Andro1d

Trusted Helpers
  • Content Count

    737
  • Joined

  • Last visited

Everything posted by Andro1d

  1. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your computer problem today. Please download this file - combofix.exe by sUBs Save it to your Desktop Please, never rename Combofix unless instructed. Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box. Click OK and this will start ComboFix in a special way. When fi
  2. NOD32 is great on not reporting false positives. You could always quarantine and if the program doesn't work properly you could take it out of quarantine and replace it. You could also run one of the following online scan's and see if it turns up on any other scans. F-Secure Online Scanner or Kaspersky Online Scanner
  3. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your computer problem today. Download OTViewIt to your desktop. Close all windows and open it Click Run Scan and let the program run uninterrupted It will produce two logs for you, one will pop up called OTViewIt.txt, the other will be saved on your desktop and called Extras. Post both those logs here. You may need to use two posts to get it all on the forum
  4. Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
  5. Hello again, Please do an online scan with Kaspersky WebScanner I highly recommend using Internet Explorer for best results! Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. Click on the Accept button and install any components it needs. The program will install and then begin downloading the latest definition files. Once they are downloaded, the database will be updated. Please accept any ActiveX or Java notifications After the files have been updated, go to the left side of the page under the Scan s
  6. I will never recommend any new Symantec products no matter what the reviews say. I have worked with it in the past, and have worked with their newer programs, and I still strongly dislike their products. I would highly recommend ESET NOD32 if you are looking to pay for a new subscription. It is very effective, low on resources, and has outstanding proactiv detection. This means it doesn't always rely on a "signature" from the company in order to detect threats. It is what I use and what many people in the malware removal community recommend. http://www.eset.com/products/nod32.php
  7. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. I am not seeing anything malicous from this log, so lets dig a little deeper. Step 1 Please download ATF Cleaner by Atribune. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. If you use Firefox browser Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser Click Opera at the top and
  8. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Step 1 Please download ATF Cleaner by Atribune. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. If you use Firefox browser Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like t
  9. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Sorry for the delay! Before we begin, you should save these instructions in Notepad to your desktop, or print them, for easy reference. Much of our fix will be done in Safe mode, and you will be unable to access this thread at that time. If you have questions at any point, or are unsure of the instructions, feel free to post here and ask for clarification before proceeding. Please re-open HijackThis and scan. Check the boxes next to all the entries listed below. O4 - HKLM\..\R
  10. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Sorry for the delay! Please Do a system scan and save a logfile button in HJT. It will scan and the log should open in notepad. Please post that log in this thread and we will then go from there.
  11. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Sorry for the delay! Step 1 Please download ATF Cleaner by Atribune. Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. If you use Firefox browser Click Firefox at the top and choose: Select All Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. If you use Opera browser Click Opera at the top and choose: Select All Click the Empty Selected button. NOTE
  12. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Sorry for the delay! Download OTViewIt to your desktop. Close all windows and open it Click Run Scan and let the program run uninterrupted It will produce two logs for you, one will pop up called OTViewIt.txt, the other will be saved on your desktop and called Extras. Post both those logs here. You may need to use two posts to get it all on the forum
  13. Hi everyone, Well I have another networking issue in my brother's PC. For our setup we have a Belkin 802.11 g wireless router connected wirelessly to a Nintendo Wii, and 2 Windows XP machines. Everything is good on the Wii and my machine, but it is on his machine where it shows its connected to the network just fine, but has no internet in Opera or IE. Now when I restart, the internet will work for a few minutes, then will just go out. I have googled this but I get lots of results with typing stuff into the CMD and getting logs, but I can't read those at all. I have tried manually resetin
  14. Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
  15. Nice job your log looks clean! Please use the following suggestions to help prevent reinfection. Time for some housekeeping Click START then RUN Now type Combofix /u in the runbox and click OK [*] When shown the disclaimer, Select "2" The above procedure will: Delete the following: ComboFix and its associated files and folders. VundoFix backups, if present The C:\Deckard folder, if present The C:_OtMoveIt folder, if present [*] Reset the clock settings. [*] Hide file extensions, if required. [*] Hide System/Hidden files, if required. [*] Reset System Restore. The following is a
  16. Hey, Please do an online scan with Kaspersky WebScanner I highly recommend using Internet Explorer for best results! Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan. Click on the Accept button and install any components it needs. The program will install and then begin downloading the latest definition files. Once they are downloaded, the database will be updated. Please accept any ActiveX or Java notifications After the files have been updated, go to the left side of the page under the Scan section a
  17. Hey, Please delete the old CFScript off of your dektop. 1. Please open Notepad Click Start , then Run Type notepad .exe in the Run Box. 2. Now copy/paste the entire content of the codebox below into the Notepad window: File:: C:\WINDOWS\system32\tcvdhd.dll C:\WINDOWS\system32\rvfduvbf.dll C:\WINDOWS\system32\bcamtryd.dll C:\WINDOWS\system32\jkkKeeDw.dll C:\sqmnoopt04.sqm C:\sqmdata04.sqm C:\WINDOWS\system32\qdoahcie.dll C:\WINDOWS\system32\mgwlun.dll C:\WINDOWS\system32\qsxjef.dll C:\WINDOWS\system32\iuujefha.dll Folder:: C:\Program Files\PCHealthCenter Registry:: [-HKEY_LOCAL_MACHINE\~\B
  18. Please go here and get the log. c:\_OTMoveIt\MovedFiles
  19. Ok, lets try a different approach. Please download the OTMoveIt2 by OldTimer. Save it to your desktop. Please double-click OTMoveIt2.exe to run it. (Vista users, please right click on OTMoveit2.exe and select "Run as an Administrator") Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy): [kill explorer] C:\WINDOWS\system32\tcvdhd.dll C:\WINDOWS\system32\rvfduvbf.dll C:\WINDOWS\system32\bcamtryd.dll C:\WINDOWS\system32\jkkKeeDw.dll C:\sqmnoopt04.sqm C:\sqmdata04.sqm C:\Program Files\PCHealthCenter H
  20. Hello again, 1. Please open Notepad Click Start , then Run Type notepad .exe in the Run Box. 2. Now copy/paste the entire content of the codebox below into the Notepad window: File:: C:\WINDOWS\system32\tcvdhd.dll C:\WINDOWS\system32\rvfduvbf.dll C:\WINDOWS\system32\bcamtryd.dll C:\WINDOWS\system32\jkkKeeDw.dll C:\sqmnoopt04.sqm C:\sqmdata04.sqm Folder:: C:\Program Files\PCHealthCenter Registry:: [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3ab3a1ea-08b8-4537-9be4-75014d32fe81}] [-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{71DAD6B9-06A8-4F66-A93F-ACBACC67B651}] 3. Save the above as CF
  21. Hi, Please manually turn off your PC by holding the power button. Wait 5 minutes and turn it back on. Then please post the CF log from C:\ComboFix.txt
  22. Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.
  23. Hello and Welcome to the forums. I am MoNsTeReNeRgY22 and I will be assisting you with your malware problem today. Please download this file - combofix.exe by sUBs Save it to your Desktop Please, never rename Combofix unless instructed. Now physically disconnect from the internet and STOP all your monitoring programs (Antivirus/Antispyware, Guards and Shields) Click on your START button and choose Run. Then copy/paste the entire content of the following quotebox (Including the "" marks and the Symbols) into the run box. Click OK and this will start ComboFix in a special way. When fin
  24. Nice job your log looks clean! Please use the following suggestions to help prevent reinfection. Also, you may delete any tools I had you download during the cleaning process. System Restore maintains a backup of your programs and may also backup infections, so please reset it to make a clean Restore Point. Please do this: On the Desktop, right-click My Computer > click Properties > click the System Restore tab. Check Turn off System Restore. Click Apply > a window will pop up and ask if you really want to turn it off > click Yes. Please wait a few moments to let it clear. Now plea
  25. Hello again, Step 1 Please re-open HijackThis and scan. Check the boxes next to all the entries listed below. O20 - AppInit_DLLs: uafmed.dll Now close all windows other than Hijackthis, then click Fix Checked. Close HijackThis. Step 2 Open notepad and copy and paste the following code box in it starting with @echo off @echo off echo Delitor by wng_z3r0 >deleteOutput.txt echo. >>deleteOutput.txt echo Files to delete: >>deleteOutput.txt echo ************************** >>deleteOutput.txt echo "C:\WINDOWS\sxmaokgf.exe" >>deleteOutput.txt attrib "C:\WINDOWS\sxmaokgf