TechSpot

Yet another Patched.64 (and other) issues

Solved
By F1forever
Nov 26, 2012
Topic Status:
Not open for further replies.
  1. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Wow, sorry that happened!

    ESET Online Scan

    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install, or it will ask to download an installer. Please do so an install it.
    • Click Start or wait for the scanner to load.
    • Make sure that the options Remove found threats and the option Scan unwanted applications are checked.
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, there are a couple of things to keep in mind:
    • 1. If NO threats were found, allow the scanner to Uninstall on close and then close the Window.
    • 2. If threats WERE detected, click on List of Threats Found, Export to Text File...save it as ESET-Scan-Log.txt. Click the back button/link, put a checkmark to Uninstall Application on Close and then close the window.
    • Open the logfile from wherever you saved it
    • Copy and paste the contents in your next reply.


    It all appears to be good, so we will finish up to make sure your computer is protected from malware in the future.

    Clean up System Restore

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name I.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive I.e. C
    • For a few moments the system will make some calculations:
      [​IMG]
    • Select the More Options tab
      [​IMG]
    • In the System Restore and Shadow Backups select Clean up
      [​IMG]
    • Select Delete on the pop up
    • Select OK
    • Select Delete
    Run OTC to remove our tools

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    Purge old temporary files

    NOTE: If you already have this installed, you don't have to reinstall it.

    Please download CCleaner Slim and save it to your Desktop - Alternate download link

    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.

    • Double-click the CCleaner shortcut on the desktop to start the program.
    • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
    • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
    • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).

    Caution: Only use the Registry feature if you are very familiar with the registry.
    Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

    Security Check

    Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
    • Save it to your Desktop.
    • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
  2. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    For some reason that computer has lost its ability to find the network or any internet access so I will have to figure that out first. Was working fine last night.
  3. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    My wife told me when she shut down an automatic update. I think this might be the issue. If I remember Combo Fix created a restore point before running. Can I use this?
  4. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    It appears that a new version of Visual c++ (2010 x86 redistributable -10.0)was installed. Could this be my issue or do you think was it an effect of the virus removal?
  5. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    I don't think anything like that has to do with it...let's try the following:

    Press start, then type in cmd - then hit Enter.

    In the command prompt window, press in the following code exactly:


    netsh winsock reset catalog

    Then, exit out.
    ==

    Do you have Internet after performing the above process?
  6. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    No Joy. When I troubleshoot the connection I get the message "Windows could not automatically detect this network's Proxy settings". Made sure all Proxy settings are off. Have tried every type of reset that I have read about. Manually configured TCP/IP using the settings from my working computer and it at least recognized a network but still no internet. A bit stumped!
  7. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Lets check some settings on your system:
    1. Enter your Control Panel and double-click on Network Connections
    2. Then right click on your Default Connection
      • Usually Local Area Connection for Cable and DSL, or AOL Connection.
    3. Left click on Properties
    4. Double-Click on the Internet
      Protocol (TCP/IP
      ) item
    5. Select the radio dial that says Obtain DNS Servers Automatically
    6. Press OK twice to get out of the properties screen
    7. Restart the computer
    Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

    ipconfig /flushdns (The space between g and / is needed)
    regsvr32 netshell.dll
    regsvr32 netcfgx.dll
    regsvr32 netman.dll

    Exit

    Restart the computer.
  8. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    All commands completed successfully. Still no network access. If it matters this is Windows 7.
  9. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

  10. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    Still NG. What about sfc /scannow or restore? Need to get internet SOON!
  11. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Go for it! :)
     
  12. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    Success! The restore point Combo Fix created worked, so I'm back to the point just before it ran. Will try the final steps (ESET and onward) tomorrow or Tues. and let you know the results. Thanks.
  13. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Okay. Will wait for that. :)
  14. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Still here. :)
  15. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    Read my mind!!! I was just about to let you know ESET scan has been running for about 25hrs. and has been working @ 99% of step 3 for about 12 of them. Still seems to be HD activity.
  16. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Sorry to hear it's been causing problems...see if you can run this scan...

    Please run Panda ActiveScan online scan.
    • Choose Quick Scan then click the big green Scan now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • Once the scan is completed, please hit the notepad icon next to the text Export to:
    • Save it to a convenient location such as your Desktop
    • Post the contents of the ActiveScan.txt in your next reply
  17. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    Thanks, that took a LOT less time (ESET was still running after 50 hrs.!) and here's the result:
    ANALYSIS: 2012-12-13 10:58:15
    PROTECTIONS: 1
    MALWARE: 22
    SUSPECTS: 0
    ;***********************************************************************************************************************************************************************************
    PROTECTIONS
    Description Version Active Updated
    ;===================================================================================================================================================================================
    AVG Anti-Virus Free Edition 2013 Yes Yes
    ;===================================================================================================================================================================================
    MALWARE
    Id Description Type Active Severity Disinfectable Disinfected Location
    ;===================================================================================================================================================================================
    00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\sd81j5u0.txt
    00145405 Cookie/RealMedia TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\35bjcsnl.txt
    00145457 Cookie/FastClick TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\i4fkrfas.txt
    00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\22zs5c8x.txt
    00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\cvumd400.txt
    00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\lno6ysca.txt
    00147824 Cookie/Clickbank TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\q6iz8r5y.txt
    00167642 Cookie/Com.com TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ql66vuac.txt
    00167747 Cookie/Azjmp TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ar9smars.txt
    00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\7mi8i24t.txt
    00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\w3i7yl2c.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ad27t819.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\63n068oq.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\5fbxj6vv.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\m33qz8cp.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\hbf7ad03.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\q5rbz7ws.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\yt0hd0fl.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\92nlazyj.txt
    00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\3o5tm69f.txt
    00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\eq7gw1o4.txt
    00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\b7o06v75.txt
    00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\vqiulrux.txt
    00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\xb2rr3ea.txt
    00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\mqs9wvxu.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\e5q454gs.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\7q42iyrs.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\72a984vf.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\h5l35d2o.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\va0sbcy3.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\j2aoh5wb.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\qze5skjp.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\u0o4x0op.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\no9psbn9.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\1scdpaeb.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\13qqzbdm.txt
    00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\zskz2gax.txt
    00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\jeu33u5f.txt
    00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\hj58yplw.txt
    00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\2n175oua.txt
    00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\voifu1yn.txt
    00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\xfnrdz7o.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\mi0ztskb.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\569h3d3c.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\y1r9x1ou.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\adk9ucqw.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\vyklb6yx.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ex8b1lnu.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\pwhd6z6j.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\i7t8yqcx.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ck37c9mc.txt
    00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\k1zrva2u.txt
    00170556 Cookie/RealMedia TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\g9rrim1e.txt
    00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\jep6gw7v.txt
    00172221 Cookie/Zedo TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\cddov55x.txt
    00194327 Cookie/Go TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\h19f2pzk.txt
    00194327 Cookie/Go TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\um2kje5z.txt
    00194327 Cookie/Go TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\mxx5nt02.txt
    00262020 Cookie/Atwola TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\tqwgbwyx.txt
    00262020 Cookie/Atwola TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ydem1hvt.txt
    00325830 Cookie/Bridgetrack TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\hxcz124r.txt
    ;===================================================================================================================================================================================
    SUSPECTS
    Sent Location
    ;===================================================================================================================================================================================
    ;===================================================================================================================================================================================
    VULNERABILITIES
    Id Severity Description
  18. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

  19. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    Without ESET scan I hope.
  20. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Yes. We just need the cleanup part of it after the ESET scan. :)
  21. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    WHEW!!! OK, I'll get to it tonight or tomorrow. Thanks again.
  22. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Okie dokie. :)
  23. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Did you get it?
  24. F1forever

    F1forever TS Rookie Topic Starter Posts: 31

    Sorry, got dragged away and Disk Cleanup took quite a bit longer than I expected but finally though all the steps. Here's the report from Security Check:

    Results of screen317's Security Check version 0.99.56
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 9
    ``````````````Antivirus/Firewall Check:``````````````
    AVG Anti-Virus Free Edition 2013
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    Malwarebytes Anti-Malware version 1.65.1.1000
    Java(TM) 6 Update 30
    Java version out of Date!
    Adobe Reader 10.1.3 Adobe Reader out of Date!
    ````````Process Check: objlist.exe by Laurent````````
    Malwarebytes Anti-Malware mbamservice.exe
    Malwarebytes Anti-Malware mbamgui.exe
    AVG avgwdsvc.exe
    Malwarebytes' Anti-Malware mbamscheduler.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 4%
    ````````````````````End of Log``````````````````````
  25. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Java Update!

    Please download the newest version of Java from Java.com.

    Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

    Once old versions are gone, please install the newest version.

    Read more about Java exploit problems


    Adobe Reader Update!

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.



    Personal Tips on Preventing Malware

    See this page for more info about malware and prevention.

    Read more about "FAQ: How did Sirefef or ZeroAccess Infect You?"

    Any other questions before I mark this topic solved?
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.