Inactive Malware interfering with connection

Status
Not open for further replies.
Uninstall Combofix and one of AV programs and then run OTL again.
It'll produce only one log, OTL.txt.

How is computer doing at the moment?
 
You're welcome :)

It should be attachable...
Let's see...
 

Attachments

  • OTL.Txt
    193 KB · Views: 1
Update your Java version here: http://www.java.com/en/download/installed.jsp

Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

Now, we need to remove old Java version and its remnants...

Download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.

=======================================================================

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    Code:
    :OTL
    [2010/08/01 02:08:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Deigo\Application Data\BitDefender(2)
    [2010/08/01 01:40:54 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender(2)
    [2010/08/01 22:57:07 | 000,000,000 | ---D | C] -- C:\Program Files\BitDefender
    [2010/08/02 02:45:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\BitDefender
    [2010/08/02 02:27:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\BitDefender
    FF - HKLM\software\mozilla\Firefox\extensions\\FFToolbar@bitdefender.com: C:\Program Files\BitDefender\BitDefender 2010\bdaphffext\ [2010/08/04 23:42:55 | 000,000,000 | ---D | M]
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - No CLSID value found.
    O4 - HKCU..\Run: [manager] C:\WINDOWS\System32\drivers\setup\manager.exe File not found
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
    [2009/12/07 18:55:40 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?) -- C:\WINDOWS\System32\
    [2009/12/07 18:55:40 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?) -- C:\WINDOWS\System32\
    @Alternate Data Stream - 1343 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:WG66vMTXIZUeSgSlZJ5DBztT8c9haB
    @Alternate Data Stream - 1293 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:paPH2e4umgQLOIRBGxRV9zG0FvJwj
    @Alternate Data Stream - 1278 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:oPqDlO8pVUdjxXactfh2b
    @Alternate Data Stream - 1272 bytes -> C:\Program Files\Common Files\System:sflLwo8Cs9heSMp9q1khQW64
    @Alternate Data Stream - 1258 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:9vJ3IXM8vfRIIaJaY
    @Alternate Data Stream - 1251 bytes -> C:\Program Files\Common Files\Microsoft Shared:k9OBeFjdC1KAmJobTCij4pz
    @Alternate Data Stream - 1233 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:RaanGkWU0h1c8TCJJyq4Cf00
    @Alternate Data Stream - 1192 bytes -> C:\Documents and Settings\Deigo\Cookies:0s6zuNyQJwmZfMMNBos5Tsi
    @Alternate Data Stream - 1176 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:fvmldb3SorWVtWeSIz1INlp
    @Alternate Data Stream - 1174 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:Cn7oUytCOOMMcNMdcg
    @Alternate Data Stream - 1169 bytes -> C:\Program Files\Outlook Express:UmtqyYXWrie0ud7KUXxE4
    @Alternate Data Stream - 1157 bytes -> C:\Documents and Settings\Deigo\Cookies:kyNYloBCZ8zepzasDAmto
    @Alternate Data Stream - 1143 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:8Ij3aQnGdWCI1J5kB8loBAo
    @Alternate Data Stream - 1111 bytes -> C:\Program Files\Common Files\System:aecNGgzfYidlTUOCLE1ETXmp
    @Alternate Data Stream - 1105 bytes -> C:\Documents and Settings\All Users\Application Data\Microsoft:5LBf7pfNKVGgiZx7nK
    
    :Services
    
    :Reg
    
    :Files
    
    :Commands
    [purity]
    [emptytemp]
    [emptyflash]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • You will get a log that shows the results of the fix. Please post it.
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
 
Good :)

Last scans...

1. Download Security Check from HERE, and save it to your Desktop.
  • Double-click SecurityCheck.exe
  • Follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


2. Download Temp File Cleaner (TFC)
  • Double click on TFC.exe to run the program.
  • Click on Start button to begin cleaning process.
  • TFC will close all running programs, and it may ask you to restart computer.


3. Go to Kaspersky website and perform an online antivirus scan.

  • Disable your active antivirus program.
  • Read through the requirements and privacy statement and click on Accept button.
  • It will start downloading and installing the scanner and virus definitions. You will be prompted to install an application from Kaspersky. Click Run.
  • When the downloads have finished, click on Settings.
  • Make sure these boxes are checked (ticked). If they are not, please tick them and click on the Save button:
    • Spyware, Adware, Dialers, and other potentially dangerous programs
    • Archives
    • Mail databases
  • Click on My Computer under Scan.
  • Once the scan is complete, it will display the results. Click on View Scan Report.
  • You will see a list of infected items there. Click on Save Report As....
  • Save this report to a convenient place. Change the Files of type to Text file (.txt) before clicking on the Save button. Then post it here.
 
Status
Not open for further replies.
Back