WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
here's rooter. Im gonna restart in regular mode and try again. I'm using internet explorer and every time I type an address, nothing happens. doesn't go to another page, nothing. just stays on google homepage

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows 7 Home Edition (6.1.7601) Service Pack 1
[32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
.
[wscsvc] STOPPED (state:1) : Security Center -> Disabled !
[MpsSvc] RUNNING (state:4)
Windows Firewall -> Enabled
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 9.10.9200.16576
.
C:\ [Fixed-NTFS] .. ( Total:99 Go - Free:27 Go )
D:\ [Fixed-NTFS] .. ( Total:182 Go - Free:78 Go )
E:\ [CD_Rom]
.
Scan : 18:10.07
Path : C:\Users\Joelo\Desktop\Rooter.exe
User : Joelo ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
______ ?????????? (284)
______ ?????????? (384)
______ ?????????? (420)
______ ?????????? (428)
______ ?????????? (468)
______ ?????????? (516)
______ ?????????? (524)
______ ?????????? (536)
______ ?????????? (636)
______ ?????????? (712)
______ ?????????? (804)
______ ?????????? (848)
______ ?????????? (908)
______ ?????????? (936)
______ ?????????? (1008)
______ ?????????? (312)
______ C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (1028)
______ ?????????? (1276)
______ ?????????? (1448)
______ ?????????? (1492)
______ ?????????? (1716)
______ C:\Program Files\AVAST Software\Avast\AvastUI.exe (356)
______ ?????????? (1472)
______ C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (1100)
______ ?????????? (1424)
______ C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE (1584)
______ C:\Users\Joelo\Desktop\Rooter.exe (1096)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:1048576 | Length:16106127360)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:16107175936 | Length:104857600)
\Device\Harddisk0\Partition3 (Start_Offset:16212033536 | Length:107374182400)
\Device\Harddisk0\Partition4 (Start_Offset:123586215936 | Length:196484268032)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\Adobe Flash Player Updater.job
C:\Windows\Tasks\GlaryInitialize.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 18:10.10
.
C:\Rooter$\Rooter_3.txt - (31/05/2013 | 18:10.10)

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
tried again in regular mode. still does nothing after you type in address. address in address bar changes but stays right on google homepage. heres rooter again. next one will be rougekiller.

Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows 7 Home Edition (6.1.7601) Service Pack 1
[32_bits] - Intel64 Family 6 Model 23 Stepping 10, GenuineIntel
.
[wscsvc] STOPPED (state:1) : Security Center -> Disabled !
[MpsSvc] RUNNING (state:4)
Windows Firewall -> Enabled
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 9.10.9200.16576
.
C:\ [Fixed-NTFS] .. ( Total:99 Go - Free:27 Go )
D:\ [Fixed-NTFS] .. ( Total:182 Go - Free:78 Go )
E:\ [CD_Rom]
.
Scan : 18:28.56
Path : C:\Users\Joelo\Desktop\Rooter.exe
User : Joelo ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
______ ???s?????? (284)
______ ???s?????? (384)
______ ???s?????? (420)
______ ???s?????? (436)
______ ???s?????? (492)
______ ???s?????? (504)
______ ???s?????? (512)
______ ???s?????? (520)
______ ???s?????? (640)
______ ???s?????? (716)
______ ???s?????? (808)
______ ???s?????? (840)
______ ???s?????? (880)
______ ???s?????? (908)
______ ???s?????? (1004)
______ ???s?????? (308)
______ C:\Program Files (x86)\Webroot\Security\current\plugins\antimalware\AEI.exe (348)
______ ???s?????? (1260)
______ ???s?????? (1432)
______ ???s?????? (1476)
______ ???s?????? (1696)
______ C:\Users\Joelo\Desktop\Rooter.exe (2012)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:1048576 | Length:16106127360)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:16107175936 | Length:104857600)
\Device\Harddisk0\Partition3 (Start_Offset:16212033536 | Length:107374182400)
\Device\Harddisk0\Partition4 (Start_Offset:123586215936 | Length:196484268032)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\Adobe Flash Player Updater.job
C:\Windows\Tasks\GlaryInitialize.job
C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 18:29.55
.
C:\Rooter$\Rooter_6.txt - (31/05/2013 | 18:29.55)

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
here's rougekiller.

RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
mail : tigzyRKgmailcom
Feedback : http://www.geekstogo.com/forum/files/file/413-roguekiller/
Website : http://tigzy.geekstogo.com/roguekiller.php
Blog : http://tigzyrk.blogspot.com/

Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Safe mode with network support
User : Joelo [Admin rights]
Mode : Scan -- Date : 05/31/2013 18:34:41
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 8 ¤¤¤
[HJPOL] HKCU\[...]\System : DisableTaskmgr (0) -> FOUND
[HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[...]\System : DisableRegistryTools (0) -> FOUND
[HJPOL] HKLM\[...]\Wow6432Node\System : DisableRegistryTools (0) -> FOUND
[HJ DESK] HKCU\[...]\ClassicStartMenu : {59031A47-3F72-44A7-89C5-5595FE6B30EE} (1) -> FOUND
[HJ DESK] HKCU\[...]\NewStartPanel : {59031A47-3F72-44A7-89C5-5595FE6B30EE} (1) -> FOUND
[HJ DESK] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
[HJ DESK] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED] ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> C:\Windows\system32\drivers\etc\hosts

127.0.0.1 localhost
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: SAMSUNG HM321HI +++++
--- User ---
[MBR] 42bb5ddf4f419cb88efe93378dbae89a
[BSP] 09dab093d2e1f4e4b3416bdc6436ef6d : KIWI Image system MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 15360 Mo
1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 31459328 | Size: 100 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 31664128 | Size: 102400 Mo
3 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 241379328 | Size: 187382 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1]_S_05312013_02d1834.txt >>
RKreport[1]_S_05312013_02d1834.txt

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
Please try MSFix-It to repair IE.
Please download and run MS Fix-it from here.

Please run RogueKiller again and delete those items.

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the please help! don't know what happened - Page 1 EsetOnline button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on please help! don't know what happened - Page 1 EsetSmartInstall to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the please help! don't know what happened - Page 1 EsetSmartInstallDesktopIcon-1 icon on your desktop.

•Check please help! don't know what happened - Page 1 EsetAcceptTerms
•Click the please help! don't know what happened - Page 1 EsetStart button.
•Accept any security warnings from your browser.

  • Leave the check mark next to Remove found threats.

•Check please help! don't know what happened - Page 1 EsetScanArchives
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push please help! don't know what happened - Page 1 EsetListThreats
•Push please help! don't know what happened - Page 1 EsetExport, and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the please help! don't know what happened - Page 1 EsetBack button.
•Push please help! don't know what happened - Page 1 EsetFinish
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
here's both from ESETS

C:\Users\Joelo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\60d0a31c-69ebd268 a variant of Java/Exploit.CVE-2013-0422.CF trojan cleaned by deleting - quarantined
C:\Users\Joelo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\7487f329-314f21f3 a variant of Java/Exploit.CVE-2013-2423.AZ trojan cleaned by deleting - quarantined
C:\Users\Joelo\Downloads\Google_Chrome_Setup (1).exe a variant of Win32/Adware.iBryte.G application cleaned by deleting - quarantined
C:\Users\Joelo\Downloads\Google_Chrome_Setup.exe a variant of Win32/Adware.iBryte.G application cleaned by deleting - quarantined


************************************************************


ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK
# version=8
# IEXPLORE.EXE=10.00.9200.16521 (win8_gdr_soc_ie.130216-2100)
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=10bc2f2aa000b34fbde10c0bdafe35ea
# engine=13965
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-06-01 01:48:23
# local_time=2013-05-31 09:48:23 (-0500, Eastern Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777214 85 91 0 145839575 0 0
# compatibility_mode=5893 16776573 100 94 0 121594753 0 0
# scanned=216596
# found=4
# cleaned=4
# scan_time=5296
sh=1888A3CF9B0DCE4830F004A8414DE3CCE902EF2A ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-0422.CF trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joelo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28\60d0a31c-69ebd268"
sh=91FF936CCA4B6380E01D9B77F11C0D068697AD5C ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-2423.AZ trojan (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joelo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41\7487f329-314f21f3"
sh=3C183AFD1A663437FB23458E29A520BC405E697B ft=1 fh=2f3f736a61f08366 vn="a variant of Win32/Adware.iBryte.G application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joelo\Downloads\Google_Chrome_Setup (1).exe"
sh=EA05D300E12A6EE60BB8B056A23434B1F78EDAF4 ft=1 fh=907439f77c07175d vn="a variant of Win32/Adware.iBryte.G application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Joelo\Downloads\Google_Chrome_Setup.exe"

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
Any other issues before we cleanup?

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
im back in regular mode. google chrome works just fine but internet explorer still doesn't work. (the address and address bar situation i told you about earlier...) I just won't use explorer anymore.

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
Did you try running MSFix-It to repair IE. If that didn't work try setting IE back to it's default.

To uninstall ComboFix


  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


please help! don't know what happened - Page 1 Combofix_uninstall_image

(Note: Make sure there's a space between the word ComboFix and the forward-slash.)


  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.

*******************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.

please help! don't know what happened - Page 1 Diskcleanup2

Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.

please help! don't know what happened - Page 1 Diskcleanup

This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
****************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
thanks a lot!!

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.

descriptionplease help! don't know what happened - Page 1 EmptyRe: please help! don't know what happened

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum