1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Inactive Google Redirect and Audio/Internet Connection randomly Stopping

Discussion in 'Malware and Virus Removal Archive' started by wealthymike, 2010/09/25.

Thread Status:
Not open for further replies.
  1. 2010/09/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Update your Java version: http://java.com/en/download/index.jsp

    Note 1: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

    Note 2: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

    Now, we need to remove old Java installations...

    Please download JavaRa to your desktop and unzip it to its own folder
    • Run JavaRa.exe (Vista users! Right click on JavaRa.exe, click Run As Administrator), pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts.

    =======================================================

    I'm not sure, if you're aware, that you have Actual Keylogger (http://www.fatwallet.com/redirect/b...m/securityadvisor/pest/pest.aspx?id=453097488) installed on your computer:
    We're about to remove it.
    I strongly suggest, you change all your passwords.

    =====================================================

    Run OTL
    • Under the [color= "#0000FF"]Custom Scans/Fixes[/color] box at the bottom, paste in the following

      Code:
      :OTL
      PRC - [2005/07/08 21:55:20 | 000,522,752 | ---- | M] (Actual Spy Software) -- C:\Program Files\AKProg\AKProg.exe
      MOD - [2005/07/07 22:22:20 | 000,018,944 | ---- | M] () -- C:\Program Files\AKProg\hkdll.dll
      MOD - [2005/06/17 12:48:56 | 000,020,480 | ---- | M] () -- C:\Program Files\AKProg\hprog.dll
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
      O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
      [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
      [1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
      [1 C:\Documents and Settings\Sampson\Desktop\*.tmp files -> C:\Documents and Settings\Sampson\Desktop\*.tmp -> ]
      [2010/09/25 22:56:48 | 000,000,718 | ---- | M] () -- C:\WINDOWS\System\akstart.lnk
      [2010/09/17 13:25:04 | 000,000,788 | -HS- | C] () -- C:\WINDOWS\System\actualspystart.lnk
      [2010/04/16 21:42:01 | 000,005,396 | -HS- | C] () -- C:\Documents and Settings\Sampson\Local Settings\Application Data\1508699692
      [2010/04/16 21:42:01 | 000,005,396 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\1508699692
      [2010/04/14 06:19:30 | 000,001,164 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Fm8hV5
      [2010/04/14 06:19:30 | 000,001,164 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\Fm8hV5
      [2010/04/10 12:48:46 | 000,016,488 | -HS- | C] () -- C:\Documents and Settings\Sampson\Local Settings\Application Data\Sn5p4E4Q
      [2010/04/10 07:47:04 | 000,016,508 | -HS- | C] () -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Sn5p4E4Q
      [2010/04/10 07:47:04 | 000,016,488 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\Sn5p4E4Q
      [2010/01/10 08:00:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SecTaskMan
      @Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
      
      :Services
      
      :Reg
      
      :Files
      C:\Program Files\AKProg
      
      
      :Commands
      [purity]
      [emptytemp]
      [emptyflash]
      [Reboot]
      
    • Then click the [color= "#FF0000"]Run Fix[/color] button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • You will get a log that shows the results of the fix. Please post it.

    ===================================================

    Last scans....

    Download Security Check from HERE, and save it to your Desktop.

    * Double-click SecurityCheck.exe
    * Follow the onscreen instructions inside of the black box.
    * A Notepad document should open automatically called checkup.txt; please post the contents of that document.

    =======================================================

    Download Temp File Cleaner (TFC)
    Double click on TFC.exe to run the program.
    Click on Start button to begin cleaning process.
    TFC will close all running programs, and it may ask you to restart computer.

    ========================================================

    Please run a free online scan with the ESET Online Scanner

    • Disable your antivirus program
    • Tick the box next to YES, I accept the Terms of Use
    • IMPORTANT! UN-check Remove found threats
    • Click Start
    • Accept any security warnings from your browser.
    • Check Scan archives
    • Click Start
    • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
    • When the scan completes, push List of found threats
    • Click on Export to text file , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
     
  2. 2010/09/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you still out there?
     

  3. to hide this advert.

Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.