Matching MD5 hashes but different file sizes, which technically is not possible. And leaves us without any verification of what file is the correct one(s). The malware altered boot level driver file is still showing in the ComboFix log, so we will need to do something different to get a handle on what needs to be done there. You are doing well so far though.
Go here and download USEC.at's radix_installer_trial.zip. Then unzip that and click the radixgui.exe to open the scan display.
Then without making any changes click the Check button to start the scan. Once it has completed click the Save Log button and save that to a location you can return to. Then click the "X" to close the Radix scanner.
!!!Caution - the Radix scanner has many settings and options, including many that can cause quick and permanent corruption to your operating system. Avoid the temptation to try any other options, scans or settings when using it.
That log will be too large for posting here, so instead just zip a copy of it, then send it to jintan AT malwarecrypt.com as an attachment. Please place "Submitted Files - banksy/bg/rdx" as the email Subject.
jintan, about 5 mins into the scan - a box appeared saying "CRASH" system error - do you want to continue ? - NOT RECOMMENDED. SO I EXITED THE SCAN..............
here`s the log anyway :
Thanks to all the people who donated and ensured the continued development of this software! If you want to donate and keep this software alive, please have a look at the About-Tab. Thanks in advance!
USEC Radix V1, 0, 0, 10 [2009/11/28] at your service. ---- Check started at 14.1.2010 16:39:54 ---- Running on: Microsoft Windows NT 5.1 Build 2600 Service Pack 3 Number of Processors: 1, Active Processor Mask: 00000001 Processor: Intel Level 6 Revision 0701 Allocation granularity: 00010000, Page granularity: 00001000 Application space: 00010000-7FFEFFFF [X] Filter common false alarms. 16:39:54 - Performing check: "Hidden files": This check can take some time depending on your harddisk size. You can interrupt it with the ESC key. 16:44:3 - Performing check: "Alternate Data Streams": This check can take some time depending on your harddisk size. You can interrupt it with the ESC key. [*] C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8:$DATA [*] C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2:$DATA [*] C:\Documents and Settings\All Users\Documents\My Pictures\photos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\BBC SPORT.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Connor Banks ConnorB7027.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\e-Mail.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Free SMS Text Messaging and Business Bulk SMS Solutions from CardBoardFish.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Google.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Links\Suggested Sites.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Liverpoolfc.tv LFC Reverse Auction. How Low Will It Go.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\liverpoolfc.tv Official Web Site.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Login - BT Yahoo!.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Max Dirt Bike - ride your dirt bike over all the obstacles very fast.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\Mousebreaker Free Online Flash Games - football games and more!.url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Favorites\YouTube - Broadcast Yourself..url:favicon:$DATA [*] C:\Documents and Settings\CONNOR\Local Settings\Application Data\Microsoft\Messenger\connor@shanklygates.co.uk\Sharing Folders\lou_feath@hotmail.co.uk\Thumbs.db:encryptable:$DATA [-] Error scanning file C:\Documents and Settings\CONNOR\Local Settings\Application Data\Microsoft\Messenger\connor@shanklygates.co.uk\SharingMetadata\lou_feath@hotmail.co.uk\DFSR\Staging\CS{F864B51F-440D-8283-D66B-A50A148A35B9}\01\10-{F864B51F-440D-8283-D66B-A50A148A35B9}-v1-{CA9C: 0x05::0x06: The system cannot find the file specified.
[-] Error scanning file C:\Documents and Settings\CONNOR\Local Settings\Application Data\Microsoft\Messenger\connor@shanklygates.co.uk\SharingMetadata\lou_feath@hotmail.co.uk\DFSR\Staging\CS{F864B51F-440D-8283-D66B-A50A148A35B9}\11\11-{CA9CF4B1-B853-4950-857C-CFAF79B22CD2}-v11-{CA9: 0x05::0x06: The system cannot find the file specified.
[*] C:\Documents and Settings\CONNOR\My Documents\My Pictures\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\CONNOR\My Documents\My Received Files\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\Desktop\Inherit.exe:SummaryInformation:$DATA [*] C:\Documents and Settings\favv\Desktop\Inherit.exe:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\favv\Desktop\MUSIC\bits & bats\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\Desktop\MUSIC\kooks - konk\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\Desktop\MUSIC\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\Favorites\e-mail & text\Free SMS Text Messaging from CardBoardFish.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\e-mail & text\garfield.banks@yahoo.com.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\e-mail & text\Login - BT Yahoo!.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\e-mail & text\nando`s e-mail.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\BBC iPlayer - Home.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\Blockbuster.co.uk.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\Cineworld - Cineworld Cinemas Bradford - Film Times, Ticket Prices and Contact Details.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\http--dvdrental.cd-wow.com-welcome-home.html.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\LOVEFiLM DVD rental.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\Movie Trailers - Film Clips, Celebrity Interviews, Reviews from MyMovies.net.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\ODEON - Leeds-Bradford.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\OutNow! dvd Rental.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\Radio Times - The Ultimate TV Guide, Radio Listings, Film Reviews.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\skymovies.com.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\Tesco DVD Rental.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\The Internet Movie Database (IMDb).url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\Tv Listings Listings What's on TV - Top TV listings guide, plus soaps, news, prizes and previews.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\film & tv\YouTube - Broadcast Yourself..url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\BBC SPORT Liverpool.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\http--www.sportizo.com-football.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\HUDDERSFIELD RCD JUNIOR FOOTBALL LEAGUE.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\kitster29 on deviantART.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\Liverpool TEAMtalk.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\Liverpool Echo.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\Liverpool Sport News Click Liverpool.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\Liverpoolfc.tv Official Web Site.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\MyP2P.eu Free Live Sports on your PC, Live Football, MLB, NBA, NHL and more....url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\Sky Sports Liverpool.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\FOOTBALL\This Is Anfield Liverpool FC Fan Site.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\forums\Bullguard Free Antivirus Forum.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\forums\Digital Spy Forum.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\forums\Digital Video forum.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Audible.co.uk - Downloadable audio books.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\BBC - Homepage.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Directory Enquiries - Online Phone Book & Telephone Directory.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Download - NDS ROMs - Nintendo DS.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Free Online Spell Checker - check any text (English, French, Spanish, German, Italian).url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Media Convert - free and on line - convert and split sound, ringtones, images, docs - MP3 WMV 3GP AMR FLV SWF AMV MOV WMA AVI M.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Route Planner (GB) Maps and directions - The AA.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Royal Mail’s online Postcode finder.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\Links\Take a Break Magazine Take a Break Magazine.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\MONEY\Egg Security Login.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\MONEY\Money Saving Expert Consumer Revenge - Credit Cards, Shopping, Bank Charges, Cheap Flights and more.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\MONEY\My Accounts Tesco Personal Finance.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\MONEY\PayPal.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\MONEY\Virgin Money Online Banking.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\music & gigs\Alive® Alive.co.uk-bradford Bradford listings.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\music & gigs\AllCDCovers Browse Our Collection of CD-DVD Covers Album Art.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\music & gigs\Bradford Live Music from Ents24.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\music & gigs\Cdcovers.cc - World's Largest CD Covers and DVD Covers Album Art Archive.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\music & gigs\Gasworks.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\music & gigs\hmv.com Music CDs, DVDs, Games & More.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\search\Ask Jeeves Web Search.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\search\Google.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\search\Yahoo! UK & Ireland.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\shops\amazon.co.uk.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\shops\CCL Computers.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\shops\Fat Fingers - eBay typos and spelling mistakes.url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\shops\Nike Official Store. Shop Nike Footwear, Clothing & Sports Equipment at Nike Store..url:favicon:$DATA [*] C:\Documents and Settings\favv\Favorites\shops\Welcome to eBay.url:favicon:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\alcudia 2008\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\benidorm `95\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\cd covers\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\halloween @ susans `09\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\hollies 10th @ laser quest\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\ians BBQ 18th july `09\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\mobile photos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\mums photos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\new years eve `09\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\photos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\pics\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Pictures\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\favv\My Documents\My Videos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\BBC - CBBC - Home.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Disney.co.uk TV Home.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Google Image Search.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Kids Games, Kids Movies, Kids Music, and More - Yahoo! Kids.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Links\liverpoolfc.tv Official Web Site.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Links\Login - BT Yahoo!.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Links\Suggested Sites.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\My cool webby!!!.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Route Planner Routes, maps and directions - The AA.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\SpongeBob SquarePants.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\Welcome to Shanklygates.co.uk.url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\Favorites\YouTube - Broadcast Yourself..url:favicon:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\New Folder\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\photos\alcudia 2008\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\photos\buttershaw v beckfoot - valley parade\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\photos\caravan may `08\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\photos\pontins, wales\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\photos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\My Pictures\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\HOLLIE\My Documents\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Christmas 2009\Saturday Night Peter Amazon.co.uk Peter Kay Books.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Christmas 2009\Thanks for Nothing Amazon.co.uk Jack Dee Books.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Christmas 2009\Yamaha F310 - Acoustic Guitar - Basic Starter Pack Amazon.co.uk Electronics & Photo.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Films\IMDb.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Anfield Online.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\BBC SPORT _ Football.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Fantasy Football - You The Manager.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Football Shirt Culture.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Liverpool English Premier League Football News from TEAMtalk.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Liverpoolfc.tv.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Premier League.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\Sky Sports Football News.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Football\This Is Anfield.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Games\EA UK.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Games\Slime Soccer.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Games\The Beatles Rock Band.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Games\Xbox.com.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Links\Facebook IF 75 PEOPLE JOIN THEN I WILL PUT LIAM BANKS SINGING ON YOUTUBE.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Links\Suggested Sites.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Links\Welcome to Facebook! Facebook.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\Blur.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\Frank Sinatra.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\Franz Ferdinand.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\hmv.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\Kings Of Leon.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\NME.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\Oasis.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\Q.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\The Killers.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\The Strokes.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Music\U2.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\BBC iPlayer.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Bradford MLE (Login).url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\CBFSMS.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Gametrailers.com.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\iPhone-iPod Touch - Electronic Arts UK Community.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\iPod + iTunes.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\iPod Touch User Guide.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Login - BT Yahoo!.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\LOVEFiLM.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Media Convert.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Mirror.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Rolling Stone.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Tesco DVD Rental.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Text To Speech, TTS English, Spanish, French, Russian, Italian, German, Portuguese, Korean, Japanese, Chinese.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Twitter.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Welcome to OutNow! Unlimited DVD Rentals, New DVD Releases, Blu-ray, and DVD Reviews at OutNow.co.uk.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Wikipedia.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\Xtranormal.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Others\YouTube.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Search Engines\Google.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Search Engines\MSN UK.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\Amazon.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\Apple Store (U.K.).url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\Argos.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\eBay.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\GAME.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\MSN Shopping.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Shopping\Welcome to Apple Store - Apple Store (U.K.).url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\Sun Secure Global Desktop Software.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\Favorites\ups UPS Returns.url:favicon:$DATA [*] C:\Documents and Settings\LIAM\My Documents\adidas-28012\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\Bitesize Science (AQA) (D)\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\Bluetooth\Image Inbox\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Karaoke\Karaoke CD+G Creator Examples\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\HOZA BIRTHDAY CD\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\Album Artwork\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Arctic Monkeys\Whatever People Say I Am, That's What I\01 The View From the Afternoon.m4a:SummaryInformation:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Arctic Monkeys\Whatever People Say I Am, That's What I\01 The View From the Afternoon.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Arctic Monkeys\Whatever People Say I Am, That's What I\07 Riot Van.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Arctic Monkeys\Who the F___ Are the Arctic Monkeys_ - E\01 The View From the Afternoon.m4a:SummaryInformation:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Arctic Monkeys\Who the F___ Are the Arctic Monkeys_ - E\01 The View From the Afternoon.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Editors\The Back Room\03 Blood.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\The Beatles\Beatles for Sale\01 No Reply.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\The Beatles\Please Please Me\11 Do You Want to Know a Secret.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\The Beatles\With the Beatles\07 Please Mister Postman.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\The Enemy\We'll Live and Die In These Towns\04 Had Enough.m4a:SummaryInformation:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\The Enemy\We'll Live and Die In These Towns\04 Had Enough.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\U2\How to Dismantle an Atomic Bomb\10 Original of the Species.m4a:SummaryInformation:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\U2\How to Dismantle an Atomic Bomb\10 Original of the Species.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\U2\How to Dismantle an Atomic Bomb\11 Yahweh.m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\U2\Zooropa\05 Stay (Faraway, So Close!).m4a:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Music\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Pictures\iPod Photo Cache\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Pictures\JN\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Pictures\KASABIAN SHIRT DESIGNS\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Pictures\New Folder\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Pictures\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\My Videos\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\LIAM\My Documents\video1.mov:SummaryInformation:$DATA [*] C:\Documents and Settings\LIAM\My Documents\video1.mov:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d}:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Abba Pictures - abba - image no 10743.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\AQA 63336 Ask any question and get a free instant answer from Any Question Answered.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\BBC iPlayer - Home.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Being made redundant Directgov - Employment.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Cheap Glasses - Super Saver Prescription Glasses for Only £5 - $8.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Cheap holiday accommodation - Beach hotels, villas, apartments Somewhere2stay.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Cheapest website to book hol - Cala d'Or Forum - TripAdvisor.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Dental insurance Compare UK dental insurance - TESCO Bank.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\eBay - The UK's Online Marketplace.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\eBill - My Account - Help - Virgin Media.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Fantasy Football - You The Manager.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Find and choose ho!!!!als near bd6 1tg.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Free SMS Text Messaging and Business Bulk SMS Solutions from CardBoardFish.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\itfactory.co.uk - Cheap laptops Fujitsu Lifebook E-Series Refurbished laptop.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Links\Suggested Sites.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Liverpoolfc.tv Official Web Site.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Login - BT Yahoo!.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Low Cost Holidays Cheap holiday packages & all inclusive hotel deals.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Money Saving Expert Consumer Revenge - Credit Cards, Shopping, Bank Charges, Cheap Flights and more.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Mortgage payment protection insurance from Best Insurance.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\My eBay Summary.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Route Planner Routes, maps and directions - The AA.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Skegness Camp Sites.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\STARTONE CG 851 1-8 - U.K. International Cyberstore.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Tesco DVD Rental.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Vacancies — Bradford College.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Virgin Credit Card - UK Credit Cards, 0% balance transfer and discount offers.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Welcome to OutNow! Rent Unlimited Amount of DVDs..url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\Your right to know about your personal records Social Services - adult care Calderdale Council.url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\Favorites\YouTube - Broadcast Yourself..url:favicon:$DATA [*] C:\Documents and Settings\MUVVER\My Documents\My Pictures\BUTTERSHAW V BECKFOOT MAY 20TH 2008\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\MUVVER\My Documents\My Pictures\Img0003\Thumbs.db:encryptable:$DATA [*] C:\Documents and Settings\MUVVER\My Documents\My Pictures\Thumbs.db:encryptable:$DATA [-] Error scanning file C:\pagefile.sys: 0x05::0x06: The process cannot access the file because it is being used by another process.
You chose correctly in not opting to continue. Gonna need something on our side there getting the accurate info though.
Go here and download reglooks.exe to your Desktop. Doubleclick on it to run it and when it has finished scanning, a log named result.txt will open in Notepad. Copy the log and post it in this thread.
---------------
Go here, scroll down and download RootRepeal.zip to your Desktop. Unzip that, and then click RootRepeal.exe to open the scanner. Next click on the Report tab, and then click on Scan. A Window will open asking what to include in the scan. Check all of the below and then click Ok.
You will then be asked which drive to scan. Check C: and click Ok again. The scan will start. It will take a little while so please be patient. When the scan has finished, click on Save Report. Name the log RootRepeal.txt and save it to your Documents folder (it should default there). When you have done this, please copy and paste it in this thread.
REGLOOKS logfile - version 0.985 Scan started: 15/01/2010 15:50:43.06
--- INFORMATION ---
Manufacturer: System Manufacturer - Model: System Name Operating System: Microsoft Windows XP Professional -- 5.1.2600 -- Service Pack 3 -- Processor: AMD Duron(tm) Processor Number of Processors: 1 Work Station Bootmode: Normal boot Total RAM: 735 MB (free 310 MB - 42%)
Computername: HOME Domain: MSHOME User: favv (Administrator account)
ROOTREPEAL (c) AD, 2007-2009 ================================================== Scan Start Time: 2010/01/15 16:04 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ==================================================
Path: C:\Documents and Settings\LIAM\My Documents\My Music\iTunes\iTunes Music\U2\How to Dismantle an Atomic Bomb\10ORIG~1.M4A:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} Status: Visible to the Windows API, but not on disk.
Path: C:\Documents and Settings\CONNOR\Local Settings\Application Data\Microsoft\Messenger\connor@shanklygates.co.uk\SharingMetadata\lou_feath@hotmail.co.uk\DFSR\Staging\CS{F864B51F-440D-8283-D66B-A50A148A35B9}\11\11-{CA9CF4B1-B853-4950-857C-CFAF79B22CD2}-v11-{CA9CF4B1-B853-4950-857C-CFAF79B22CD2}-v11-Downloaded.frx:{59828bbb-3f72-4c1b-a420-b51ad66eb5d3}.XPRESS Status: Visible to the Windows API, but not on disk.
All wrapped around the issue of ndis.sys there. and the file info on that is just not reliable.
Locate another computer that has XP Pro, Service Pack 3 (perhaps a friend or family member), and have them provide you with a clean copy of their ndis.sys file. They will find it here on their systems:
c:\windows\system32\drivers\ndis.sys
Once you have that file, place a copy of it in that "drivers" folder. Agree to any prompts to overwrite the existing file. Reboot, and run and post back a new Reglooks log please.
i have copied ndis.sys from my laptop to a cd-r, but when i try & copy/paste it to the drivers folder i get : "cannot copy ndis : access is denied. make sure the disk is not full or write-protected and that the file is not currently in use". banksy.
In reviewing the logs in this thread I see now I didn't catch that ComboFix earlier indicated another file, atapi.sys was being altered. Either along with ndis.sys, or the infected atapi.sys is causing the malware log results. Let's locate a clean copy of that as well, then use that CD you just mentioned to access the Recovery Console and exchange file there. For now, place that clean copy of ndis.sys directly in the C folder, so it will then be C:\ndis.sys (if one is already there delete it first).
Click here and download jpshortstuff's SystemLook to your desktop, then click that file to open the scan display. In the open textbox, copy and paste the following (inside the Code box below):
:filefind atapi.sys
Then click Look. Once the scan completes Notepad will open - copy/paste those contents back here please. That will also be saved as a log where you have the scan file, named SystemLook.txt.
Let's see if Windows will do the work for us there.
Make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"
Right click My Computer, left click Explore to open Explorer.
Using the plus (+) symbols to expand the lists, navigate to C:\Windows and create a new folder and call it lastgood. If lastgood or lastgood.tmp folders already exists, please rename the folder to oldlastgood.
When you have done this, open the lastgood folder and create a folder called System32, and in that create a folder named drivers.
So after that you should have:
C:\Windows\lastgood\System32\drivers
In that new "drivers" folder place a copy of that clean ndis.sys file you got from the other computer.
Then navigate to the following file, copy it and also place a copy of it in that new "drivers" folder:\
Then restart the computer, and as it boots up tap the F8 key about once per half-second, to access the startup menu (where you can make Safe Mode selections). From that menu select the following:
Last Known Good Configuration
After the bootup completes run a new ComboFix scan, and post that log please.
i`ve created "lastgood" folder but, as i`ve said the copy of "ndis.sys" from the laptop seems to be protected.... when i try & paste it says : "cannot copy ndis : access is denied. make sure the disk is not full or write-protected and that the file is not currently in use". banksy.
I hadn't anticipated the file to be locked from copying to the new folder.
Rename that clean ndis.sys file to larry.com, and place that in your C drive folder, so it is then C:\larry.com
Then make a copy of that i386\atapi.sys file, rename it to moe.com and place that also directly in the C drive folder. You should then have (yes, the names are from the old comedy team):
C:\larry.com C:\moe.com
--------------
Then load the XP CD into the CD-ROM drive and restart the system. On reboot watch for and agree to any prompts to boot from the CD. If the system only reboots to Windows stop and post back here and we will discuss steps to make changes in the BIOS.
After the installation software inspects the system and loads all necessary device drivers you will see the "Welcome To Setup" screen, with the following menu:
This portion of the Setup program prepares Microsoft Windows XP to run on your computer:
To setup Windows XP now, press ENTER.
To repair a Windows XP installation using Recovery Console, press R.
To quit Setup without installing Windows XP, press F3.
Press "R" to start the Recovery Console setup. After you start the Windows Recovery Console, you receive the following message:
Microsoft Windows(R) Recovery Console
The Recovery Console provides system repair and recovery functionality. Type EXIT to quit the Recovery Console and restart the computer.
1: C:\WINDOWS
Which Windows Installation would you like to log on to (To cancel, press ENTER)?
After you enter the number for the appropriate Windows installation (usually #1), Windows will then prompt you to enter the Administrator account password if one was created (if one was not created then just press Enter).
At the prompt type the following, pressing Enter after each:
Agree to any messages to overwrite the existing files. When you hit Enter after typing exit your computer will reboot. Do Not press any key until the system has completely rebooted, then after the reboot be sure to remove your XP CD from the CD-ROM drive.
Then run and post back a new ComboFix scan log please.
hi jintan, my pc doesn`t reboot direct fron cd when i restart but it always gives me 2 options :
1. start microsoft windows recovery console
or
2. start microsoft windows xp professional
option 2 is the default but i have a 2 or 3 seconds to change options before it starts - should just go to option 1 ?
also, ive created larry.com & moe.com & they are in my c drive, but larry.com has become : larry.com.sys (system file 178kb) & moe.com is called moe.com (MS-DOS Application 95kb) is this ok ? banksy.
That larry.com.sys issue could be related to your file views there. Make sure you can View Hidden Files. Also uncheck "Hide Extensions for Known File Types"
Then see if you can just rename that to larry.com. If not, use the following, with this newer file name:
hi jintan, changed larry.com.sys to larry.com ran windows recovery console as advised combofix log as follows :
ComboFix 10-01-17.04 - favv 18/01/2010 16:32:40.4.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.735.416 [GMT 0:00] Running from: c:\documents and settings\favv\Desktop\456out.com .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
c:\documents and settings\favv\Application Data\inst.exe
. ((((((((((((((((((((((((( Files Created from 2009-12-18 to 2010-01-18 ))))))))))))))))))))))))))))))) .
I am not quite sure what ".*ù*¹*%" will appear as there, but it should show as a group of unreadable characters like the key here. Just right click that ".*ù*¹*%" and select Delete. Agree to the warning, then close the Registry Editor.
-----------------
Be sure to continue to temporarily disable any protective software when running the scan tools we use here.
Open notepad (go to Start, Run, type notepad and press Enter) and copy/paste the text in the codebox below into it:
You should now have both ComboFix and that CFScript.txt on the desktop. Just left click/hold on the CFScript.txt file, and drag it into ComboFix to start the scan.
ComboFix will now run as it did before. Allow the scan to run. When completed a text window will appear - please copy/paste the contents back here. This log can also be found at C:\ComboFix.txt.
A caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.
----------------
Download Malwarebytes' Anti-Malware from Here or Here.
Double Click mbam-setup.exe to install the application.
* Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish. * If an update is found, it will download and install the latest version. * Once the program has loaded, select "Perform quick scan", then click Scan. * The scan may take some time to finish,so please be patient. * When the scan is complete, click OK, then Show Results to view the results. * Make sure that everything is checked, and click Remove Selected. * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. * The log is automatically saved by Malwarebytes and can be viewed by clicking the Logs tab in Malwarebytes. * Copy and Paste the entire report in your next reply. If it calls for a reboot to complete the repairs do that as well then.
----------
Disable your antivirus program and go here and run an online scan using ESET Online Scanner (you will need to use Internet Explorer for this scan, or download the installer to run it in a different browser). If you accept the Terms of Use, check the box and click Start. After the ActiveX Control has loaded, it will take a couple minutes for the scanner to get ready. Next, check the following boxes:
Remove found threats Scan unwanted applications
Next to "Current scan targets: Operating memory, Local drives", click the "Change" word. Make sure you place a check next to all disk drives, including any external drives that are attached (no need to check off the floppy or DVD/CD-Rom drives).
Click Start. This scan may take a while, so please be patient. A log may open when the scan is complete (if not, go to C:\Program Files\EsetOnlineScanner\ and open the file log.txt). Click Edit - Select All then copy/paste that log back here please.
If you have any problems getting Eset started, one work-around is to have an open Internet connection, and then click here and download the esetsmartinstaller_enu.exe Eset installer. Then click that file, and follow the same previous steps to run the scan.
Post that log, the C:\ComboFix.txt log and the Malwarebytes log please.
ComboFix 10-01-18.01 - favv 18/01/2010 18:23:57.5.1 - x86 Microsoft Windows XP Professional 5.1.2600.3.1252.44.1033.18.735.353 [GMT 0:00] Running from: c:\documents and settings\favv\Desktop\456out.com Command switches used :: c:\docume~1\favv\Desktop\CFScript.txt .
((((((((((((((((((((((((( Files Created from 2009-12-18 to 2010-01-18 ))))))))))))))))))))))))))))))) .
ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=7 # IEXPLORE.EXE=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6211 # api_version=3.0.2 # EOSSerial=27ea9d65c7eb554ca9f05454969bdcdb # end=finished # remove_checked=true # archives_checked=false # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2010-01-18 09:40:27 # local_time=2010-01-18 09:40:27 (+0000, GMT Standard Time) # country="United Kingdom" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=512 16777215 100 0 1057585 1057585 0 0 # compatibility_mode=8192 67108863 100 0 4159 4159 0 0 # scanned=95887 # found=26 # cleaned=26 # scan_time=4159 C:\Documents and Settings\LIAM\My Documents\Setup.exe Win32/Adware.180Solutions application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Documents and Settings\LIAM\My Documents\zSetup.exe a variant of Win32/Adware.180Solutions application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\Windows Live\Messenger\msimg32.dll Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Program Files\Windows Live\Messenger\riched20.dll Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\CoreSrv.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HostIE.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HostOL.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSA.exe.vir probably a variant of Win32/Adware.180Solutions application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSADF.exe.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarSAHook.dll.vir a variant of Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\HotbarUninstaller.exe.vir multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\Srv.exe.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\Program Files\Hotbar\bin\11.0.78.0\Toolbar.dll.vir Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\ndis.sys.vir Win32/Protector.B virus (cleaned - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012268.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012271.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012272.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012273.exe probably a variant of Win32/Adware.180Solutions application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012275.exe Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012276.dll a variant of Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012277.exe multiple threats (deleted - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012278.exe Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP24\A0012279.dll Win32/Adware.HotBar.E application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP32\A0015332.dll Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\System Volume Information\_restore{18F1C887-1B5D-4ADD-B28A-9923490B7F34}\RP32\A0015333.dll Win32/Toolbar.MyWebSearch application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\WINDOWS\system32\dllcache\ndis.sys Win32/Protector.B virus (cleaned - quarantined) 00000000000000000000000000000000 C
jintan, i wasn`t sure whether to delete the quarantined files - so i didn`t, but they are in a folder within the eset online scanner folder - should i delete them ? cheers again, banksy.
Other than a few installer files bundled with an adware component, the majority of what eset just found are just infection ComboFix already removed to it's Qoobox quarantine, and then infection that had been held harmless in System Restore. We will address those, and you can install Eset using Add/Remove Programs, and if offered by that check off the option to delete the quarantine as well.
No malware being picked up at this time. Before we move on to some last steps here, post back how things are running please.
things seem to be running ok, sometimes the internet is quite slow compared with the laptop (which runs wireless from the router connected to this pc) i dont know if that means anything. i`ve noticed that in my C:\WINDOWS folder there is OVER 260 folders called "$NtUninstall....." each one has its own number, they are all various sizes, the full name of one (picked at random) is : $NtUinstallKB885835$ it is 1.46 MB in size. i dont know what they are or where they`ve come from ! do you know what they are ? thanks again, banksy.
You are seeing the normally hidden system files - those are Windows update backup files saved to allow you to uninstall any of the updates if you need to. If you reverse the procedures here you can have them hidden again.
To make sure temp file storage bogging down isn't slowing things let's clean that.
Download CCleaner from one of the links here. Click the downloaded file to start the install. At the options display I suggest unchecking the bottom four options, unless for some reason you want it to install a Yahoo toolbar.
Then click Run Cleaner, okay the warning and allow CCleaner to remove temp files. I truly recommend against using any of the options displayed on CCleaner's left panel, as some of these have the potential to cause serious problems. Let's me know if that helped things there please.
cheers, jintan. done ccleaner, do i need to keep all the downloaded programmes from my desktop eg.(hijackthis,avenger,combofix,malwarebytes,rootrepeal,reglooks,rsit,radix,systemlook) also folders created en-route (quoobox,456out) - not to mention : larry & moe
You may need to delete some files manually, like those two of the three stooges-named files, but yes, it is a good idea now to uninstall or delete everything our work added there.
Eset, if you don't plan to use it again, uninstalls through Add/Remove Programs.
You can also at this time delete the files/folders of the tools we used. To assist with some of that download OTC.exe by OldTimer to your desktop. This will help by automatically removing some of the tools we used.
Just click OTC.exe, then click CleanUp, and select Yes. When it finishes removing some of the tools and files we used there just agree to the reboot, and OTC should self-delete once the system has rebooted (if not just delete the OTC.exe file).
-------------------------
Then a good idea is to reset the System Restore. To do this, right-click My Computer and select Properties. Click the System Restore tab in the window that appears, and check the box that says "Turn off System Restore on all drives" and click Apply.
You will be asked if you are sure, click Yes. This will delete the restore points. Then click OK in the Properties window and reboot your computer.
When your desktop appears, right-click My Computer and select Properties once more. Uncheck the "Turn off System Restore..." box and click Apply. OK.
In addition, I like to recommend reviewing the information Here to make sure you stay malware free.
Currently it is Sunday, May 19, 2013 1:00 AM (GMT +3) There are a total of 59,515 posts in 13,139 threads. In the last 3 days there were 4 new threads and 5 reply posts. View Active Threads
Who's Online
This forum has 34611 registered members. Please welcome our newest member, caspied. 16 Guest(s), 0 Registered Member(s) are currently online. Details