| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 107872 | 2010-03-04 21:26:00 | Personal Security | NZHawk (4093) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 864123 | 2010-03-04 21:26:00 | Windows Vista Home Basic infected with Personal Security can't open Malwarebytes Googled removal but procedures didn't work anyone have a fool proof way of getting rid of Personal Security Thank you |
NZHawk (4093) | ||
| 864124 | 2010-03-04 21:28:00 | Do a System Restore to before you got it...if you don't know when, just try going back further and further until you get it right. Mind you, you could have already tried that? |
FAB (6923) | ||
| 864125 | 2010-03-04 22:10:00 | Great suggestion - no I hadn't tried that. Will give it a go. |
NZHawk (4093) | ||
| 864126 | 2010-03-04 22:27:00 | Darn - no system restore points! any other suggestions |
NZHawk (4093) | ||
| 864127 | 2010-03-04 22:37:00 | Run combofix (download.bleepingcomputer.com). Post the log here when it's done. |
wratterus (105) | ||
| 864128 | 2010-03-04 22:47:00 | having to run in safe mode as will not run in normal mode. | NZHawk (4093) | ||
| 864129 | 2010-03-04 22:49:00 | Forget system restore - malware infests them. 1)Safe mode 2)Hijackthis 3)Spybot, malware Bytes, NOD32 Works every time. |
pctek (84) | ||
| 864130 | 2010-03-04 22:51:00 | Thats alright, it still does the job, or at least hopefully enough for malwarebytes to work properly. | wratterus (105) | ||
| 864131 | 2010-03-04 23:03:00 | combofix log report: ComboFix 10-03-04 . 01 - sue 05/03/2010 11:48:58 . 1 . 2 - x86 MINIMAL Microsoft® Windows Vista Home Basic 6 . 0 . 6001 . 1 . 1252 . 64 . 1033 . 18 . 3545 . 3180 [GMT 13:00] Running from: c:\users\sue\Desktop\2 Cleaning Tools\ComboFix . exe SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . c:\$recycle . bin\S-1-5-21-2347180839-3205931739-3509662-500 c:\$recycle . bin\S-1-5-21-3883055561-1211494065-617990207-500 c:\program files\PersSecurity c:\program files\PersSecurity\psecurity . exe c:\windows\bill103 . exe c:\windows\ligh c:\windows\system32\oem6 . inf c:\windows\system32\Vb40032 . dll . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Service_srvoko6 ((((((((((((((((((((((((( Files Created from 2010-02-04 to 2010-03-04 ))))))))))))))))))))))))))))))) . 2010-03-04 22:54 . 2010-03-04 22:54 -------- d-----w- c:\users\Default\AppData\Local\temp 2010-03-04 22:54 . 2010-03-04 22:57 -------- d-----w- c:\users\sue\AppData\Local\temp 2010-03-04 20:27 . 2006-06-19 00:01 69632 ----a-w- c:\windows\system32\ztvcabinet . dll 2010-03-04 20:27 . 2006-05-25 02:52 162304 ----a-w- c:\windows\system32\ztvunrar36 . dll 2010-03-04 20:27 . 2005-08-25 12:50 77312 ----a-w- c:\windows\system32\ztvunace26 . dll 2010-03-04 20:27 . 2003-02-02 07:06 153088 ----a-w- c:\windows\system32\UNRAR3 . dll 2010-03-04 20:27 . 2002-03-05 12:00 75264 ----a-w- c:\windows\system32\unacev2 . dll 2010-03-04 20:27 . 2010-03-04 20:27 -------- d-----w- c:\programdata\Simply Super Software 2010-03-04 20:27 . 2010-03-04 20:27 -------- d-----w- c:\program files\Trojan Remover 2010-03-04 20:27 . 2010-03-04 20:27 -------- d-----w- c:\users\sue\AppData\Roaming\Simply Super Software 2010-03-04 20:27 . 2010-03-04 20:27 -------- d-----w- c:\users\sue\AppData\Local\Adobe 2010-03-03 22:20 . 2010-03-03 22:20 -------- d-----w- c:\users\sue\AppData\Roaming\GlarySoft 2010-03-03 22:17 . 2010-03-03 22:17 -------- d-----w- c:\program files\Glary Utilities 2010-03-03 21:55 . 2010-03-03 21:55 206848 ----a-w- c:\users\sue\AppData\Local\rdr_1267653324 . exe 2010-03-03 21:46 . 2010-03-03 21:46 -------- d-----w- c:\users\sue\AppData\Roaming\Malwarebytes 2010-03-03 21:46 . 2010-01-07 03:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy . sys 2010-03-03 21:46 . 2010-03-03 21:46 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware 2010-03-03 21:46 . 2010-03-03 21:46 -------- d-----w- c:\programdata\Malwarebytes 2010-03-03 21:46 . 2010-01-07 03:07 19160 ----a-w- c:\windows\system32\drivers\mbam . sys 2010-03-03 01:25 . 2010-02-11 18:42 162512 ----a-w- c:\windows\system32\drivers\aswSP . sys 2010-03-03 01:25 . 2010-02-11 18:39 23376 ----a-w- c:\windows\system32\drivers\aswRdr . sys 2010-03-03 01:25 . 2010-02-11 18:38 19024 ----a-w- c:\windows\system32\drivers\aswFsBlk . sys 2010-03-03 01:25 . 2010-02-11 18:42 46672 ----a-w- c:\windows\system32\drivers\aswTdi . sys 2010-03-03 01:25 . 2010-02-11 18:38 51792 ----a-w- c:\windows\system32\drivers\aswMonFlt . sys 2010-03-03 01:24 . 2010-02-11 18:53 38848 ----a-w- c:\windows\system32\avastSS . scr 2010-03-03 01:24 . 2010-02-11 18:53 153184 ----a-w- c:\windows\system32\aswBoot . exe 2010-03-03 01:24 . 2010-03-03 01:24 -------- d-----w- c:\programdata\Alwil Software 2010-03-03 01:24 . 2010-03-03 01:24 -------- d-----w- c:\program files\Alwil Software 2010-03-02 22:41 . 2010-03-02 22:41 -------- d-----w- c:\program files\Common Files\PersSecurityUninstall 2010-03-02 22:08 . 2010-03-02 22:08 -------- d-----w- c:\windows\system32\EventProviders 2010-03-02 21:35 . 2010-03-02 21:35 0 ----a-w- c:\users\sue\AppData\Local\rdr_1267565708 . exe 2010-03-02 21:30 . 2010-03-02 21:30 207360 ----a-w- c:\users\sue\AppData\Local\rdr_1267565392 . exe 2010-02-23 19:23 . 2010-01-23 09:44 2048 ----a-w- c:\windows\system32\tzres . dll 2010-02-23 19:23 . 2010-01-25 12:48 472576 ----a-w- c:\windows\system32\secproc_isv . dll 2010-02-23 19:23 . 2010-01-25 12:48 472064 ----a-w- c:\windows\system32\secproc . dll 2010-02-23 19:23 . 2010-01-25 08:35 346624 ----a-w- c:\windows\system32\RMActivate_ssp_isv . exe 2010-02-23 19:23 . 2010-01-25 08:35 523776 ----a-w- c:\windows\system32\RMActivate_isv . exe 2010-02-23 19:23 . 2010-01-25 08:34 511488 ----a-w- c:\windows\system32\RMActivate . exe 2010-02-23 19:23 . 2010-01-25 08:34 347136 ----a-w- c:\windows\system32\RMActivate_ssp . exe 2010-02-23 19:23 . 2010-01-25 12:48 151040 ----a-w- c:\windows\system32\secproc_ssp_isv . dll 2010-02-23 19:23 . 2010-01-25 12:48 151040 ----a-w- c:\windows\system32\secproc_ssp . dll 2010-02-23 19:23 . 2010-01-25 12:45 329216 ----a-w- c:\windows\system32\msdrm . dll 2010-02-10 01:15 . 2009-12-08 20:52 897624 ----a-w- c:\windows\system32\drivers\tcpip . sys 2010-02-10 01:15 . 2009-12-11 12:07 301568 ----a-w- c:\windows\system32\drivers\srv . sys 2010-02-10 01:15 . 2009-12-11 12:07 98304 ----a-w- c:\windows\system32\drivers\srvnet . sys 2010-02-10 01:15 . 2009-12-08 20:36 3600472 ----a-w- c:\windows\system32\ntkrnlpa . exe 2010-02-10 01:15 . 2009-12-08 20:36 3548760 ----a-w- c:\windows\system32\ntoskrnl . exe 2010-02-10 01:12 . 2009-12-28 12:35 11776 ----a-w- c:\windows\system32\tsbyuv . dll 2010-02-10 01:12 . 2009-12-28 12:35 1314816 ----a-w- c:\windows\system32\quartz . dll 2010-02-10 01:12 . 2009-12-28 12:32 22528 ----a-w- c:\windows\system32\msyuv . dll 2010-02-10 01:12 . 2009-12-28 12:32 31744 ----a-w- c:\windows\system32\msvidc32 . dll 2010-02-10 01:12 . 2009-12-28 12:32 123904 ----a-w- c:\windows\system32\msvfw32 . dll 2010-02-10 01:12 . 2009-12-28 12:32 13312 ----a-w- c:\windows\system32\msrle32 . dll 2010-02-10 01:12 . 2009-12-28 12:31 82944 ----a-w- c:\windows\system32\mciavi32 . dll 2010-02-10 01:12 . 2009-12-28 12:31 50176 ----a-w- c:\windows\system32\iyuv_32 . dll 2010-02-10 01:12 . 2009-12-28 12:28 91136 ----a-w- c:\windows\system32\avifil32 . dll 2010-02-10 01:12 . 2009-12-28 12:28 65024 ----a-w- c:\windows\system32\avicap32 . dll 2010-02-10 01:12 . 2009-12-04 16:12 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10 . sys 2010-02-10 01:12 . 2009-12-04 16:12 105472 ----a-w- c:\windows\system32\drivers\mrxsmb . sys . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))) )) . 2010-03-02 21:29 . 2009-06-14 23:02 -------- d-----w- c:\users\sue\AppData\Roaming\Skype 2010-03-02 19:45 . 2009-06-14 23:45 -------- d-----w- c:\users\sue\AppData\Roaming\skypePM 2010-02-24 20:03 . 2009-06-12 00:41 71208 ----a-w- c:\users\sue\AppData\Local\GDIPFONTCACHEV1 . DAT 2010-02-10 14:18 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail 2010-02-03 19:35 . 2009-06-14 23:02 -------- d-----w- c:\program files\Google 2010-02-03 19:28 . 2010-02-03 19:28 509552 ----a-w- c:\programdata\Google\Google Toolbar\Update\gtb575F . tmp . exe 2010-01-20 19:51 . 2009-06-05 06:01 -------- d-----w- c:\program files\Microsoft Silverlight 2010-01-18 09:30 . 2009-06-05 05:56 -------- d-----w- c:\program files\Dell DataSafe Online 2010-01-18 09:29 . 2009-07-28 05:49 8653312 ----a-w- c:\users\sue\AppData\Roaming\DataSafeDotNet . exe 2010-01-18 09:29 . 2009-07-28 05:49 8653312 ----a-w- c:\users\sue\AppData\Roaming\DataSafeDotNet . exe 2010-01-18 09:21 . 2009-06-05 05:48 -------- d-----w- c:\program files\Common Files\Adobe 2010-01-02 06:38 . 2010-01-21 19:57 916480 ----a-w- c:\windows\system32\wininet . dll 2010-01-02 06:32 . 2010-01-21 19:57 71680 ----a-w- c:\windows\system32\iesetup . dll 2010-01-02 06:32 . 2010-01-21 19:57 109056 ----a-w- c:\windows\system32\iesysprep . dll 2010-01-02 04:57 . 2010-01-21 19:57 133632 ----a-w- c:\windows\system32\ieUnatt . exe 2009-06-05 06:07 . 2009-06-05 06:07 75 --sh--r- c:\windows\CT4CET . bin 2009-06-05 08:08 . 2009-06-05 08:06 8192 --sha-w- c:\windows\Users\Default\NTUSER . DAT . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar . exe" [2008-01-21 1233920] "swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNo tifier . exe" [2009-06-14 39408] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr . exe" [2008-12-03 3882312] "Skype"="c:\program files\Skype\\Phone\Skype . exe" [2009-10-09 25623336] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG . exe" [2008-01-21 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui . exe" [2008-01-21 1008184] "Apoint"="c:\program files\DellTPad\Apoint . exe" [2009-04-01 217088] "SysTrayApp"="c:\program files\IDT\WDM\sttray . exe" [2009-04-01 483428] "IgfxTray"="c:\windows\system32\igfxtray . exe" [2009-04-01 141848] "HotKeysCmds"="c:\windows\system32\hkcmd . exe" [2009-04-01 173592] "Persistence"="c:\windows\system32\igfxpers . exe" [2009-04-01 150552] "Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY . exe" [2008-12-22 3810304] "IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif . exe" [2008-05-07 178712] "Dell DataSafe Online"="c:\program files\Dell DataSafe Online\DataSafeOnline . exe" [2009-11-13 1807600] "PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv . exe" [2008-05-23 128296] "Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell2 . exe" [2009-01-09 405639] "mcagent_exe"="c:\program files\McAfee . com\Agent\mcagent . exe" [2009-10-28 1218008] "dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd . exe" [2009-06-03 206064] "SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate . exe" [2006-10-24 210472] "PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt . exe" [2007-10-11 29984] "IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch . exe" [2007-10-11 46368] "PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg . exe" [2007-08-30 328992] "BrMfcWnd"="c:\program files\Brother\Brmfcmon\BrMfcWnd . exe" [2008-02-18 1089536] "ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen . exe" [2007-12-21 86016] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9 . 0\Reader\Reader_sl . exe" [2009-12-21 35760] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1 . 0\AdobeARM . exe" [2009-12-11 948672] "TrojanScanner"="c:\program files\Trojan Remover\Trjscan . exe" [2009-10-17 1070984] c:\users\sue\AppData\Roaming\Microsoft\Windows\Sta rt Menu\Programs\Startup\ Dell Dock . lnk - c:\program files\Dell\DellDock\DellDock . exe [2009-2-28 1316192] c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ Dell Remote Access . lnk - c:\windows\Installer\{F66A31D9-7831-4FBA-BA02-C411C0047CC5}\NewShortcut4_F66A31D978314FBABA02C41 1C0047CC5 . exe [2009-6-14 53248] [HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\GoToAssist] 2009-06-05 05:50 10536 ----a-w- c:\program files\Citrix\GoToAssist\514\g2awinlogon . dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "mixer"=wdmaud . drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\mcmscsvc] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\MCODS] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\Wdf01000 . sys] @="Driver" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AntiVirusOverride"="" "FirewallOverride"="" R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate . exe [2010-02-03 135664] R3 PCD5SRVC{3F6A8B78-EC003E00-05040104};PCD5SRVC{3F6A8B78-EC003E00-05040104} - PCDR Kernel Mode Service Helper Driver;c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC . pk ms [2008-11-04 22904] S1 aswSP;aswSP; [x] S1 o6ko;Connections Access Hook;c:\windows\system32\drivers\o6ko . sys [2008-01-21 32768] S2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileReposi tory\stwrt . inf_f6ef8056\aestsrv . exe [2009-04-01 81920] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\as wMonFlt . sys [2010-02-11 51792] S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin . exe [2008-12-18 155648] S2 yksvc;Marvell Yukon Service;RUNDLL32 . EXE ykx32coinst,serviceStartProc [x] S3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\DRIVERS\CtClsFlt . sys [2008-12-31 144128] S3 OA009Ufd;Creative Camera OA009 Upper Filter Driver;c:\windows\system32\DRIVERS\OA009Ufd . sys [2009-03-05 133632] S3 OA009Vid;Creative Camera OA009 Function Driver;c:\windows\system32\DRIVERS\OA009Vid . sys [2009-03-19 271552] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc netsvc6 REG_MULTI_SZ srvoko6 . Contents of the 'Scheduled Tasks' folder 2010-03-04 c:\windows\Tasks\GlaryInitialize . job - c:\program files\Glary Utilities\initialize . exe [2010-03-03 10:01] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineCore . job - c:\program files\Google\Update\GoogleUpdate . exe [2010-02-03 19:35] 2010-03-04 c:\windows\Tasks\GoogleUpdateTaskMachineUA . job - c:\program files\Google\Update\GoogleUpdate . exe [2010-02-03 19:35] 2010-03-04 c:\windows\Tasks\User_Feed_Synchronization-{A5C6C626-110D-4778-897C-888DC2D06460} . job - c:\windows\system32\msfeedssync . exe [2010-01-21 04:56] . . ------- Supplementary Scan ------- . uStart Page = about:blank IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL . EXE/3000 IE: Google Sidewiki . . . - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6 FF0C6D236BF8 . dll/cmsidewiki . html . - - - - ORPHANS REMOVED - - - - AddRemove-PersSecurity - c:\program files\PersSecurity\psecurity . exe ************************************************** ************************ catchme 0 . 3 . 1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www . gmer . net Rootkit scan 2010-03-05 11:56 Windows 6 . 0 . 6001 Service Pack 1 NTFS scanning hidden processes . . . scanning hidden autostart entries . . . scanning hidden files . . . scan completed successfully hidden files: 0 ************************************************** ************************ [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\P CD5SRVC{3F6A8B78-EC003E00-05040104}] "ImagePath"="\??\c:\progra~1\DELLSU~1\HWDiag\bin\PCD5SRVC . pkms" . ------------------------ Other Running Processes ------------------------ . c:\windows\System32\DriverStore\FileRepository\stw rt . inf_f6ef8056\STacSV . exe c:\windows\System32\WLTRYSVC . EXE c:\windows\System32\bcmwltry . exe c:\program files\Alwil Software\Avast5\AvastSvc . exe c:\program files\Common Files\Dell\Advanced Networking Service\hnm_svc . exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon . exe c:\progra~1\COMMON~1\McAfee\McProxy\McProxy . exe c:\progra~1\McAfee\VIRUSS~1\mcshield . exe c:\program files\McAfee\MPF\MPFSrv . exe c:\program files\McAfee\MSK\MskSrver . exe c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort . exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC . EXE c:\windows\system32\RUNDLL32 . EXE c:\program files\Canon\CAL\CALMAIN . exe c:\windows\system32\WUDFHost . exe c:\progra~1\McAfee\MSC\mcmscsvc . exe c:\progra~1\mcafee . com\agent\mcagent . exe c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM . exe c:\windows\system32\igfxsrvc . exe c:\program files\Dell Remote Access\ezi_ra . exe c:\program files\Windows Media Player\wmpnetwk . exe c:\program files\Brother\ControlCenter3\brccMCtl . exe c:\program files\Brother\Brmfcmon\BrMfcmon . exe c:\windows\system32\msiexec . exe c:\progra~1\McAfee\VIRUSS~1\mcsysmon . exe c:\program files\Common Files\mcafee\mna\mcnasvc . exe c:\program files\Dell Support Center\bin\sprtsvc . exe c:\\?\c:\windows\system32\wbem\WMIADAP . EXE . ************************************************** ************************ . Completion time: 2010-03-05 12:02:39 - machine was rebooted ComboFix-quarantined-files . txt 2010-03-04 23:02 Pre-Run: The system cannot find message text for message number 0x2379 in the message file for Application . Post-Run: 199,316,127,744 bytes free - - End Of File - - 2F34F43D90C147BB2280D4B677CD83C4 |
NZHawk (4093) | ||
| 864132 | 2010-03-04 23:12:00 | Great, looks like it got the bulk of PSecurity. Try malwarebytes now. |
wratterus (105) | ||
| 1 2 | |||||