also @ TechSpot: Blizzard talks Diablo 3 facts, nerfing and buffs for legendary items

TechSpot

No help yet to my post #597631

Discussion in 'Virus and Malware Removal' started by NeedHelpNow, Apr 4, 2008.

Thread Status:
Not open for further replies.
  1. NeedHelpNow Newcomer, in training

    I reposted my hijack this as a .txt on 3/30. I'm hoping someone can help me.

    Thanks so much
  2. kritius Newcomer, in training

    repost a fresh one here
  3. NeedHelpNow Newcomer, in training

    Here is a fresh hijack this log.

    Summary of problems:

    I want to thank you in advance for anything you can do to help me. I have been trying since Monday to fix this on my own by reading other's threads, but I have not been successful.


    I began on Monday by clicking something which immediately set off my virus alerts. I had multiple trojans, including smitfraud, trojan-ace-x, trojan-downloader-zlob, trojan-downloader.vb.axa, trojan.unclassified/gts. I seem to have been able to remove these, but have the pop ups for PC-Antispyware , Downloader, and "Protection Control". I have run McAfee, SpySweeper, PCTools SpyDoctor, Spybot S&D, SuperAntispyware, CCleaner, Malwarebytes, TrendMicro Online.

    One thread re: PC-Antispyware said to run LSPFix, reboot in safemode, run superantispyware, reboot, then run malwarebytes, reboot. I've done this, it comes up clean, then I get the PC-Antispyware , Downloader, and "Security System Protection Control Panel" pop-ups. I just ran a hijack this log. See below.

    I am also getting a pop up that says "System Integrity Scan Wizard"

    I am also getting a notice to install new hardware when I log on. For program, it says "unknown". I haven't installed anything new.
  4. kritius Newcomer, in training

    Download and Run ComboFix
    • Download this file from either of the two below listed places :

      HERE or HERE
    • Then double click combofix.exe & follow the prompts.
    • When finished, it shall produce a log for you. Attach that log in your next reply
    WARNING: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
  5. NeedHelpNow Newcomer, in training

    I ran combo fix

    I ran, it rebooted, it said it was preparing a log, when I came back to check on it again, the combo fix window was gone, and there was no log there. I have searched and can't locate it. Any suggestions???
  6. kritius Newcomer, in training

    its usually C:\ComboFix.txt I hae to head out now, ill look over the log when I get back. If you cant find it,

    • Click START then RUN
    • Now type Combofix /u in the runbox and click OK
    • [IMG]
    • When shown the disclaimer, Select "2"

    Then redownload combofix to your desktop and run it again.
  7. NeedHelpNow Newcomer, in training

    combo fix .txt

    Here is the combofix file.
  8. kritius Newcomer, in training

    Sorry ComoFix needs to saved to the desktop in order for it to work properly, can you please put it there for me? Also remember to deactivate your antivirus and temporarily disconnect from the internet when running it.
  9. NeedHelpNow Newcomer, in training

    New ComboFix Log

    Thank you for your patience. I hope this one works.
  10. kritius Newcomer, in training

    COMBOFIX-Script

    • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

    • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

      [IMG]
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
    • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
    • When finished, it shall produce a log for you. Attach the log in your next reply along with a fresh HijackThis log.
    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.
  11. NeedHelpNow Newcomer, in training

    Logs attached

    Here is the combofix log and I did 2 hijack now logs, one right after combo fix, then i rebooted and did another. ...thank you so much for helping me!!!!
  12. kritius Newcomer, in training

    COMBOFIX-Script

    • Please open Notepad (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the code box below:

      Code:
      File::
      C:\Documents and Settings\All Users\Application Data\atwtixml\kzqvupal.exe
      
      Folder::
      C:\Documents and Settings\All Users\Application Data\atwtixml
      
      Registry::
      [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run]
      "2k0u0xUioM"=-
      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\run]
      "2k0u0xUioM"=-
      
          
    • Save this as CFScript.txt and change the "Save as type" to "All Files" and place it on your desktop.

      [IMG]
    • Very Important! Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before following the steps below. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
    • ComboFix will now run a scan on your system. It may reboot your system when it finishes. This is normal.
    • When finished, it shall produce a log for you. Copy and paste the contents of the log in your next reply.
    CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

    Run HijackThis

    Fix entries using HiJackThis
    • Launch HiJackThis
    • Click the Do a system scan only button
    • Put a check next to the entries listed below (if they are still there)
    O4 - HKLM\..\Policies\Explorer\Run: [2k0u0xUioM] C:\Documents and Settings\All Users\Application Data\atwtixml\kzqvupal.exe
    O4 - HKCU\..\Policies\Explorer\Run: [2k0u0xUioM] C:\Documents and Settings\All Users\Application Data\atwtixml\kzqvupal.exe
    O24 - Desktop Component 0: (no name) - https://www.victoriassecret.com/images/common/navbar/logo.gif?

    • IMPORTANT: Do NOT click fix until you exit all browser sessions including the one you are reading in right now
    • Click the Fix checked button and close HiJackThis
    • Reboot HijackThis if necessary

    Delete Files and Folders
    • Right Click on the start button and chose explore
    • Show all hidden files and folders, see how HERE
    • Navigate to the following files and folders and delete them(if still present)
    C:\Documents and Settings\All Users\Application Data\atwtixml<---------This Folder
    • Empty the recycle bin.
    If that does not work then repeat the process in safe mode. See how to boot into Safe mode HERE.
    ***DO NOT USE MSCONFIG TO BOOT INTO SAFE MODE***
  13. NeedHelpNow Newcomer, in training

    Attached are new logs

    I ran combofix & saved log per instructions.

    Ran hijack this, the first two files were not there (the 2 "04" files listed above), the 024 was there, and I checked and fixed.

    I followed the stops to show hidden files, and looked for "C:\Documents and Settings\All Users\Application Data\atwtixml" in reg mode & safe mode, but it wasn't there.

    I ran new hijack this log for you after I rebooted from safe mode.

    The virus pop ups seem to be gone (I haven't been using this computer other than trying to fix though). When I initially log on, I am still getting the "new hardware installed" pop up, source unknown.
  14. kritius Newcomer, in training

    Just the one entry to fix,

    Fix entries using HiJackThis
    • Launch HiJackThis
    • Click the Do a system scan only button
    • Put a check next to the entries listed below
    O21 - SSODL: ComponentDrive - {a3cbedc9-b08b-44f1-9314-d1da6ba47ddc} - (no file)

    • IMPORTANT: Do NOT click fix until you exit all browser sessions including the one you are reading in right now
    • Click the Fix checked button and close HiJackThis
    • Reboot HijackThis if necessary

    I would like you to do an online scan so that we can what else may be in your system,
    Run Kaspersky online scanner
    With the exception of Internet Explorer, which must be used for this scan, keep ALL programs closed
    Note: It is recommended to disable onboard antivirus program and antispyware programs while performing scans to speed up scan time and to make sure there are no conflicts.
    Do not go surfing while your resident protection is disabled!
    Once the scan is finished remember to re-enable resident antivirus protection along with whatever antispyware application you use.


    Do an online scan with Kaspersky Online Scanner in Internet Explorer. You will be prompted to install and run an ActiveX component from Kaspersky, Click Yes.
    Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75%. Once the licence accepted, reset to 100%.
    • The program will launch and then start to download the latest definition files.
    • Once the scanner is installed and the definitions downloaded, click Next.
    • Now click on Scan Settings
    • In the scan settings make sure that the following are selected:
      o Scan using the following Anti-Virus database:
      o Extended (If available, otherwise use standard)
      o Scan Options:
      o Scan Archives
      o Scan Mail Bases
    • Click OK
    • Under select a target to scan, select My Computer
    • The scan will take a while so be patient and let it run.
    • Please do not use your computer while the scan is running. Once the scan is complete it will display if your system has been infected.
    • Click the Save Report As... button (see red arrow below)

      [IMG]
    • In the Save as... prompt, select Desktop
    • In the File name box, name the file
    • In the Save as type prompt, select Text file (see below)

      [IMG]
    • Include the report in your next post.

    We'll see what Kaspersky has to say, dont get worried or delete anything it finds though.
  15. NeedHelpNow Newcomer, in training

    Kapersky & New Hijack this log attached

    I haven't closed kapersky, but didn't fix anything yet.
  16. NeedHelpNow Newcomer, in training

    I just noticed mcafee was turned back on

    partway into the scan. I had disabled it but not long enough. Let me know if you need me to re-run Kaspersky w/out McAfee.
  17. kritius Newcomer, in training

    Ok just a few things to do,

    Fix entries using HiJackThis
    • Launch HiJackThis
    • Click the Do a system scan only button
    • Put a check next to the entries listed below
    O8 - Extra context menu item: &Webshots Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM

    • IMPORTANT: Do NOT click fix until you exit all browser sessions including the one you are reading in right now
    • Click the Fix checked button and close HiJackThis
    • Reboot HijackThis if necessary

    Delete Files and Folders
    • Right Click on the start button and chose explore
    • Show all hidden files and folders, see how HERE
    • Navigate to the following files and folders and delete them(if still present)
    C:\Documents and Settings\Melia Renee\Application Data\HouseCall 6.6\Backup\kzqvupal.exe<---------This File
    C:\Documents and Settings\Melia Renee\Desktop\Melia's Music\Top of Charts - 2004 (strap).wma<---------This File
    C:\QooBox\Quarantine<---------The contents of this Folder NOT THE FOLDER

    • Empty the recycle bin.


    If that does not work then repeat the process in safe mode. See how to boot into Safe mode HERE.
    ***DO NOT USE MSCONFIG TO BOOT INTO SAFE MODE***

    Now Go to Start-Settings-Control Panel, click on Add remove Programs. If any of the following programs are listed there, click on the program to highlight it, and click on remove. Then close the Control Panel.

    • Button Manager v1.836
  18. NeedHelpNow Newcomer, in training

    Ok

    I was able to find and complete everything you posted. I rebooted. I saved the Hijack this log from step one, before reboot. Upon reboot, the found new hardware still popped up.
  19. kritius Newcomer, in training

    What exactly does the message say? Because the logs are clean.
  20. NeedHelpNow Newcomer, in training

    When I boot up

    a "Found New Hardware Wizard" pops up. it says:

    Welcome to the found new hardware Wizard

    This wizard helps you install software for:

    unknown

    If your hardware came with an installation cd or floppy disk, insert it now.

    What do you want the wizard to do:

    - install the software automatically (recommended)
    - install from a list or specific location (advanced)

    Click next to continue

    Then it has a next and cancel button.


    I don't know what this is for, and it only started once I had the viruses.

    I can't thank you enough for all of your help!!!!!!
Thread Status:
Not open for further replies.