CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

[FIXED]Unhappy Mothers Day - infected computer
Goto page Previous  1, 2, 3, 4
 
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
MauriceN

1st Responder
Premium Member

Joined: May 20, 2006
Posts: 989

1st Responders MVP Premium

PostPosted: Mon Jun 09, 2008 2:46 am    Post subject:
Reply with quote

Hello Jim,
Close all browsers and all other programs that you have started.

Start HijackThis. Look for these lines and place a checkmark against each of the following, if still present

Quote:
O2 - BHO: (no name) - {00000250-0320-4dd4-be4f-7566d2314352} - (no file)

O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.Net\PartyPokerNet\RunPF.exe (file missing)
Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer (& or any other browser) is closed when you click Fix Checked!
>
Go to Control Panel, Add-Remove Programs. Un-install Adobe Reader. Then make a clean exit when done.
You have an older version of it, which may lead to security exploitations.
Download and install Adobe Reader 8.1.2
http://www.adobe.com/products/acrobat/readstep2.html
>

On the Windows "update" issue: See and do the items at Windows and Microsoft Update Problem Solver

Your HJT log looked good. ESET scan showed no new malware & only tagged item in quarantine already. The Kaspersky showed no new malware either.

Since there are no further signs of malware, I'm about to close this thread. You may, if needed, use the general Windows forum to pursue any further issues. If it is related to malware, ping me by PM (if needed) to re-open this.

Now, it is time to remove Combofix and some tools we used.
We will remove Combofix and all its associated folders. By whichever name you named it, (either Combofix or Combo-fix), put that name in the RUN box stated just below. The "/u" in the Run line below is to start Combofix for it's cleanup & removal function.
The utility must be removed to prevent any un-intentional or accidental usage, PLUS, to free up much space on your hard disk.

  • Click Start, then click Run.

    In the command box that opens, type or copy/paste
    combofix /u
    and then click OK.

    [img]

    http://i78.photobucket.com/albums/j116/amateur_photos/CFuninstall.png
    [/img]

  • Please double-click OTMoveIt.exe to run it.
  • Click on the CleanUp! button. When you do this a text file named cleanup.txt will be downloaded from the internet. If you get a warning from your firewall or other security programs regarding OTMoveIt attempting to contact the internet you should allow it to do so. After the list has been download you'll be asked if you want to Begin cleanup process? Select Yes.
  • This step removes the files, folders, and shortcuts created by the tools I had you download and run.
Run ATF Cleaner, and checkmark "Empty Recycle Bin", click "Empty Selected" and exit the program.
ATF Cleaner you may keep, and indeed use regularly to remove temp files.

MBAM is a great anti-malware tool. You may keep it and either subscribe (purchase) to get automatic updates or keep as is and do manual updates. Use it periodically to scan system, in addition to the tools you previously had.

Closing remarks:On some regular schedule, it is a good idea to do an online scan for viruses and malware. Here is a very short list of sites where this may be done:
ESET Online Scanner

F-Secure Online Scanner

Kaspersky Webscan Online Virus Scanner

Panda ActiveScan

Trend Micro Housecall

We are done here. All the best to you. Cool


_________________
~Maurice Naggar
MS-MVP
Back to top
View users profile Send private message Visit posters website
jcrotinger

Trooper
Trooper


Joined: May 12, 2008
Posts: 34
Location: USA

PostPosted: Sat Jun 21, 2008 6:36 pm    Post subject:
Reply with quote

Hi Maurice,

Thanks for all the help. For some reason I didn't get an email on this post, which is why it took this long to respond. Wish I'd checked in earlier.

The Windows Update fix has been pulled, so I've updated manually. Only an Office 2003 fix available so perhaps its been running fine.

I'll turn this back over to my wife and we'll see how it goes. By - she'll be excited. Smile

Thanks,

Jim

Back to top
View users profile Send private message
MauriceN

1st Responder
Premium Member

Joined: May 20, 2006
Posts: 989

1st Responders MVP Premium

PostPosted: Tue Jul 01, 2008 10:55 am    Post subject:
Reply with quote

Hello Jim,

If there are no more issues, I'm going to ask that this thread be permanently closed and locked.

All the best to you.


_________________
~Maurice Naggar
MS-MVP
Back to top
View users profile Send private message Visit posters website
jcrotinger

Trooper
Trooper


Joined: May 12, 2008
Posts: 34
Location: USA

PostPosted: Tue Jul 01, 2008 1:08 pm    Post subject:
Reply with quote

Hi Maurice,

There was one issue remaining - Spybot S&D still complains that the security center has been disabled. Aside from this, my wife is using the computer again with no problems.

Thanks - Jim

Back to top
View users profile Send private message
MauriceN

1st Responder
Premium Member

Joined: May 20, 2006
Posts: 989

1st Responders MVP Premium

PostPosted: Tue Jul 01, 2008 11:34 pm    Post subject:
Reply with quote

Hi Jim,
Download and Unzip to your Desktop: http://www.techsupportforum.com/sectools/ResetTeaTimer.zip
Double-click on ResetTeaTimer.bat to remove all entries set by TeaTimer.

[color=red]Logoff and Restart Windows for these changes to take effect.
You may now delete the ResetTeaTimer ZIP and folder on your desktop.
=
Download and Install Windows Defender by Microsoft (free) if you do not already have it:
http://www.microsoft.com/downloads/details.aspx?FamilyId=435BFCE7-DA2B-4A6A-AFA4-F7F14E605A0D
=
Next, go to Control Panel, then click (select) Secuity Center.
What does it show for Firewall,
Automatic Updates setting,
and for Virus Protection ?

Are any of them showing a Red icon?


_________________
~Maurice Naggar
MS-MVP
Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Trend Micro HijackThis Logs All times are GMT
Goto page Previous  1, 2, 3, 4
Page 4 of 4

 
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer