Logs attached - just need confirmation

Status
Not open for further replies.

wallywimple

Posts: 12   +0
A computer on my home network was infected, these are from another computer.
PANDA reported no rootkits found.
 
Hi,

You may wish to copy and paste these instructions on notepad for easier reference later.

  1. Boot into safe mode under your normal user name. See how HERE
  2. Next turn on "Show all files and folders, including hidden and system". See how HERE

  3. Go to start > run and type services.msc. Press the enter key.
    Search for the following services. Double click to select stop if they are running. Set the startup type to disabled. Click apply/ok for each service you disable.

    Viewpoint Manager Service

  4. Go to start > Control Panel > Add and Remove Programs.
    Remove anything related to the following:

    Viewpoint Manager/Player/etc
    Freecorder Toolbar


  5. After that, run HijackThis and fix the following entries, if found (do this by placing a tick in the check boxes beside these entries and clicking "Fix checked"):

    R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
    O2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
    O3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre0.dll
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    Close HJT.
  6. Check this folder C:\sj675, was it created by you? What are its contents? Let me know in your next reply.
  7. Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

    File::
    C:\WINDOWS\Alcmtr.exe
    Folder::
    C:\Program Files\Freecorder
    C:\Documents and Settings\Bradley\Application Data\Viewpoint
    C:\Documents and Settings\Nicholas\Application Data\Viewpoint
    C:\Program Files\Viewpoint
    C:\Documents and Settings\All Users\Application Data\Viewpoint

    Registry::
  8. Save this as CFScript on the desktop.
  9. Referring to the image below, drag CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe.
    CFScript.gif

  10. ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.

    Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang

  11. Reboot into normal mode and rehide your protected OS files.
Thereafter, please post a fresh HJT log from normal mode as an attachment into this thread.


Regards,
momok =)

This thread is for the use of wallywimple only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Hi,

Your logs look clean now.

  1. Delete all files in AVG Antispyware Quarantine folder. (located in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Quarantine)

  2. Turn off system restore (XP/ME only). Learn how to do that HERE.
    This will remove all the remaining nasties from your old restore points.

  3. After that turn system restore back on.
    This would have created a new safe and clean restore point for your system.

  4. Often times, an infection can occur again not due to the incompetence of programs, but because of user habits.
    May I recommend you to read this article.
    This can help to prevent future infections.

Should you have any further problems, please post in this thread.


Regards,
Your friendly momok =)

This thread is for the use of wallywimple only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
fyi: re: your question: >Check this folder C:\sj675, was it created by you?<

this folder is created by an HP Print driver install :)
 
Status
Not open for further replies.
Back