1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Following instructions to post my FARBAR results here

Discussion in 'Malware and Virus Removal Archive' started by blakston6286, 2015/08/09.

  1. 2015/08/19
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    Here is the result of Security Check.exe

    Results of screen317's Security Check version 1.007
    Windows Vista Service Pack 2 x64 (UAC is disabled!)
    Internet Explorer 9
    Internet Explorer 8
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    avast! Antivirus
    Antivirus up to date!
    `````````Anti-malware/Other Utilities Check:`````````
    MVPS Hosts File
    Java 8 Update 31
    Java version 32-bit out of Date!
    Adobe Flash Player 18.0.0.232
    Adobe Reader XI
    Mozilla Firefox 39.0.3 Firefox out of Date!
    ````````Process Check: objlist.exe by Laurent````````
    AVAST Software Avast AvastSvc.exe
    AVAST Software Avast ng vbox\AvastVBoxSVC.exe
    AVAST Software Avast AvastUI.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 0 %
    ````````````````````End of Log``````````````````````
     
  2. 2015/08/19
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    Here is the result of the Farbar Service Scanner:

    Farbar Service Scanner Version: 26-07-2015
    Ran by DreamChamber (administrator) on 19-08-2015 at 17:26:23
    Running from "C:\Users\DreamChamber\Desktop "
    Microsoft® Windows Vista™ Home Premium Service Pack 2 (X64)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Google.com is accessible.
    Yahoo.com is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============

    System Restore Policy:
    ========================


    Security Center:
    ============


    Windows Update:
    ============

    Windows Autoupdate Disabled Policy:
    ============================


    Windows Defender:
    ==============
    WinDefend Service is not running. Checking service configuration:
    The start type of WinDefend service is set to Demand. The default start type is Auto.
    The ImagePath of WinDefend service is OK.
    The ServiceDll of WinDefend service is OK.


    Windows Defender Disabled Policy:
    ==========================
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
    "DisableAntiSpyware "=DWORD:1


    Other Services:
    ==============


    File Check:
    ========
    C:\Windows\System32\nsisvc.dll => File is digitally signed
    C:\Windows\System32\drivers\nsiproxy.sys => File is digitally signed
    C:\Windows\System32\dhcpcsvc.dll => File is digitally signed
    C:\Windows\System32\drivers\afd.sys => File is digitally signed
    C:\Windows\System32\drivers\tdx.sys => File is digitally signed
    C:\Windows\System32\Drivers\tcpip.sys => File is digitally signed
    C:\Windows\System32\dnsrslvr.dll => File is digitally signed
    C:\Windows\System32\mpssvc.dll => File is digitally signed
    C:\Windows\System32\bfe.dll => File is digitally signed
    C:\Windows\System32\drivers\mpsdrv.sys => File is digitally signed
    C:\Windows\System32\SDRSVC.dll => File is digitally signed
    C:\Windows\System32\vssvc.exe => File is digitally signed
    C:\Windows\System32\wscsvc.dll => File is digitally signed
    C:\Windows\System32\wbem\WMIsvc.dll => File is digitally signed
    C:\Windows\System32\wuaueng.dll => File is digitally signed
    C:\Windows\System32\qmgr.dll => File is digitally signed
    C:\Windows\System32\es.dll => File is digitally signed
    C:\Windows\System32\cryptsvc.dll => File is digitally signed
    C:\Program Files\Windows Defender\MpSvc.dll => File is digitally signed
    C:\Windows\System32\ipnathlp.dll => File is digitally signed
    C:\Windows\System32\iphlpsvc.dll => File is digitally signed
    C:\Windows\System32\svchost.exe => File is digitally signed
    C:\Windows\System32\rpcss.dll => File is digitally signed


    **** End of log ****
     

  3. to hide this advert.

  4. 2015/08/19
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    OK...very weird...I ran the Temporary File Cleaner.

    I actually ran it 2 times because the first time I ran it it hung up after going thru the beginning process it stopped responding . The upper bar of the window actually said that it was (not responding).
    I waited for the first process to start responding but after 15 minutes I guessed that it was kind of stuck.

    So... I right clicked the icon and ran the file as an administrator.
    When the new window opened it must have goosed the original window because it went out of the (not responding) mode and both windows started running .
    The first process had a lot of bytes in all the categories. But the second running had even higher bytes in many categories and 0 bytes in many categories that the first running had high bytes in...very confusing.

    I tried to copy and paste when the processes were finished but a reboot request appeared and prevented me from any action but clicking on it's OK button.

    Thinking that after the reboot I would have the logs on my desktop I waited for my computer to finish rebooting but no log files or results appeared...any idea where I can go to recover those results????
     
    Last edited: 2015/08/19
  5. 2015/08/19
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    Well.... I downloaded the Sophos Virus Removal tool the install Wizard appeared and I followed the instructions.

    When I clicked on Finish I waited for something to open up but nothing ever appeared.

    So I clicked on the Icon and all I get is a re installation and then an error message. No Scan options ever appear...Just error 1606. Could not access network location data. Tried to run it a few more times and I got the same message over and over.
     
    Last edited: 2015/08/19
  6. 2015/08/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run this instead of Sophos...

    Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Click on "Run ESET Online Scanner" button.
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
     
  7. 2015/08/19
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    ESET is running. So far it has listed two potential threats as follows.... a variant of Win32/Toolbar.Conduit H potentially unwanted application.... is appearing twice.
    Are these some things that I will want to clean out after the ESET is done or should I simply leave the results to stand and take no actions????
     
    Last edited: 2015/08/19
  8. 2015/08/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    If you didn't change Eset setting those findings should be cleaned by default.
     
  9. 2015/08/19
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    OK Good!!
    I will post the results as instructed when the process is finished.
    I have over 400,000 files on my computer so everything takes awhile to complete.
     
  10. 2015/08/19
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No rush.
     
  11. 2015/08/20
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    OK...Here is the results you asked for of the ESET Scan...

    C:\Program Files (x86)\NCH Software\ExpressZip\expresszip.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application cleaned by deleting - quarantined
    C:\Program Files (x86)\NCH Software\ExpressZip\expresszipsetup_v2.15.exe a variant of Win32/Toolbar.Conduit.H potentially unwanted application deleted - quarantined
    C:\Users\DreamChamber\Desktop\STUFF\Various Media players\KMPlayer_3-6-0-87.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application deleted - quarantined
    C:\Users\DreamChamber\Documents\Downloads\Download App\WinZipRegistryOptimizer.exe a variant of Win32/OpenInstall potentially unwanted application cleaned by deleting - quarantined
     
  12. 2015/08/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    [​IMG] Update Firefox to the current version.

    [​IMG] Update your Java version here: http://www.java.com/en/download/manual.jsp
    Alternate download: http://www.filehippo.com/search?q=java

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.
    Note 2: If you're running 64-bit system make sure you install BOTH, 32-bit and 64-bit Java.

    =========================================

    Your computer is clean [​IMG]

    1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
    This is a very crucial step so make sure you don't skip it.
    Download [​IMG]DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

    Double-click Delfix.exe to start the tool.
    Make sure the following items are checked:
    • Activate UAC (optional; some users prefer to keep it off)
    • Remove disinfection tools
    • Create registry backup
    • Purge System Restore
    • Reset system settings
    Now click "Run" and wait patiently.
    Once finished a logfile will be created. You don't have to attach it to your next reply.

    2. Make sure Windows Updates are current.

    3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    4. Check if your browser plugins are up to date.
    Firefox - https://www.mozilla.org/en-US/plugincheck/
    other browsers: https://browsercheck.qualys.com/ (click on "Scan without installing plugin" and then on "Scan now ")

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    11. Read:
    How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
    Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
    About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

    12. Please, let me know, how your computer is doing.
     
  13. 2015/08/20
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    Even though you said it was not necessary I included the log file to show you what was deleted. with Delfix.
    I will now run all the malware tools you instructed. Looks like the first set of tools you had me run in the proper order..Do you want any of the results?

    My computer actually seems to be running lots quicker now. So I will see when I finish all you recommend.
    I have already done the Java and Firefox upgrade.

    Thank you for the incredible lineup of powerful Malware and virus removals.

    I will read your instructions on how to maintain a clean computer.

    Be back shortly
     
  14. 2015/08/20
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    # DelFix v1.011 - Logfile created 20/08/2015 at 16:10:00
    # Updated 18/08/2015 by Xplode
    # Username : DreamChamber - DREAMCHAMBER-PC
    # Operating System : Windows (TM) Vista Home Premium Service Pack 2 (64 bits)

    ~ Activating UAC ... OK

    ~ Removing disinfection tools ...

    Deleted : C:\Qoobox
    Deleted : C:\FRST
    Deleted : C:\AdwCleaner
    Deleted : C:\ComboFix.txt
    Deleted : C:\Users\DreamChamber\Desktop\esetsmartinstaller_enu.exe
    Deleted : C:\Users\DreamChamber\Desktop\FSS.exe
    Deleted : C:\Users\DreamChamber\Desktop\FSS.txt
    Deleted : C:\Users\DreamChamber\Desktop\SecurityCheck.exe
    Deleted : C:\Users\DreamChamber\Desktop\TFC.exe
    Deleted : C:\Windows\grep.exe
    Deleted : C:\Windows\PEV.exe
    Deleted : C:\Windows\NIRCMD.exe
    Deleted : C:\Windows\MBR.exe
    Deleted : C:\Windows\SED.exe
    Deleted : C:\Windows\SWREG.exe
    Deleted : C:\Windows\SWSC.exe
    Deleted : C:\Windows\SWXCACLS.exe
    Deleted : C:\Windows\Zip.exe
    Deleted : HKLM\SOFTWARE\OldTimer Tools
    Deleted : HKLM\SOFTWARE\AdwCleaner
    Deleted : HKLM\SOFTWARE\Swearware
    Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\combofix.exe

    ~ Creating registry backup ... OK

    ~ Cleaning system restore ...


    New restore point created !

    ~ Resetting system settings ... OK

    ########## - EOF - ##########
     
  15. 2015/08/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I don't need any new logs.
    That's for your future use.

    Good news :)
    Good luck and stay safe :)
     
  16. 2015/08/21
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    Thanks broni...I am already a lifetime member but when I get paid next Friday I am going to donate $50. Your expertise was worth ten times that much but times have gotten touch and go for me the last 5 years.

    Are the free versions enough to keep me clean and virus free as long as I run them once a week?
     
  17. 2015/08/21
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    I have one small concern...I have started getting these messages that suddenly appear that say 'your carbonite engine has stopped working. I have not ever gotten these messages before. I did have to reinstall carbonite after all the processes but this message started appearing somewhere in the middle of all the processes. I just mostly ignored it at the beginning cause I just thought a process was simply closing my Carbonite so it could do its thing unimpeded. But now even when I am not cleaning or updating this message appears often enough to concern me....In fact as I am typing this the message reappeared after I closed it a few minutes ago
    This is exactly what appears....Top outer rim of Window is typed 'Microsoft Windows

    Interior of window is printed ....Carbonite Secure Backup Engine stopped working and was closed

    under that in smaller print is this message.....A problem caused the application to stop working correctly. Windows will notify you if a solution is available'

    I have never gotten this message before and now it simply won't stop appearing and reappearing. Does this mean I have to reinstall Carbonite?
     
    Last edited: 2015/08/21
  18. 2015/08/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes, corruption just happens sometimes.
    Reinstall Carbonite and that should solve the issue.
     
  19. 2015/08/24
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    OK thanks. I will contact them and see how to do that.. So far my compujter seems to be working better..,fingers crossed.
     
  20. 2015/08/24
    blakston6286 Lifetime Subscription

    blakston6286 Well-Known Member Thread Starter

    Joined:
    2002/01/20
    Messages:
    364
    Likes Received:
    0
    Not so fast

    Now when I log into my bank. After a few minutes I get the Blue screen that tells me in white letters that windows has encountered a problem and it is doing some ????crash dumping??? whatever that is and then it goes thru this weird process the reboots. I wish I could freeze the screen and send you a print out of the process but I lose control of my computer when it starts...It just simply does its thing and then reboots. Maybe I will take a camera and snap a picture and send the results if it comes out....Maybe that will work..
     
  21. 2015/08/24
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I suggest new topic in Windows forum.

    In this forum, we make sure, your computer is free of malware and your computer is clean :)
    Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
    You'll get more attention.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.