|
#21
|
|||
|
|||
|
Here are the new HJT and ComboFix logs.
It looks like the 08 entries were deleted successfully but the 023 Netcom3 entry still appears. However, my google searches are now directing me to the coorrect websites. Last edited by jjdb5; 03-05-2008 at 08:44 AM.. |
|
#22
|
|||
|
|||
|
Is it possible that the NetCom3 entry could cause problems if it can't be removed?
Last edited by jjdb5; 03-05-2008 at 03:42 PM.. |
|
|
|
#23
|
||||
|
||||
|
Ok, first lets install the recovery console, then we will continue to remove
Go to Microsoft's website here --> http://support.microsoft.com/kb/310994 Select the download that's appropriate for your Operating System Windows XP SP2 Download the file and save it as it's original name to your desktop Close all open windows and programs, then drag the setup package onto ComboFix.exe and drop it. Follow the prompts to start ComboFix and when prompted, agree to the End-User License Agreement to install the Microsoft Recovery Console. When complete, a log named CF_RC.txt will open. Please attach that log here. ![]() Last edited by Blind Dragon; 03-05-2008 at 04:00 PM.. |
|
#24
|
|||
|
|||
|
Here is the CF-RC log.
|
|
#25
|
||||
|
||||
|
Start -> all programs -> Accessories -> command prompt
type services.msc at the command prompt and press enter Stop the netcom3 or PSCMonitor.exe service from running by right-click it and choose Properties. In the Properties dialog box that appears, choose Manual from the Startup Type drop-down list and choose Disabled. Reboot into safe mode Launch Hijackthis -> System Scan only -> check the following O17 - HKLM\System\CCS\Services\Tcpip\..\{0D7C60DB-20E2-407C-B5E0-CB37E9A99148}: NameServer = 85.255.116.109 85.255.112.21 O17 - HKLM\System\CS1\Services\Tcpip\..\{0D7C60DB-20E2-407C-B5E0-CB37E9A99148}: NameServer = 85.255.116.109 85.255.112.21 O23 - Service: NetCom3 Service (Netcom3) - Unknown owner - C:\Program Files\Netcom3 Cleaner\PSCMonitor.exe (file missing) Select Fix checked -------------------------------------------------------------------------------------------------------- Reboot into normal mode -------------------------------------------------------------------------------------------------------- Run a fresh scan with Hijackthis and attach the log here Last edited by Blind Dragon; 03-05-2008 at 11:28 PM.. |
|
#26
|
|||
|
|||
|
After I followed the directions at the command prompt and ran HJT in safe mode those three entries were already not listed.
However, when I rebooted in normal mode, the 017 entries appeared but the 023 remained missing. I checked off and fixed the two 017 entries and here is the latest and greatest HJT log. |
|
#27
|
||||
|
||||
|
The log looks fine to me now as long as those 017 entries don't come back. I am going to ask for a 2nd opinion just to be sure, while we wait a new Java update just came out yesterday and you can update this one through the console. Also I may see one more thing in there, what brand of computer are you running HP or DELL?
Update your Java Runtime Environment
If for some reason you couldn't update through the above instructions.
Last edited by Blind Dragon; 03-06-2008 at 09:34 AM.. |
|
#28
|
|||
|
|||
|
I installed the new version of Java - thanks.
Also I have a Dell system and an HP printer. I ran another HJT and those 017 entries do keep reappearing. It lets me delete them but they come right back. The log is attached |
|
#29
|
||||
|
||||
|
Now that we have system restore off lets try this again
FixWareOut run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal. At the end of the fix, you may need to restart your computer again. : Remove bad HijackThis entries * HijackThis should launch automatically * Click on the Scan button * Put a check beside all of the items listed below (if present): O17 - HKLM\System\CCS\Services\Tcpip\..\{0D7C60DB-20E2-407C-B5E0-CB37E9A99148}: NameServer = 85.255.116.109 85.255.112.21 O17 - HKLM\System\CS1\Services\Tcpip\..\{0D7C60DB-20E2-407C-B5E0-CB37E9A99148}: NameServer = 85.255.116.109 85.255.112.21 * Close all open windows and browsers/email, etc... * Click on the "Fix Checked" button * When completed, close the application. ----------------------------------------------------------------------------------------------------- Go to start -> all programs -> accessories -> command prompt At the command prompt type => ipconfig /flushdns Close the command prompt -------------------------------------------------------------------------------------------------------- Run Ccleaner again
Restart your computer run a fresh scan with Hijackthis and lets see if they are still there, if they are I must be missing something and will ask for a fresh look at the logs from somebody else. |
|
|
|
#30
|
|||
|
|||
|
I received an error message at the command prompt when I tried to enter that command:
"Could not flush the DNS Resolver Cache: Function failed during execution." I did run FixWareout again and CCleaner and it looked like the two entries were gone after the reboot. However, right before I went to reply I checked just to make sure and the entries were back. It must have been 3-4 minutes after the reboot. Here are the logs. |
|
#31
|
||||
|
||||
|
I have requested help on this one
|
|
#33
|
|||
|
|||
|
Thanks Blind Dragon!
Momok - I've never seen ukrtelegroup before. |
|
#34
|
||||
|
||||
|
Hi,
Quote:
from ukrtelegroup: Quote:
Last edited by momok; 03-16-2008 at 03:26 AM.. |
|
#35
|
|||
|
|||
|
This occured when I followed these instructions:
Go to start -> all programs -> accessories -> command prompt At the command prompt type => ipconfig /flushdns Close the command prompt My version of Combofix had expired and I wasn't sure how to get the new one. As far as ukrtelegroup goes, I am the only person using this computer and I've never used it or any other domain hosting service for that matter. My latest HJT is attached. |
|
#36
|
||||
|
||||
|
Hi,
Please download Deckard's System Scanner from HERE. You may wish to copy and paste these instructions on notepad for easier reference later.
Regards, momok =) This thread is for the use of jjdb5 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum. |
|
#37
|
|||
|
|||
|
Thanks Momok.
Here is the DSS log |
|
#38
|
||||
|
||||
|
Hi,
You may wish to copy and paste these instructions on notepad for easier reference later.
Regards, momok =) This thread is for the use of jjdb5 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum. Last edited by momok; 03-18-2008 at 06:56 AM.. |
|
#39
|
|||
|
|||
|
I followed these instructions but Spykiller was not listed in my Programs and the files in bold were not anywhere to be found either.
I've posted a new HJT and it looks like those 017 entries have re-appeared |
|
#40
|
||||
|
||||
|
Hi,
Sorry I need a fresh DSS log too. I'm not sure how and why the O17 entries are coming back. Perhaps I'll have to direct you to some other sites where several experts specialise in dealing with these issues. |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Infected -- Followed 15 steps. Results Attached | Virus & Malware removal | 12 | 10-28-2007 09:42 PM | |
| HJT log after following Howards 15 Steps | Virus & Malware removal | 3 | 10-25-2007 02:33 PM | |
| Following the virus/malware removal steps would like to know something? | Virus & Malware removal | 23 | 05-17-2007 04:41 PM | |
| TCPIPMON.exe final steps of removal | Virus & Malware removal | 7 | 04-26-2007 09:35 PM | |
| log files after removal steps followed | Virus & Malware removal | 4 | 12-17-2006 08:39 AM | |
All times are GMT -4. The time now is 07:36 AM.



