1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Unsure if its a virus - dll/win32/Microsoft problems

Discussion in 'Malware and Virus Removal Archive' started by paultess, 2013/12/11.

  1. 2013/12/20
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    Sorry about the delay I didn't notice yesterday that the file was too large.
    Paul
     
  2. 2013/12/20
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    Only Contributing Members can post attachments
     

  3. to hide this advert.

  4. 2013/12/20
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    I found that finally and contributed, I will be able to send them when account activated 1-2 days.
     
  5. 2013/12/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If you need to provide a screenshot...

    With the window open that you want to take the Screenshot of, press the Print Screen/SysRq Key (next to F12 on the keyboard).
    If you only want a screenshot of an active window within the main window press ALT+Print Screen/SysRq.

    Now open Microsoft Paint by pressing Start > All Programs > Accessories > Paint.

    This will open the Paint window.
    On the menu bar at the top left, click on Edit and select Paste. This will put your screenshot in the Paint window.

    Next, click File on the menu bar and click Save As.

    In the drop-down box that appears, where it shows File name replace the highlighted Untitled with a suitable name.
    In the Save as type box press the down arrow and select JPEG from the list of options.
    In the Save in box at the top press the down arrow and navigate to Desktop and select it then press Save at the bottom.

    Upload the file(s) here: http://www.sendspace.com/
    Click on Browse button and navigate to the file you want to upload.
    Click on Upload button.
    Click on FIRST Copy Link button and paste the link in your next reply.

    ===========================================

    [​IMG] Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following
    Code:
    :OTL
    SRV - File not found [Auto | Stopped] -- C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\17.2.0\ToolbarUpdater.exe -- (vToolbarUpdater17.2.0)
    DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\zwciwaol.sys -- (zwciwaol)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIMMP)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\SymIM.sys -- (SymIM)
    DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\SBREDrv.sys -- (SBRE)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
    DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
    DRV - File not found [Kernel | System | Stopped] -- C:\Windows\system32\drivers\hewfhhna.sys -- (hewfhhna)
    DRV - File not found [Kernel | On_Demand | Stopped] -- C:\Users\paultess\AppData\Local\Temp\catchme.sys -- (catchme)
    DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
    DRV - [2013/05/23 07:39:13 | 000,043,368 | ---- | M] (ThreatTrack Security) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\gfiark.sys -- (gfiark)
    DRV - [2013/11/10 10:26:03 | 000,037,664 | ---- | M] (AVG Technologies) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\avgtpx86.sys -- (avgtp)
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    O3 - HKLM\..\Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
    O15 - HKU\.DEFAULT\..Trusted Ranges: Range1 ([http] in Local intranet)
    O15 - HKU\S-1-5-18\..Trusted Ranges: Range1 ([http] in Local intranet)
    O15 - HKU\S-1-5-21-2410994966-3734587764-1746882321-1000\..Trusted Ranges: Range1 ([http] in Local intranet)
    [2013/12/08 17:25:38 | 000,269,216 | ---- | C] (AVAST Software) -- C:\Windows\System32\aswBoot.exe
    [2013/12/08 17:25:04 | 000,043,152 | ---- | C] (AVAST Software) -- C:\Windows\avastSS.scr
    [2013/12/08 17:23:34 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
    [2013/12/08 17:22:53 | 000,000,000 | ---D | C] -- C:\ProgramData\AVAST Software
    [2013/12/09 06:50:47 | 000,000,002 | RHS- | C] () -- C:\Windows\winstart.bat
    [2013/12/08 17:27:33 | 000,000,000 | ---D | M] -- C:\Users\paultess\AppData\Roaming\AVAST Software
    @Alternate Data Stream - 147 bytes -> C:\ProgramData\TEMP:07BF512B
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:98181191
    @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:373E1720
    
    :Services
    
    :Reg
    
    :Files
    C:\FRST
    
    :Commands
    [purity]
    [emptytemp]
    [emptyjava]
    [emptyflash]
    [Reboot]
    
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    NOTE. If for any reason OTL stalls (most likely at "killing processes..." step) run the fix from safe mode.

    Last scans...

    [​IMG] Download Security Check from here or here and save it to your Desktop.
    • Double-click SecurityCheck.exe
    • Follow the onscreen instructions inside of the black box.
    • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
    NOTE 1. If one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.
    NOTE 2 SecurityCheck may produce some false warning(s), so leave the results reading to me.


    [​IMG] Please download Farbar Service Scanner (FSS) and run it on the computer with the issue.
    • Make sure the following options are checked:
      • Internet Services
      • Windows Firewall
      • System Restore
      • Security Center
      • Windows Update
      • Windows Defender
      • Other Services
    • Press "Scan ".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.

    [​IMG] Download Temp File Cleaner (TFC)
    Alternate download: http://www.itxassociates.com/OT-Tools/TFC.exe
    • Double click on TFC.exe to run the program.
    • Click on Start button to begin cleaning process.
    • TFC will close all running programs, and it may ask you to restart computer.

    [​IMG] Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, click on List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
    • NOTE. If Eset won't find any threats, it won't produce any log.
     
  6. 2013/12/20
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
  7. 2013/12/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Delete your SecurityCheck file, disable AV program for the moment, download fresh file and try again.
     
  8. 2013/12/21
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    Same result.
     
  9. 2013/12/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Go ahead with other steps.
     
  10. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    After running the last cleaning(?) sets a number of shortcuts have become non-funtional, including the Torch server which has disappeared totally.

    One error message which appears when I click on an email link is:

    http://www.windowsbbscom/faq.php?faq=vb3_board_faq
    Application not found.

    Not sure if they were removed because they are a problem or if there is a problem since the scan? -cleaning?



    I would likie to wish you a Happy Holiday Season and thank you for your efforts so far.

    Paul
     
  11. 2013/12/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Same to you :)

    I need to see all logs.

    1. Replace not working shortcuts with new ones.
    2. Do you problem with ANY link in your email program?
     
  12. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    Hi...I have not run any of the new programs yet...I will today.
    All sorts of errors popping up - Java crashed, cant find data files, wont re-install- links not working in emails and on desktop - 'unable to find data files'. - itunes has stopped working - windows has closed itunes to prevent damage - netflix, 'unable to find files, re-install.'

    No apparent problems with email other than linls no longer working.
    ALL this happened AFTER Post #20 was implemented.
    Paul
     
  13. 2013/12/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Post #20?
    That's OTL which is just a scanner. It doesn't make any changes.
     
  14. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    I ran 3 - adwarecleaner; OTP and an HKEY, which deleted a lot - I don't know enough to say good deletions or not.
    This was before I tried to run Security check.
     
  15. 2013/12/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't see anything in OTL fix which could cause this kind of problems.

    Give me more details as to what exactly is not working and what is the exact error message.
    Please be specific.
     
  16. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    I have not tested everything, just some I use fairly regularly. I will add a couple more after this is sent.
     

    Attached Files:

  17. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    It seems to be all links in email.
    I cant see a connection between these, other programs seem to work perfectly.
    One thing, itunes was giving me this message then started to work fine - nothing done to the program, just clicked it again...no idea at all. Paul
     

    Attached Files:

  18. 2013/12/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    What email program do you use?
     
  19. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    Some help

    Links are mostly Torch - Torch has disappeared
     
  20. 2013/12/23
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I'm not familiar with Torch at all.
    Did you try to reinstall it?
    How do you know links in your email program don't work since you just said the program is gone?
     
  21. 2013/12/23
    paultess

    paultess Inactive Thread Starter

    Joined:
    2013/12/11
    Messages:
    50
    Likes Received:
    0
    email works apparently perfectly, any link in email does not work - generates the message I showed you.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.