Solved Yet another Patched.64 (and other) issues

Status
Not open for further replies.
Wow, sorry that happened!

ESET Online Scan

Please run a free online scan with the ESET Online Scanner
  • Tick the box next to YES, I accept the Terms of Use
  • Click Start
  • When asked, allow the ActiveX control to install, or it will ask to download an installer. Please do so an install it.
  • Click Start or wait for the scanner to load.
  • Make sure that the options Remove found threats and the option Scan unwanted applications are checked.
  • Click Scan (This scan can take several hours, so please be patient)
  • Once the scan is completed, there are a couple of things to keep in mind:
  • 1. If NO threats were found, allow the scanner to Uninstall on close and then close the Window.
  • 2. If threats WERE detected, click on List of Threats Found, Export to Text File...save it as ESET-Scan-Log.txt. Click the back button/link, put a checkmark to Uninstall Application on Close and then close the window.
  • Open the logfile from wherever you saved it
  • Copy and paste the contents in your next reply.


It all appears to be good, so we will finish up to make sure your computer is protected from malware in the future.

Clean up System Restore

Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

To manually create a new Restore Point
  • Go to Control Panel and select System and Maintenance
  • Select System
  • On the left select Advance System Settings and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name I.e. Clean
  • Select Create
Now we can purge the infected ones
  • Go back to the System and Maintenance page
  • Select Performance Information and Tools
  • On the left select Open Disk Cleanup
  • Select Files from all users and accept the warning if you get one
  • In the drop down box select your main drive I.e. C
  • For a few moments the system will make some calculations:
    diskcleanup1.png
  • Select the More Options tab
    moreoptions.png
  • In the System Restore and Shadow Backups select Clean up
    moreoptions2.png
  • Select Delete on the pop up
  • Select OK
  • Select Delete
Run OTC to remove our tools

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.
Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

Purge old temporary files

NOTE: If you already have this installed, you don't have to reinstall it.

Please download CCleaner Slim and save it to your Desktop - Alternate download link

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

  • Double-click the CCleaner shortcut on the desktop to start the program.
  • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
  • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
  • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).

Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

Security Check

Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
 
For some reason that computer has lost its ability to find the network or any internet access so I will have to figure that out first. Was working fine last night.
 
My wife told me when she shut down an automatic update. I think this might be the issue. If I remember Combo Fix created a restore point before running. Can I use this?
 
It appears that a new version of Visual c++ (2010 x86 redistributable -10.0)was installed. Could this be my issue or do you think was it an effect of the virus removal?
 
I don't think anything like that has to do with it...let's try the following:

Press start, then type in cmd - then hit Enter.

In the command prompt window, press in the following code exactly:


netsh winsock reset catalog

Then, exit out.
==

Do you have Internet after performing the above process?
 
No Joy. When I troubleshoot the connection I get the message "Windows could not automatically detect this network's Proxy settings". Made sure all Proxy settings are off. Have tried every type of reset that I have read about. Manually configured TCP/IP using the settings from my working computer and it at least recognized a network but still no internet. A bit stumped!
 
Lets check some settings on your system:
  1. Enter your Control Panel and double-click on Network Connections
  2. Then right click on your Default Connection
    • Usually Local Area Connection for Cable and DSL, or AOL Connection.
  3. Left click on Properties
  4. Double-Click on the Internet
    Protocol (TCP/IP
    ) item
  5. Select the radio dial that says Obtain DNS Servers Automatically
  6. Press OK twice to get out of the properties screen
  7. Restart the computer
Go to Start->Run->Type CMD and click Ok. The MSDOS Window will be displayed. At the command prompt, type the following and press Enter after each line:

ipconfig /flushdns (The space between g and / is needed)
regsvr32 netshell.dll
regsvr32 netcfgx.dll
regsvr32 netman.dll

Exit

Restart the computer.
 
Success! The restore point Combo Fix created worked, so I'm back to the point just before it ran. Will try the final steps (ESET and onward) tomorrow or Tues. and let you know the results. Thanks.
 
Read my mind!!! I was just about to let you know ESET scan has been running for about 25hrs. and has been working @ 99% of step 3 for about 12 of them. Still seems to be HD activity.
 
Sorry to hear it's been causing problems...see if you can run this scan...

Please run Panda ActiveScan online scan.
  • Choose Quick Scan then click the big green Scan now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • Once the scan is completed, please hit the notepad icon next to the text Export to:
  • Save it to a convenient location such as your Desktop
  • Post the contents of the ActiveScan.txt in your next reply
 
Thanks, that took a LOT less time (ESET was still running after 50 hrs.!) and here's the result:
ANALYSIS: 2012-12-13 10:58:15
PROTECTIONS: 1
MALWARE: 22
SUSPECTS: 0
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
AVG Anti-Virus Free Edition 2013 Yes Yes
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\sd81j5u0.txt
00145405 Cookie/RealMedia TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\35bjcsnl.txt
00145457 Cookie/FastClick TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\i4fkrfas.txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\22zs5c8x.txt
00145731 Cookie/Tribalfusion TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\cvumd400.txt
00145738 Cookie/Mediaplex TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\lno6ysca.txt
00147824 Cookie/Clickbank TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\q6iz8r5y.txt
00167642 Cookie/Com.com TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ql66vuac.txt
00167747 Cookie/Azjmp TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ar9smars.txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\7mi8i24t.txt
00168056 Cookie/YieldManager TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\w3i7yl2c.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ad27t819.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\63n068oq.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\5fbxj6vv.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\m33qz8cp.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\hbf7ad03.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\q5rbz7ws.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\yt0hd0fl.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\92nlazyj.txt
00168061 Cookie/Apmebf TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\3o5tm69f.txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\eq7gw1o4.txt
00168090 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\b7o06v75.txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\vqiulrux.txt
00168093 Cookie/Serving-sys TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\xb2rr3ea.txt
00168097 Cookie/BurstBeacon TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\mqs9wvxu.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\e5q454gs.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\7q42iyrs.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\72a984vf.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\h5l35d2o.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\va0sbcy3.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\j2aoh5wb.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\qze5skjp.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\u0o4x0op.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\no9psbn9.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\1scdpaeb.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\13qqzbdm.txt
00169190 Cookie/Advertising TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\zskz2gax.txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\jeu33u5f.txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\hj58yplw.txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\2n175oua.txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\voifu1yn.txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\xfnrdz7o.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\mi0ztskb.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\569h3d3c.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\low\y1r9x1ou.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\adk9ucqw.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\vyklb6yx.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ex8b1lnu.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\pwhd6z6j.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\i7t8yqcx.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ck37c9mc.txt
00170495 Cookie/PointRoll TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\k1zrva2u.txt
00170556 Cookie/RealMedia TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\g9rrim1e.txt
00171982 Cookie/QuestionMarket TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\jep6gw7v.txt
00172221 Cookie/Zedo TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\cddov55x.txt
00194327 Cookie/Go TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\h19f2pzk.txt
00194327 Cookie/Go TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\um2kje5z.txt
00194327 Cookie/Go TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\mxx5nt02.txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\tqwgbwyx.txt
00262020 Cookie/Atwola TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\ydem1hvt.txt
00325830 Cookie/Bridgetrack TrackingCookie No 0 Yes No c:\users\pam\appdata\roaming\microsoft\windows\cookies\hxcz124r.txt
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
 
Sorry, got dragged away and Disk Cleanup took quite a bit longer than I expected but finally though all the steps. Here's the report from Security Check:

Results of screen317's Security Check version 0.99.56
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 9
``````````````Antivirus/Firewall Check:``````````````
AVG Anti-Virus Free Edition 2013
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.65.1.1000
Java(TM) 6 Update 30
Java version out of Date!
Adobe Reader 10.1.3 Adobe Reader out of Date!
````````Process Check: objlist.exe by Laurent````````
Malwarebytes Anti-Malware mbamservice.exe
Malwarebytes Anti-Malware mbamgui.exe
AVG avgwdsvc.exe
Malwarebytes' Anti-Malware mbamscheduler.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 4%
````````````````````End of Log``````````````````````
 
Java Update!

Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

Read more about Java exploit problems


Adobe Reader Update!

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.



Personal Tips on Preventing Malware

See this page for more info about malware and prevention.

Read more about "FAQ: How did Sirefef or ZeroAccess Infect You?"

Any other questions before I mark this topic solved?
 
Status
Not open for further replies.
Back