1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved system check virus?

Discussion in 'Malware and Virus Removal Archive' started by gpb59, 2012/01/28.

  1. 2012/01/29
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    Results of screen317's Security Check version 0.99.24
    Windows Vista Service Pack 2 x86 (UAC is enabled)
    Internet Explorer 9
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    AVG 2012
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Java(TM) 6 Update 13
    Java(TM) 6 Update 30
    Java(TM) 6 Update 7
    Out of date Java installed!
    Adobe Flash Player 11.1.102.55
    Mozilla Firefox (x86 en-US..)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Malwarebytes' Anti-Malware mbamservice.exe
    Malwarebytes' Anti-Malware mbamgui.exe
    AVG avgwdsvc.exe
    AVG avgtray.exe
    AVG avgrsx.exe
    AVG avgnsx.exe
    AVG avgemc.exe
    ``````````End of Log````````````
     
  2. 2012/01/29
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    Farbar Service Scanner Version: 18-01-2012 01
    Ran by Gary (administrator) on 29-01-2012 at 20:56:34
    Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86)
    Boot Mode: Normal
    ****************************************************************

    Internet Services:
    ============

    Connection Status:
    ==============
    Localhost is accessible.
    LAN connected.
    Google IP is accessible.
    Yahoo IP is accessible.


    Windows Firewall:
    =============

    Firewall Disabled Policy:
    ==================


    System Restore:
    ============
    SDRSVC Service is not running. Checking service configuration:
    The start type of SDRSVC service is OK.
    The ImagePath of SDRSVC service is OK.
    The ServiceDll of SDRSVC service is OK.
    Checking LEGACY_SDRSVC: Attention! Unable to open LEGACY_SDRSVC\0000 registry key. The key does not exist.

    VSS Service is not running. Checking service configuration:
    The start type of VSS service is OK.
    The ImagePath of VSS service is OK.


    System Restore Disabled Policy:
    ========================


    Security Center:
    ============

    Windows Update:
    ===========

    File Check:
    ========
    C:\Windows\system32\nsisvc.dll => MD5 is legit
    C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit
    C:\Windows\system32\dhcpcsvc.dll => MD5 is legit
    C:\Windows\system32\Drivers\afd.sys => MD5 is legit
    C:\Windows\system32\Drivers\tdx.sys => MD5 is legit
    C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit
    C:\Windows\system32\dnsrslvr.dll => MD5 is legit
    C:\Windows\system32\mpssvc.dll => MD5 is legit
    C:\Windows\system32\bfe.dll => MD5 is legit
    C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit
    C:\Windows\system32\SDRSVC.dll => MD5 is legit
    C:\Windows\system32\vssvc.exe => MD5 is legit
    C:\Windows\system32\wscsvc.dll => MD5 is legit
    C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit
    C:\Windows\system32\wuaueng.dll => MD5 is legit
    C:\Windows\system32\qmgr.dll
    [2009-05-31 14:35] - [2009-04-10 22:28] - 0758784 ____A (Microsoft Corporation) 93952506C6D67330367F7E7934B6A02F

    C:\Windows\system32\es.dll => MD5 is legit
    C:\Windows\system32\cryptsvc.dll
    [2009-05-31 14:35] - [2009-04-10 22:28] - 0129024 ____A (Microsoft Corporation) FB27772BEAF8E1D28CCD825C09DA939B

    C:\Windows\system32\svchost.exe => MD5 is legit
    C:\Windows\system32\rpcss.dll => MD5 is legit


    **** End of log ****
     

  3. to hide this advert.

  4. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    C:\Program Files\FoxTabMusicConverter\AudioConverter.exe a variant of Win32/InstallCore.A application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\RegistryBooster\Launcher.exe Win32/RegistryBooster application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\RegistryBooster\rbmonitor.exe Win32/RegistryBooster application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\RegistryBooster\rbnotifier.exe Win32/RegistryBooster application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\RegistryBooster\rb_move_serial.exe Win32/RegistryBooster application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\RegistryBooster\rb_ubm.exe Win32/RegistryBooster application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\RegistryBooster\registrybooster.exe Win32/RegistryBooster application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\SpeedUpMyPC\spnotifier.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\SpeedUpMyPC\sp_move_serial.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
    C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe Win32/SpeedUpMyPC application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ReactivateIE.exe.vir a variant of Win32/Toolbar.Zugo application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\Toolbar32.dll.vir a variant of Win32/Toolbar.Zugo application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarBroker.exe.vir a variant of Win32/Toolbar.Zugo application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe.vir a variant of Win32/Toolbar.Zugo application cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\ProgramData\jLyiTUCQBK.exe.vir Win32/TrojanDownloader.Prodatect.BK trojan cleaned by deleting - quarantined
    C:\Qoobox\Quarantine\C\ProgramData\nv4bl3vb4fAGSS.exe.vir a variant of Win32/Kryptik.ZQB trojan cleaned by deleting - quarantined
    C:\Users\Gary\AppData\Roaming\Auslogics\Rescue\One Button Checkup\111226154844032.rsc multiple threats deleted - quarantined
    C:\Users\Gary\AppData\Roaming\Auslogics\Rescue\One Button Checkup\120115091213054.rsc a variant of Win32/Adware.HotBar.L application deleted - quarantined
    J:\Music I drive\FedEx_Invoice (1).zip a variant of Win32/Kryptik.ZQM trojan deleted - quarantined
    J:\Music I drive\FedEx_Invoice.zip a variant of Win32/Kryptik.ZQM trojan deleted - quarantined
    J:\Music I drive\MPLSetup (1).exe a variant of Win32/Adware.HotBar.L application cleaned by deleting - quarantined
    J:\Music I drive\MPLSetup.exe a variant of Win32/Adware.HotBar.L application cleaned by deleting - quarantined
    J:\Music I drive\Track your parcel NO1334.zip a variant of Win32/Kryptik.ZQM trojan deleted - quarantined
    J:\Old drive\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\InternetSpeedMonitor.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined
     
  5. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall:
    Java(TM) 6 Update 7
    Java(TM) 6 Update 13


    You have one registry key missing affecting system restore functioning.

    Following steps involve registry editing. Please create new restore point before proceeding!!!
    How to:
    XP - http://support.microsoft.com/kb/948247
    Vista and Seven - http://www.howtogeek.com/howto/wind...tore-point-for-windows-vistas-system-restore/



    Please go to Start=>Run (alternatively use Windows key+R), type regedit and click OK.
    Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root
    Right-Click Root and select Permissions...
    Click Advanced.
    Under Owner tab select the entry starting with you user name, example: Farbar(Farbar-PC\Farbar)
    Put a check mark next to Replace owner on subcontainers and objects and click Apply and OK.
    Under Security type while Everyone is selected put a check mark in the box under Allow next to Full Control.
    Click Apply and OK.
    Download Vista.zip file from here: http://www.smartestcomputing.us.com/files/download/9-registry-network-keys/
    Unzip downloaded file.
    You'll find several files inside.
    Double-click legacy_sdrsvc.reg and confirm the prompt.
    Please go back to the the Root key again while Everyone is selected remove check mark in the box under Allow next to Full Control and close the registry.
    Restart computer.
    Post new FSS log.
     
    Last edited: 2012/01/30
  6. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    Thanks, will be back home around 4 today. BTW, you prefer the Avastor Avira over the AVG? If so I'll probably change it after we're done
     
  7. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  8. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  9. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    I can't uninstall the Java update, also there's no update 7 in the control panel , there's and update 13 and update 30
     
  10. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    UNinstall?

    Uninstall update 13
     
  11. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    It won't uninstall, I go to the control panel, it says preparing to uninstall, then asks to allow the program, and then it just stops and the update is still there
     
  12. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  13. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    Ok, after uninstall it says to click scan, now I have "found leftover registry items ", what do I do then?
     
  14. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Leave registry alone and proceed with other steps.
     
  15. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    I hit finish, it's still there
     
  16. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's most likely just registry entry (dead one).
    Leave it alone.
     
  17. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    ok I'll proceed to the other steps
     
  18. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    on this part:
    Put a check mark next to Replace owner on subcontainers and objects and click Apply and OK.

    I got a message saying registry editor could not set owner on the key currently selected, or some of it's subkeys
     
  19. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  20. 2012/01/30
    gpb59

    gpb59 Well-Known Member Thread Starter

    Joined:
    2012/01/28
    Messages:
    320
    Likes Received:
    0
    I don't know if I'm doing this right, this is what I'm getting

    Microsoft Windows [Version 6.0.6002]
    Copyright (c) 2006 Microsoft Corporation. All rights reserved.

    C:\Windows\system32>net user administrator/active:yes
    The syntax of this command is:

    NET USER
    [username [password | *] [options]] [/DOMAIN]
    username {password | *} /ADD [options] [/DOMAIN]
    username [/DELETE] [/DOMAIN]
    username [/TIMES:{times | ALL}]


    C:\Windows\system32>
     
  21. 2012/01/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Are you logged as administrator?
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.