|
|
#11 (permalink) |
|
Gold Member
![]() Join Date: May 2006
Location: Oregon
Age: 18
Posts: 426
|
here's main.txt
http://myfreefilehosting.com/f/71cdde63ed_0.04MB and extra.txt http://myfreefilehosting.com/f/b5ce45ec21_0.03MB and in safe mode, it was taking way too long, it took 5 hours to scan 50,000 files, and there are over a million on this machine. |
|
|
|
|
|
#12 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,237
|
Can you check your links? They appear to be broken.
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. |
|
|
|
|
|
#14 (permalink) |
|
Gold Member
![]() Join Date: May 2006
Location: Oregon
Age: 18
Posts: 426
|
Hmmm. They worked fine for me, but I'll try a different site
main.txt http://www.mediafire.com/?unwtyrb0mgj extra.txt http://www.mediafire.com/?nmlymm32jjd |
|
|
|
|
|
#15 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,237
|
The links work fine for me now as well, must have been a temporary issue. I can see no signs of active malware in any of the logs you've provided, I suspect it's something else that's responsible for this. I'd like to know if an online scan is able to complete.
Please do a scan with Kaspersky Online Scanner Click on the Accept button and install any components it needs.
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. |
|
|
|
|
|
#16 (permalink) |
|
Gold Member
![]() Join Date: May 2006
Location: Oregon
Age: 18
Posts: 426
|
Sorry about taking so long. I ran it last night but there was a storm, and my surge protector switched when there was a surge (good to know that works
) anyways. I just tried to start it again, and it said "Starting Java applet has failed! Please go online to use this program." when it tried to update and install.Edit: Tried it several times with the same result. Edit 2: I jumped the gun, I tried it in a different instance of FF And I was able to update and start the scan. Last edited by thermophilis; 07-04-2008 at 08:58 AM. |
|
|
|
|
|
#17 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,237
|
No problems about the delay (I've done it to you a couple of times now, sorry
). I'll be interested to see the results.
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. |
|
|
|
|
|
#18 (permalink) |
|
Gold Member
![]() Join Date: May 2006
Location: Oregon
Age: 18
Posts: 426
|
KASPERSKY ONLINE SCANNER 7 REPORT
Friday, July 4, 2008 Operating System: Microsoft Windows XP Home Edition Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, July 04, 2008 07:57:56 Records in database: 912450 Scan settings Scan using the following database extended Scan archives yes Scan mail databases yes Scan area My Computer C:\ D:\ E:\ F:\ G:\ H:\ Scan statistics Files scanned 195529 Threat name 8 Infected objects 8 Suspicious objects 0 Duration of the scan 03:17:32 File name Threat name Threats count C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1D266616.dll Infected: Packed.Win32.Klone.k 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\24EB70CD.dll Infected: Trojan.Win32.BHO.g 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\367942E6.htm Infected: Exploit.HTML.IESlice.d 1 C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\7C51149E Infected: not-a-virus:AdWare.Win32.Virtumonde.dt 1 C:\Documents and Settings\Compaq_Owner\Application Data\Thunderbird\Profiles\fljdw6h5.default\Mail\Lo cal Folders\Junk Infected: Trojan-Spy.HTML.Fiffraud.n 1 C:\Program Files\Online Services\PeoplePC\ISP5900\Branding\ppal3ppc.exe Infected: not-a-virus:AdWare.Win32.Agent.aeh 1 F:\Eric\Stuff\Antivirus and Antispyware\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f 1 F:\Eric\Stuff\Game Maker 7[1].0.rar Infected: Trojan.Win32.Dialer.yz 1 The selected area was scanned. |
|
|
|
|
|
#19 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 21
Posts: 5,237
|
There are a few leftovers showing in the various scans, but nothing active. Nonetheless we can remove them.
Please click on Start -> Control Panel -> Add or Remove Programs. If WildTangent appears, click on it and click Remove. Please download ATF Cleaner by Atribune.
Please download the OTMoveIt2 by OldTimer.
This archive is also infected and I strongly suggest you delete it: F:\Eric\Stuff\Game Maker 7[1].0.rar That said, these would not be responsible for the problems you've been having. A software conflict or similar problem strikes me as the most likely suspect. I know that Malwarebytes didn't run normally in Safe Mode, but see if you can run any of your other scans such as A-squared in Safe Mode. If that works, we can narrow down the list of suspects.
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. Last edited by ceewi1; 07-06-2008 at 05:11 AM. |
|
|
|
|
|
#20 (permalink) |
|
Gold Member
![]() Join Date: May 2006
Location: Oregon
Age: 18
Posts: 426
|
ot move it:
C:\WINDOWS\wt\wtupdates\wtwebdriver\update_info moved successfully. C:\WINDOWS\wt\wtupdates\wtwebdriver moved successfully. C:\WINDOWS\wt\wtupdates\wtupdater moved successfully. C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files \install moved successfully. C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files \controlpanel moved successfully. C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23\files moved successfully. C:\WINDOWS\wt\wtupdates\WireControl\1.1.0.23 moved successfully. C:\WINDOWS\wt\wtupdates\WireControl moved successfully. C:\WINDOWS\wt\wtupdates\webd\4.1.1\install moved successfully. C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\update_in fo moved successfully. C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\legacy moved successfully. C:\WINDOWS\wt\wtupdates\webd\4.1.1\files\controlpa nel moved successfully. C:\WINDOWS\wt\wtupdates\webd\4.1.1\files moved successfully. C:\WINDOWS\wt\wtupdates\webd\4.1.1 moved successfully. C:\WINDOWS\wt\wtupdates\webd moved successfully. C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\install moved successfully. C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files\control panel moved successfully. C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19\files moved successfully. C:\WINDOWS\wt\wtupdates\DRM\3.2.0.19 moved successfully. C:\WINDOWS\wt\wtupdates\DRM moved successfully. C:\WINDOWS\wt\wtupdates moved successfully. C:\WINDOWS\wt\webdriver\4.1.1 moved successfully. C:\WINDOWS\wt\webdriver moved successfully. C:\WINDOWS\wt\updater moved successfully. C:\WINDOWS\wt moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{A49FEB7D-38B7-4C5C-B126-9C201E4BD0BD} moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{6C743BD3-A21D-4E58-9AAE-92A9D141061F} moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\{677FCD49-921A-40A7-977B-D979CE3119FC} moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine moved successfully. C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus moved successfully. File/Folder not found. < HKEY_CLASSES_ROOT\AppID\{323301C5-CB6B-490C-B59F-E7FAD4D69C93} > Registry key HKEY_CLASSES_ROOT\AppID\{323301C5-CB6B-490C-B59F-E7FAD4D69C93}\\ deleted successfully. < HKEY_USERS\PE_C_COMPAQ_OWNER\Software\Microsoft\Wi ndows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} > Registry key HKEY_USERS\PE_C_COMPAQ_OWNER\Software\Microsoft\Wi ndows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E}\\ not found. < HKEY_CLASSES_ROOT\Interface\{1FAD572E-1A3D-44D9-9C23-A87F922DA8C0} > Registry key HKEY_CLASSES_ROOT\Interface\{1FAD572E-1A3D-44D9-9C23-A87F922DA8C0}\\ deleted successfully. < HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866} > Registry key HKEY_CLASSES_ROOT\TypeLib\{7946205B-FEF7-494F-A64B-3E992A780866}\\ deleted successfully. < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\WildTangent CDA > Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Uninstall\WildTangent CDA\\ deleted successfully. < HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Logger.LogSess ion > Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Logger.LogSess ion\\ deleted successfully. < HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Logger.LogSess ion.1 > Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Logger.LogSess ion.1\\ deleted successfully. < HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A62FA99 E-922E-4ECA-A1D9-B54EF294A3CC} > Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A62FA99 E-922E-4ECA-A1D9-B54EF294A3CC}\\ deleted successfully. < HKEY_USERS\PE_C_COMPAQ_OWNER\AtlMon.ReusableComp.5 > Registry key HKEY_USERS\PE_C_COMPAQ_OWNER\AtlMon.ReusableComp.5 \\ not found. OTMoveIt2 by OldTimer - Version 1.0.4.3 log created on 07052008_231659 Okay, so I started in safe mode, and safe mode for some reason normally runs really slow, but today it was running REALLY slow, I logged into the admin account and an hour later it was still trying to log in. |
|
|
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Computer Restrictions After Virus Infection | Sucrose | Computer Security | 20 | 07-31-2006 11:31 PM |
| Wrong Or Not? | hells3000 | Computer Security | 2 | 04-04-2006 03:04 PM |
| Windows Media player Virus | Zinn | Computer Security | 21 | 03-26-2006 03:43 PM |
| My Computer is also sick! | beergoggles | Computer Security | 12 | 02-26-2006 09:51 PM |
| need help fast plz! | hells3000 | Computer Security | 23 | 10-03-2005 01:02 PM |