I cannot restore.

uninstall Aro 2011!! Run Combofix
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Ok Combofix has finished. Before Combofix started scanning it said Webroot may interfere with the scan but I uninstalled Webroot. I just now tried to search for it in the search bar and nothing came up. Im not sure what thats about. Other than that everything seems to have went ok. The process didnt take long as I expected. Here is the combofix log.
 

Attachments

  • ComboFix.txt
    16.6 KB · Views: 28

My Computer

It looks like you possibly got infected from an e-mail c:\Windows\SysWOW64\s6ovg.com(Trojan.Email)

Please download TFC by Old Timer TFC - Temp File Cleaner by OldTimer - Geeks to Go Forums and save it to your desktop.
Save any unsaved work. TFC will close ALL open programs including your browser!
Double-click on TFC.exe to run it. If you are using Vista/Windows 7 right-click on the file and choose Run As Administrator.
Click the Start button to begin the cleaning process and let it run uninterrupted to completion.
Important! If TFC prompts you to reboot, please do so immediately. If not prompted, manually reboot the machine anyway to ensure a complete clean.


Next, I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
You're doing good!

Now, download MalwarebyesAnti-Malware (click Download Now button) ... don't click the 'purchase' link. This is free, unless you want to activate/enable real time protection.
Save it to your desktop
* Right click mbam-setup.exe, to run as Administrator, and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org
Database version: 8382
Windows 6.0.6002 Service Pack 2
Internet Explorer 9.0.8112.16421
12/16/2011 6:05:20 PM
mbam-log-2011-12-16 (18-05-20).txt
Scan type: Full scan (C:\|)
Objects scanned: 416050
Time elapsed: 1 hour(s), 14 minute(s), 19 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
 

Attachments

  • mbam-log 2011-12-16(18-05-20).txt
    920 bytes · Views: 25

My Computer

Wh00t --- You're look'n good!!!:party:



:Uninstall ComboFix:
  • turn off all active protection software
  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box ComboFix /Uninstall and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.
  • CF-Uninstall.png

:Make your Internet Explorer more secure:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialise and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.

:Make Firefox more secure:
Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector



:Turn On Automatic Updates:
  • Turn On Automatic Updates
    1. Click Start, click Run, type sysdm.cpl, and then press ENTER.

  • 2. Click the Automatic Updates tab, and then click to select one of the following options. We recommend that you select the Automatic (recommended) Automatically download recommended updates for my computer and install them
  • If you click this setting, click to select the day and time for scheduled updates to occur. You can schedule Automatic Updates for any time of day. Remember, your computer must be on at the scheduled time for updates to be installed.
  • After you set this option, Windows recognizes when you are online and uses your Internet connection to find updates on the Windows Update Web site or on the Microsoft Update Web site that apply to your computer. Updates are downloaded automatically in the background, and you are not notified or interrupted during this process. An icon appears in the notification area of your taskbar when the updates are being downloaded. You can point to the icon to view the download status.
  • To pause or to resume the download, right-click the icon, and then click Pause or Resume. When the download is completed, another message appears in the notification area so that you can review the updates that are scheduled for installation.
  • If you choose not to install at that time, Windows starts the installation on your set schedule.
    or visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
  • If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
:antispyware programs:


I would recommend the download and install of some or all of the following programs (all free), and update them regularly:
  • WinPatrol As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
Here is some great reading about how to be safer online:
Let me know how your computer is running now and if you've followed through with my instructions
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Wh00t --- You're look'n good!!!:party:




:Uninstall ComboFix:
  • turn off all active protection software
  • push the "windows key" + "R" (between the "Ctrl" button and "Alt" Button)
  • please copy and past the following into the box ComboFix /Uninstall and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.
  • CF-Uninstall.png

:Make your Internet Explorer more secure:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialise and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.

:Make Firefox more secure:
Make sure your applications have all of their updates
It is also possible for other programs on your computer to have security vulnerability that can allow malware to infect you. Therefore, it is also a good idea to check for the latest versions of commonly installed applications that are regularly patched to fix vulnerabilities. You can check these by visiting Secunia Software Inspector




:Turn On Automatic Updates:
  • Turn On Automatic Updates
    1. Click Start, click Run, type sysdm.cpl, and then press ENTER.

  • 2. Click the Automatic Updates tab, and then click to select one of the following options. We recommend that you select the Automatic (recommended) Automatically download recommended updates for my computer and install them
  • If you click this setting, click to select the day and time for scheduled updates to occur. You can schedule Automatic Updates for any time of day. Remember, your computer must be on at the scheduled time for updates to be installed.
  • After you set this option, Windows recognizes when you are online and uses your Internet connection to find updates on the Windows Update Web site or on the Microsoft Update Web site that apply to your computer. Updates are downloaded automatically in the background, and you are not notified or interrupted during this process. An icon appears in the notification area of your taskbar when the updates are being downloaded. You can point to the icon to view the download status.
  • To pause or to resume the download, right-click the icon, and then click Pause or Resume. When the download is completed, another message appears in the notification area so that you can review the updates that are scheduled for installation.
  • If you choose not to install at that time, Windows starts the installation on your set schedule.
    or visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer.
  • If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
:antispyware programs:



I would recommend the download and install of some or all of the following programs (all free), and update them regularly:
  • WinPatrol As a robust security monitor, WinPatrol will alert you to hijackings, malware attacks and critical changes made to your computer without your permission. WinPatrol takes snapshot of your critical system resources and alerts you to any changes that may occur without your knowledge.
Here is some great reading about how to be safer online:
Let me know how your computer is running now and if you've followed through with my instructions
Im finally back. My daughter was born Monday and we was just released today.

I followed all of your instructions and the computer seems to be running just fine. So has all of the viruses been removed from my computer?

I really appreciate all the help guys!!:D
 

My Computer

Oh my gosh! Congratulations and welcome to the world baby girl TH40229 :D
 

My Computer

System One

  • Manufacturer/Model
    Bruce ... somewhere in his 40's
    CPU
    Intel(R) Core(TM)2 Quad CPU
    Motherboard
    INTEL/D975XBX2
    Memory
    4 GB
    Graphics Card(s)
    ATI Radeon HD 2600 Pro
    Monitor(s) Displays
    Samsung SyncMaster 914v
    Screen Resolution
    1280 x 1024
    Hard Drives
    2/500GB each ... ST3500630AS ATA Device.
    One is not connected
    PSU
    Rocketfish 700 W
    Case
    G.Skill Gigabyte Chassis
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    Microsoft PS/2 Mouse
    Internet Speed
    DSL
    Other Info
    ATI HDMI Audio
Thank u :) So what should I do when my malwarebytes free trial runs out? I downloaded the other programs that you recommended. Should they be enough?
 

My Computer

As many other members, use the free Malwarbytes at least once a week to prevent future problems. Good luck and a great New Year to you.
 

My Computer

System One

  • Manufacturer/Model
    Dell XPS420
    Memory
    6 gig
    Graphics Card(s)
    ATI Radeon HD3650 256 MB
    Sound Card
    Intergrated 7.1 Channel Audio
    Monitor(s) Displays
    Dell SP2009W 20 inch Flat Panel w Webcam
    Hard Drives
    640 gb
    Cooling
    Fan
    Keyboard
    Dell USB
    Mouse
    Dell USB 4 button optical
    Other Info
    DSL provided by ATT
Mbam will , from my understanding, at the end of the 30 day free trial , which was Real Time protection, at the end of that trial , will revert to on demand and cease to protect you in Real Time.
In other words, for it to function, you will have to update it and then scan with it, as it will not update itself nor will it be running to block threats.
So, using a layered approach to your security, your anti virus, if you are using MSE , ( my choice ) in addition , use Mbam once a week or so to ensure that nothing has been missed.
If you are having any issues with this , then simply uninstall it, and then reinstall it. Just get free version .
 

My Computer

System One

  • Manufacturer/Model
    Emachine ET 1161-05
    CPU
    AMD Athlon 64 LE-1640
    Motherboard
    eMachines MCP61PM-GM (Socket AM2 )
    Memory
    2.00 GB Dual-Channel DDR2 @ 387MHz (6-6-6-18)
    Graphics Card(s)
    Acer E181H (1280x768@60Hz) 128MB GeForce 6150SE nForce 430 (
    Sound Card
    Realtek High Definition Audio
    Monitor(s) Displays
    Name Acer E181H on NVIDIA GeForce 6150SE nForce 430
    Screen Resolution
    1280x768 pixels
    Hard Drives
    ST316081 5AS SCSI Disk Device
    PSU
    MCP61PM-GM 9000 NVIDIA Chipset Model MCP61 Chipset Revisio
    Case
    Tower
    Cooling
    Fan Speed 1247 RPM
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    PS/2 Compatible Mouse
    Internet Speed
    http://www.speedtest.net/result/1538974261.png
Mbam will , from my understanding, at the end of the 30 day free trial , which was Real Time protection, at the end of that trial , will revert to on demand and cease to protect you in Real Time.
In other words, for it to function, you will have to update it and then scan with it, as it will not update itself nor will it be running to block threats.
So, using a layered approach to your security, your anti virus, if you are using MSE , ( my choice ) in addition , use Mbam once a week or so to ensure that nothing has been missed.
If you are having any issues with this , then simply uninstall it, and then reinstall it. Just get free version .

Oh ok I didn't know I could still continue to scan after the trial ran out. Thanks for the info! Should I go ahead and install MSE also?

So what if I uninstalled Mbam then reinstalled it would my viruses reappear and could I get real time protection with the reinstall?
 

My Computer

What anti virus are you currently using ? Whatever it is, to use MSE , you would want to download it, Uninstall the other one you have using its uninstaller , note: all antivirus programs will normally require more than just a remove / uninstall in programs , they have their own uninstaller in addition to the Windows uninstaller. Post back what you currently use and i will advise further.
As far as Mbam goes, they recently have been doing a 30 day free trial of the paid version, as i said, i believe it will nag you to purchase it , but , to my knowledge just stops full time protection and has to be manually updated and set to scan by user , whereas before with the free trial , it auto updated and performed as you had set it to.
 

My Computer

System One

  • Manufacturer/Model
    Emachine ET 1161-05
    CPU
    AMD Athlon 64 LE-1640
    Motherboard
    eMachines MCP61PM-GM (Socket AM2 )
    Memory
    2.00 GB Dual-Channel DDR2 @ 387MHz (6-6-6-18)
    Graphics Card(s)
    Acer E181H (1280x768@60Hz) 128MB GeForce 6150SE nForce 430 (
    Sound Card
    Realtek High Definition Audio
    Monitor(s) Displays
    Name Acer E181H on NVIDIA GeForce 6150SE nForce 430
    Screen Resolution
    1280x768 pixels
    Hard Drives
    ST316081 5AS SCSI Disk Device
    PSU
    MCP61PM-GM 9000 NVIDIA Chipset Model MCP61 Chipset Revisio
    Case
    Tower
    Cooling
    Fan Speed 1247 RPM
    Keyboard
    Standard PS/2 Keyboard
    Mouse
    PS/2 Compatible Mouse
    Internet Speed
    http://www.speedtest.net/result/1538974261.png
Back
Top