10-09-2010, 05:08 AM
Greetings,
In return for this service, I propose to you two conditions:
Thank you.
Genuinely yours,
Paradoxum
Whilst I am in the process of scrutinizing your complete set of provided logs for any possible infections or problems, I ask for your forbearance. Understand that the process of analysis requires time and careful examination hence the need for a cautious response. Accuracy is of the essence. Once I come across infections, I shall present the finest methods of removal for your convenience.
In return for this service, I propose to you two conditions:
- You are not to create any new threads regarding the similar topic as it will waste another helper's time.
- You are not to install any new software in your system, as it may hinder our process thus making this futile.
- You are not to modify the logs in any way. Failure to do so will instantly deprive you of this service.
- You are to paste each log separately at PasteBin as it is. That is correct, no syntax highlighting, no editing - just the log purely. Post back the links for each log. You shall not hide them under spoiler codes.
- You are to provide the complete set of requested logs.
- You are to respond to every step I ask you to do using the format provided at the end of my post.
- You agree that I have the right to discontinue the analysis at any time, upon a violation of a single rule.
Thank you.
Genuinely yours,
Paradoxum
- Pre-Step
Click 'here' to download Temp File Cleaner (TFC) by OldTimer. Save it to your Desktop.
- Please ensure that there are no other applications running. Be sure to save any unsaved work before running TFC as it will close everything.
- Double-click TFC.exe and select 'Allow' when prompted to execute the program.
- Press the 'Start' button.
- When finished, if any files need to be removed by a reboot you will be asked to reboot. Otherwise the desktop will be restored.
- Select 'OK' when prompted to reboot.
- Please ensure that there are no other applications running. Be sure to save any unsaved work before running TFC as it will close everything.
- Prerequisite
Your current version of HijackThis is out of date.
- Download the latest HijackThis Installer from Trend Micro by clicking 'here'. Save it to your Desktop.
- Double-click the HijackThis icon. Click Run when prompted.
- By default, it will install to C:\Program Files\Trend Micro\HijackThis and will create a shorcut in your Desktop.
- Upon running the program, click Accept to agree to the License Agreement.
- Close HijackThis.
If you are having a problem running HijackThis as Administrator, please follow the steps below.- Download the latest HijackThis Installer from Trend Micro by clicking 'here'. Save it to your Desktop.
- Go to My Computer and navigate to your default disc drive (C: is the most common).
- Go to Program Files > Trend Micro > HijackThis.
- Right-click HiJackThis.exe and run it as Administrator.
- Go to My Computer and navigate to your default disc drive (C: is the most common).
- Step 1
Please run HijackThis. Click 'Do a system scan only' and place a check next to the following line(s) if present:
F2 - REGystem.ini: UserInit=userinit.exe
Then, close all other open windows and click 'Fix Checked'. You are to reboot your system afterwards.
- Step 2
Please run a free online scan with ESET Online Scanner by downloading ESET Smart Installer 'here'. Save it to your Desktop.
- Double-click esetsmartinstaller_enu.exe to execute the program.
- Tick 'YES, I accept the Terms of Use'.
- Click 'Start'.
- If this is your first time installing the scanner, allow the 'ActiveX Control' to install.
- Database download may take some time.
- When done, make sure that the option 'Remove found threats' is ticked. Under the and 'Advanced Settings', please put a check on the following options:
- Scan for potentially unwanted applications
- Enable Anti-Stealth Technology
- Scan for potentially unwanted applications
- Click 'Start'.
- Wait for the scan to finish.
- Once it is finished, use Notepad to open the logfile located at C:\Program Files\ESET\ESET Online Scanner\log.txt.
- Copy and paste that log as a reply to this topic.
- Double-click esetsmartinstaller_enu.exe to execute the program.
- Step 3
- Please download Malwarebytes' Anti-Malware 'here'.
- Double-click mbam-setup-1.45.exe to install the application.
- Make sure a checkmark is placed next to 'Malwarebytes' Anti-Malware' and 'Launch Malwarebytes' Anti-Malware', then click 'Finish'.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select 'Perform Full Scan', then click 'Scan'. The scan may take some time to finish, so please be patient.
- When the scan is complete, click 'OK', then 'Show Results' to view the results.
- Make sure that everything is checked, and click 'Remove Selected'.
- When disinfection is completed, a log will open in Notepad and you may be prompted to restart. Restart if it tells you to.
- The log is automatically saved by Malwarebytes' Anti-Malware and can be viewed by clicking the 'Logs' tab in the interface.
- Copy and paste the entire report in your next reply.
- Please download Malwarebytes' Anti-Malware 'here'.
- Step 4
Download DDS.scr by sUBs from one of the following links & save it to your desktop.
Link 1
Link 2- Double-Click on dds.scr and a command window will appear. This is normal
- Shortly after two logs will appear, DDS.txt & Attach.txt
- A window will open instructing you save & post the logs.
- Save the logs to a convenient place such as your desktop.
- Copy the contents of both logs & post in your next reply.
- Double-Click on dds.scr and a command window will appear. This is normal
- In your next post, please provide the following:
- A Fresh HijackThis (HJT) Log
- Deckard's System Scanner (DDS) Logs
- DDS.txt
- Attach.txt
- DDS.txt
- A Fresh HijackThis (HJT) Log
- ESET Scan Log
- Malwarebytes' Anti-Malware Scan Log
- Format of Response
As part of my service terms, you are to fill this up everytime you respond to your log. Copy and paste the content inside the code box and write directly after the closing tags. Do not add spaces as they are already provided. An exception applies to the numbers, as they are to be written after the # sign.
Step #1: Change the number accordingly.
Problems Encountered: Put N/A if the operation went smoothly.
Link To Requested Logs: Post the links to the logs I have asked you to produce.
Example: (Click to View)
- Code:
[color=#00BFFF][b]Step #[/b][/color]
[color=#FFD700][b]Problems Encountered:[/b][/color]
[color=#00BFFF][b]Step #[/b][/color]
[color=#FFD700][b]Problems Encountered:[/b][/color]
[color=#00BFFF][b]Step #[/b][/color]
[color=#FFD700][b]Problems Encountered:[/b][/color]
[color=#00BFFF][b]Link To Requested Logs:[/b][/color]