|
|
|
|
#1 (permalink) |
|
Platinum Member
![]() Join Date: Dec 2007
Location: Garden Grove CA
Age: 18
Posts: 811
|
Thats fine Respital
![]() I'll get whatever help I can get whenever I can get it. My computer is at least in working condition now
__________________
Mike Pics of my rig HERE Case:Lian Li with Swiftek apogee watercooling CPU: Intel Q6600 (2.4 GHz) Video: NVIDIA GeForce 8800GTX BFG OC Edition. LG 23" 1080HD and Sharp 19" RAM/Storage:4GB Kingston Hyper X DDR2/320GB(7,200RPM) an 160GB(10,000 RPM) internals, and 320GB External Sound Card: Creative X-Fi XtremeGamer Fatality OS: Windows Vista Home Premium (64-bit) M-B-Photos Winner of Photo Tournaments: Automobiles and Birds |
|
|
|
|
|
#3 (permalink) | |
|
Bronze Member
![]() Join Date: Dec 2007
Posts: 62
|
A CF script will be able to clean out 99% of the files Kespersky found.
The problem is there is a rootkit present which could protect or repopulate an infection. Some of the infections found already have been fixed with ComboFix and HJT, and are quarantined or in a back-up folder. Here's the CF Script I came up with. Quote:
|
|
|
|
|
|
|
#4 (permalink) |
|
Folding@Home
![]() Join Date: Aug 2007
Location: Northern Cali
Age: 29
Posts: 8,694
|
Let Buzz handle it, Cohen.
__________________
Core i7 920 @ 2.66 GHz || Cooler Master V8 || Foxconn BloodRage X58|| 896MB EVGA GTX 260 (55nm)|| 6GB G Skill DDR3 @ 1600MHz|| 2X 300GB WD Velociraptors (RAID 0) || 1TB Hitachi Deskstar || Cooler Master HAF 932 || 620W Corsair HX PSU || Windows 7 Ultimate/Vista Ultimate x64/Windows XP Pro FOLDING FOR THE GOOD OF MANKIND:F@H Team 44358 |
|
|
|
|
|
#5 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 22
Posts: 5,418
|
As some of you have noticed, my activity here has been limited recently and is likely to stay that way for the foreseeable future. It's rather sad to see what's happening with these threads, though.
I notice you have the Freeze.com Toolbar installed. This is considered by many to be adware. See http://www.emsisoft.com/en/malware/?...ze.com+Toolbar for more information. I suggest you remove it. To do so click on Start -> Control Panel -> Add or Remove Programs. If Freeze.com Toolbar appears, click on it and click Remove. Once done, delete the following folder: C:\Program Files\Freeze.com Toolbar Please download SDFix and save it to your Desktop but do not run it yet. Please download ATF Cleaner by Atribune.
Double click SDFix.exe and it will extract the files to C:\SDFix You may wish to print out these instructions or copy them to a notepad document since you will be unable to access the Internet while in Safe Mode to read from this site. Please then reboot your computer in Safe Mode (tap F8 just before Windows starts to load and select Safe Mode from the list).
Please plug drive H: into your system if it is an external drive.
Do NOT mouse-click ComboFix's window while it is running. That may cause it to stall. Also, please do NOT adjust your time format while ComboFix is running. The name of the following file has not been completely displayed, presumably due to this forum's language filter. Please locate and delete it (the **** will correspond to a swear word): C:\Documents and Settings\chevy\Incomplete\T-3545425-we dont give ****.mp3 Please click on Start -> Run. Type the following command and click OK: notepad C:\WINDOWS\winstart.bat This should popup a Notepad document showing the contents of winstart.bat. Please post the contents in your next reply. Please post:
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. |
|
|
|
|
|
#6 (permalink) |
|
Moderator
![]() Join Date: Dec 2005
Location: Melbourne, Australia
Age: 22
Posts: 5,418
|
It seems that the CFScript file has been unsuccessful. I've attached it to this post. Please save it to your Desktop and drag it into ComboFix as before, then post the log generated.
Also, please click on Start -> Run. Type the following command and click OK: notepad C:\WINDOWS\winstart.bat This should popup a Notepad document showing the contents of winstart.bat. Please post the contents in your next reply.
__________________
CPU: Core 2 Duo E6600 / MOBO: Gigabyte 965P-DS3 / GPU: Gigabyte HD4870 RAM: 2GB G.Skill F2-6400CL4D-2GBPK / HDD: 2TB Total HDD / PSU: Antec NeoPower 480W Cheap PSUs - 2% of system costs, responsible for 28% of system deaths As Sealed Stick was removed, lost or damaged, it shall be out of warranty validity. - The "Warranty void if removed" sticker on numerous CoolerMaster PSUs. |
|
|
|
|
|
#7 (permalink) |
|
Bronze Member
![]() Join Date: Dec 2007
Posts: 62
|
Cohen, lol..... that's a ComboFix script to clean out the infected files for MBGraphics.
If you have a close look and compare to the Kaspersky scan performed you will find it lists the infected files. Geez you're swift, I posted that not 2 minutes ago. <EDIT> I refrained from giving detailed instructions on running the script.... Just thought it could save some one time</EDIT> |
|
|
|
|
|
#8 (permalink) | |
|
Diamond Member
![]() Join Date: Jan 2008
Location: Melbourne, Australia
Age: 15
Posts: 8,361
|
Quote:
Sorry.
__________________
Cohen |
|
|
|
|
|
|
#10 (permalink) |
|
Bronze Member
![]() Join Date: Dec 2007
Posts: 62
|
Here are alternative links to MBAM (MalwareBytes' Anti-Malware)
This one starts the downloader: http://www.besttechie.net/tools/mbam-setup.exe From Major Geeks: http://www.majorgeeks.com/Malwarebyt...are_d5756.html |
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Virus/Adware problems | PunterCam | Computer Security | 2 | 03-18-2008 07:21 PM |