Your logs look clean now.

    1. Delete all files in AVG Antispyware Quarantine folder. (located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine)

    2. Turn off system restore (XP/ME only). Learn how to do that HERE.
      This will remove all the remaining nasties from your old restore points.

    3. After that turn system restore back on.
      This would have created a new safe and clean restore point for your system.

    4. Often times, an infection can occur again not due to the incompetence of programs, but because of user habits.
      May I recommend you to read this article.
      This can help to prevent future infections.

    Should you have any further problems, please post in this thread.


    Regards,
    Your friendly momok =)

    This thread is for the use of wallywimple only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
     
  5. jobeard

    jobeard TS Ambassador Posts: 9,333   +622

    fyi: re: your question: >Check this folder C:\sj675, was it created by you?<

    this folder is created by an HP Print driver install :)
     
  6. wallywimple

    wallywimple TS Rookie Topic Starter

    Dear Friendly Momok,

    Thank you

    John
     
Topic Status:
Not open for further replies.

Similar Topics

Add New Comment

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...