This thread's last reply is from January 25, 2009, 8:15 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Bio-Hazard
Hello!
Do you still want to continue?
tnt77
Hello - got side tracked. I am still fighting with this one. I ran the Panda anti-Rootkit and had no infection alerts then as indicated the panada virus scan which advised that i had a number of issues but I was going to have to pay to have then removed. I ran the Sophos anti-rootkit and it identified a number of questionable registry keys but did not allow me to do anything with them (other than see some details). I believe there is an problem between my F-secure and the combo-fix - even when I unload. I had - even when running combo-fix in safe mode had a pop-up advising that shaw (my service provider- who supplies F-secure) secure firewall was running - even though I tried to shut it off.
I at this point have some computer issues but not sure if they are now virus related or scars from such
cheers
Bio-Hazard
Hello!
It is a big log so it will take me some time research. I will answer you either today or tomorrow.
Regards,
Bio-Hazard
tnt77
thanks - I appreciate the help. There is a lot of extraneous stuff as well that requires a clean up !
cheers
tnt77
Hi - emptied house calls quarantine
I had, when first got the computer, Norton (symantex ) but when I uninstalled to use FSecure 'pieces' have been left behind including the process NPROTECT.exe - for the recycle bin.
Bizarre occurrence today - when I opened task manager and switched to processes - the top part of the Manager screen disappeared ( the top of box which allows choice tabs, shutdown and min/max size). I tied to close task manger from taskbar by right mouse click and close but would not get the menu option - period
Sorry Malware scan showed 0 issues
removed hijack this entries
backed up registry
OT Move log below : I had an "access violation at address 72058B0 read address of address 270508B0" when ran
new Hijack this posted as attachment
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\Kazaa Lite K++\Kazaa.kpp deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\LimeWire\LimeWire.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Documents and Settings\T&A\Desktop\nancy drew short cuts\BitDownload\BitDownload.exe deleted successfully.
========== FILES ==========
C:\Documents and Settings\T&A\Desktop\Kaylee's games\nancy drew short cuts\bigfishgames_p22128766_s1_l1.exe moved successfully.
C:\Combo-Fix moved successfully.
C:\WINDOWS\temp\fsaua.tmp moved successfully.
C:\WINDOWS\temp\F-Secure\Anti-Virus moved successfully.
C:\WINDOWS\temp\F-Secure moved successfully.
Folder move failed. C:\WINDOWS\temp scheduled to be moved on reboot.
C:\ComboFix\N_ moved successfully.
C:\ComboFix moved successfully.
C:\Program Files\LimeWire moved successfully.
C:\Program Files\Azureus\plugins\azupdater moved successfully.
C:\Program Files\Azureus\plugins\azplugins moved successfully.
C:\Program Files\Azureus\plugins moved successfully.
C:\Program Files\Azureus moved successfully.
C:\WINDOWS\system32\CF24175.exe moved successfully.
C:\WINDOWS\system32\CF23029.exe moved successfully.
C:\WINDOWS\system32\CF22085.exe moved successfully.
C:\WINDOWS\system32\CF16448.exe moved successfully.
C:\WINDOWS\system32\CF13676.exe moved successfully.
C:\WINDOWS\system32\CF10714.exe moved successfully.
C:\WINDOWS\system32\CF10280.exe moved successfully.
C:\WINDOWS\system32\CF10149.exe moved successfully.
C:\WINDOWS\system32\CF19462.exe moved successfully.
C:\WINDOWS\system32\CF18568.exe moved successfully.
C:\WINDOWS\gmer.ini moved successfully.
C:\WINDOWS\gmer_uninstall.cmd moved successfully.
C:\WINDOWS\gmer.exe moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\gmer.dll
Bio-Hazard
Hello!
Could you please try to run HijackThis again and post a log for me to see.