WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
That's normal for svchost.exe.

I want to do a check with this tool real quick, which will help speed some things up too...


  • Download RogueKiller and save it on your desktop.
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan

HELP - Infected with LIVE SECURITY PLATINUM - Page 1 RGKRScan


  • Wait for the end of the scan.
  • The report has been created on the desktop.
  • Click on the Delete button.

HELP - Infected with LIVE SECURITY PLATINUM - Page 1 RGKRDelete


  • The report has been created on the desktop.


  • Next click on the ShortcutsFix

    HELP - Infected with LIVE SECURITY PLATINUM - Page 1 RGKRShortcutsFix
  • The report has been created on the desktop.

Please post:

All RKreport.txt text files located on your desktop.

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
This file is RKreport1:

RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Randy Pierce [Admin rights]
Mode: Scan -- Date: 08/17/2012 17:12:18

¤¤¤ Bad processes: 1 ¤¤¤
[SVCHOST] svchost.exe -- Path not found -> KILLED [TermProc]

¤¤¤ Registry Entries: 1 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHV2080AH +++++
--- User ---
[MBR] 74ea17bf7248875463031858aef385da
[BSP] ae203e84dcb456630d870d8f3155a2b5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 53984 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 110655720 | Size: 19061 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt



descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
This file is RKreport2:

RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Randy Pierce [Admin rights]
Mode: Remove -- Date: 08/17/2012 17:14:02

¤¤¤ Bad processes: 1 ¤¤¤
[SVCHOST] svchost.exe -- Path not found -> KILLED [TermProc]

¤¤¤ Registry Entries: 1 ¤¤¤
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 localhost


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: FUJITSU MHV2080AH +++++
--- User ---
[MBR] 74ea17bf7248875463031858aef385da
[BSP] ae203e84dcb456630d870d8f3155a2b5 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 96390 | Size: 53984 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 110655720 | Size: 19061 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt



descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
This file is RKreport3:

RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRKgmailcom
Feedback: http://www.geekstogo.com/forum/files/file/413-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows XP (5.1.2600 Service Pack 3) 32 bits version
Started in : Normal mode
User: Randy Pierce [Admin rights]
Mode: Shortcuts HJfix -- Date: 08/17/2012 17:20:32

¤¤¤ Bad processes: 1 ¤¤¤
[SVCHOST] svchost.exe -- Path not found -> KILLED [TermProc]

¤¤¤ Driver: [LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 0 / Fail 0
Quick launch: Success 0 / Fail 0
Programs: Success 12 / Fail 0
Start menu: Success 0 / Fail 0
User folder: Success 77 / Fail 0
My documents: Success 21 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 1187 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume1 -- 0x3 --> Restored
[D:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[E:] \Device\CdRom0 -- 0x5 --> Skipped

¤¤¤ Infection : ¤¤¤

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt



descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
I also have a folder on my desktop now called RK_Quarantine, along with the 3 txt files....what do I do with those?

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
You can delete those now.

How is the computer running after that?

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
It seems to have started up pretty quickly today and is running fine! Thank you again SO much! You can be sure that I send people to y'all when then need help (all the time) and we so appreciate your efforts! You are amazing!

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
Hi! Time to clean up...

Clean up System Restore

Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE

You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


Run OTC to remove our tools

To remove all of the tools we used and the files and folders they created, please do the following:
Please download OTC.exe by OldTimer:
  • Save it to your Desktop.
  • Double click OTC.exe.
  • Click the CleanUp! button.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

Purge old temporary files

Download CCleaner Slim and save it to your Desktop - Alternate download link

When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
Follow the prompts to install the program.

* Double-click the CCleaner shortcut on the desktop to start the program.
* Click on the Options block on the left, then choose Cookies.
* Under Cookies to Delete, highlight any cookies you would like to retain permanently
* Click the right arrow > to move them to the Cookies to Keep window.
* Go into Options > Advanced & uncheck Only delete files in Windows Temp folders older than 48 hours
* Click Cleaner on the left then Run Cleaner on the right to run the program.
* Important: Make sure that ALL browser windows are closed before selecting Run Cleaner

Caution: Only use the Registry feature if you are very familiar with the registry.
Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

Security Check

Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.


Tell me in your next reply, if you have completed these tasks:
  • Cleaned System Restore
  • Ran OTC
  • Ran CCleaner
  • Ran Security Check

Also, let me know how your computer is running, and don't forget to post the contents of the Security Check log.

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
I have done all of the programs that you listed above. The computer still seems to hesitate at times but for the most part it is SO much better!

Following is the Notepad report from the Security Check log:


Results of screen317's Security Check version 0.99.46
Windows XP Service Pack 3 x86
Internet Explorer 8
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Microsoft Security Essentials
Antivirus up to date!
`````````Anti-malware/Other Utilities Check:`````````
CCleaner
Java(TM) 6 Update 31
Java version out of Date!
Adobe Flash Player 11.3.300.268
Adobe Reader X (10.1.4)
Mozilla Firefox (14.0.1)
````````Process Check: objlist.exe by Laurent````````
Microsoft Security Essentials MSMpEng.exe
Microsoft Security Essentials msseces.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:: 2%
````````````````````End of Log``````````````````````

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
Clean your computer from time to time with CCleaner. Make sure to restart it at least twice a week to maintain powerful speed and keep the disk healthy.

Java Update!

Please download the newest version of Java from Java.com.

Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

Once old versions are gone, please install the newest version.

Read more about Java exploit problems

Personal Tips on Preventing Malware

See this page for more info about malware and prevention.

Any other questions before I mark this topic solved?

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
My only other question is if I should remove Security Check from my system or not? Also, I do shut down my system every time I'm done with my laptop because I've always had issues with the hibernating feature but I might not have those issues anymore so I'll have to try just leaving it on from time to time. Is it better to let it hibernate or to shut down every time?

Thanks again for your help!

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
Yes, remove Security Check. Hibernate is really the best option compared to shutting it down.

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
Alrighty then! Thanks again so much - you can close my topic now!

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
Okie dokie. Smile... Done.

descriptionHELP - Infected with LIVE SECURITY PLATINUM - Page 1 EmptyRe: HELP - Infected with LIVE SECURITY PLATINUM

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum