WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
NHL06-->F:\Program Files\NHL06\EAUninstall.exe
Norton AntiSpam-->MsiExec.exe /I{3B29A786-5803-4e9e-9B58-3014A5B4E519}
Norton AntiSpam-->MsiExec.exe /I{5677563D-0CB1-485f-9E18-C5025306BB3F}
Norton AntiVirus 2005-->MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B}
Norton Internet Security 2005 (Symantec Corporation)-->C:\Program Files\Common Files\Symantec Shared\SymSetup\{A93C9E60-29B6-49da-BA21-F70AC6AADE20}.exe /X
Norton Internet Security-->MsiExec.exe /I{12E2B9E9-05B1-407d-B0FD-B5F350535125}
Norton Internet Security-->MsiExec.exe /I{48185814-A224-447a-81DA-71BD20580E1B}
Norton Internet Security-->MsiExec.exe /I{526AD5DC-CFC4-4f2a-8442-C84CC91D6C7F}
Norton Internet Security-->MsiExec.exe /I{A93C9E60-29B6-49da-BA21-F70AC6AADE20}
Norton Internet Security-->MsiExec.exe /I{E3EFA461-EB83-4C3B-9C47-2C1D58A01555}
Norton Internet Security-->MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43}
Norton Internet Security-->MsiExec.exe /I{FC2C0536-583C-46c0-844A-62CECAE01F22}
Norton WMI Update-->MsiExec.exe /X{E85FA9A1-C241-4698-893B-DD99509B8DB0}
Norton WMI Update-->MsiExec.exe /X{F64306A5-4C32-41bb-B153-53986527FAB4}
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
NVIDIA ForceWare Network Access Manager-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{1F6423DE-7959-4178-80E0-023C7EAA5347} /l1033
NVIDIA Performance-->"C:\Program Files\InstallShield Installation Information\{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}\setup.exe" -runfromtemp -l0x0409 -removeonly
NVIDIA Performance-->MsiExec.exe /I{7C7F30F4-94E7-4AA8-8941-90C4A80C68BF}
NVIDIA PhysX v8.09.04-->MsiExec.exe /X{A7E07C2B-2220-4415-87E3-784D5814BC93}
NVIDIA System Monitor-->"C:\Program Files\InstallShield Installation Information\{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}\setup.exe" -runfromtemp -l0x0409 -removeonly
NVIDIA System Monitor-->MsiExec.exe /I{E9CFBE78-ED91-4FCF-9E6F-210E477E527D}
NVIDIA System Update-->"C:\Program Files\InstallShield Installation Information\{6F69C969-2942-4E7B-B594-75B37664B8BA}\setup.exe" -runfromtemp -l0x0409 -removeonly
NVIDIA System Update-->MsiExec.exe /I{6F69C969-2942-4E7B-B594-75B37664B8BA}
OpenAL-->"C:\Program Files\OpenAL\OalinstGridRelease.exe" /U
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
Pinnacle Hollywood FX for Studio-->C:\WINDOWS\unvise32.exe E:\Program Files\Hollywood FX for Studio\6.0\uninstal.log
Pinnacle Instant DVD Recorder-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{EF781A5C-58F5-4BFD-87F9-E4F14D382F25}\setup.exe" -l0x9 UNINSTALL
Pinnacle Studio MediaSuite-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{77B8ECB2-1ACF-4587-8FB1-FCF856DB8149}\Setup.exe" -l0x9 UNINSTALL
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
proDAD Heroglyph 2.0-->"C:\Program Files\proDAD\Heroglyph-2.0\uninstall.exe" uninstall spcp PATHVERSION 2.0 MAINNAME Heroglyph
PunkBuster Services-->C:\WINDOWS\system32\pbsvc.exe -u
QuickTime-->C:\WINDOWS\unvise32qt.exe C:\WINDOWS\system32\QuickTime\Uninstall.log
RAPID-->MsiExec.exe /X{EEECE229-49F6-4851-A73A-99B058221F8C}
Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\setup.exe" -l0x9 -removeonly
Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB939653)-->"C:\WINDOWS\ie7updates\KB939653-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP11$\spuninst\spuninst.exe"
Security Update for Windows Media Player 11 (KB954154)-->"C:\WINDOWS\$NtUninstallKB954154_WM11$\spuninst\spuninst.exe"
Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
Security Update for Windows XP (KB954459)-->"C:\WINDOWS\$NtUninstallKB954459$\spuninst\spuninst.exe"
Security Update for Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
Security Update for Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}
SPBBC-->MsiExec.exe /I{77772678-817F-4401-9301-ED1D01A8DA56}
Studio 10 Bonus DVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6A012D9C-2E2E-405A-B87C-E909F5297C3F}\Setup.exe" -l0x9 UNINSTALL
Studio 10-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3CB05291-F546-458E-A796-B5BCF5A3CDC4}\Setup.exe" -l0x9 UNINSTALL
Studio MediaSuite Recording-->MsiExec.exe /I{D29FA925-E9D7-411E-8E75-C726EDF56AE6}
Symantec Script Blocking Installer-->MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138}
SymNet-->MsiExec.exe /I{2DA85B02-13C0-4E6D-9A76-22E6B3DD0CB2}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
TiVo Desktop 2.6.2-->MsiExec.exe /X{4E839090-3B68-436A-B3CF-A2A08C38DD26}
Ulead Straight-to-Disc SDK-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8D2C1E44-7685-4D05-8342-B0DC6422FA47}\setup.exe" -l0x9
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
WaveLab Lite-->"C:\Program Files\Steinberg\WaveLab Lite\Uninstall.exe" "C:\Program Files\Steinberg\WaveLab Lite\install.log"
WD Diagnostics-->MsiExec.exe /X{0AB76F69-E761-4CFA-B9B0-A1906B4E9E4B}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"

======Security center information======

AV: Norton Internet Security (outdated)
AV: ESET NOD32 Antivirus 3.0
FW: Norton Internet Security

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SYSTEMROOT%\SYSTEM32;%SYSTEMROOT%;%SYSTEMROOT%\SYSTEM32\WBEM;C:\WINDOWS;C:\WINDOWS\SYSTEM32\WBEM;C:\WINDOWS\SYSTEM32;E:\Program Files\Pinnacle\Shared Files\InstantCDDVD\
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 11, GenuineIntel
"PROCESSOR_REVISION"=0f0b
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Thank you for helping me. I really appreciate it, and sorry for being a newbie and not doing this first.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Hello.
Log came back clean, but the rootkit maybe hiding.

1. Please download The Avenger by Swandog46 to your Desktop
Link: HERE.

  • Click on Avenger.zip to open the file
  • Extract avenger.exe to your desktop
2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):


Files to delete:
C:\Documents and Settings\Raf\Local Settings\Temp\tdss1ee9.tmp


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.

  • Under "Input script here:", paste in the script from the quote box above.
  • Leave the ticked box "Scan for rootkit" ticked.
  • Then tick "Disable any rootkits found"
  • Now click on the Execute to begin execution of the script.
  • Answer "Yes" twice when prompted.

    The Avenger will automatically do the following:

  • It will Restart your computer.
  • On reboot, it will briefly open a black command window on your desktop, this is normal.
  • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
  • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
I ran it and said it did something successfully, but I had to restart because it completely froze my computer once that log file opened. And now my system is running extremely slow!I try and go to my computer to get that log file and its really slow and says it is searching. I will post that log file as soon as I can get to it.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Also now my norton is not starting up. Just noticed that. The system is running extremely slow eventhough my CPU is nowhere near being maxed out. WHy?

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
The log is located at C:\avenger.txt
Can you use the system in safe mode?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 3)
Fri Dec 05 11:17:45 2008

11:17:45: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "TDSSserv.sys" found!
ImagePath: \systemroot\system32\drivers\TDSSmqlt.sys
Driver disabled successfully.

Rootkit scan completed.

File "C:\Documents and Settings\Raf\Local Settings\Temp\tdss1ee9.tmp" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
that first time I forgot to copy over the files to be deleted script

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
The system is running, just extremely slow. Anything I try and do is really slow, even just going to all programs takes way longer than it used to.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
It's okay, I wasn't bothered about the temp file, I was looking for something else, and the avenger found what I wanted..
There's the rootkit, but now it's disabled, we can use combofix.


  • Download combofix from here, use the top links - combofix.exe
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    Help me remove Trojan.Knowedel PLEASE!!! - Page 1 Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes

    Help me remove Trojan.Knowedel PLEASE!!! - Page 1 Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
i think I want to try and run this thing on safe mode. That ok? How do you typically do safe mode? In the bios? I have a custombuilt system

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
A BIOS is a BIOS.
You can run combofix in safe mode. Smile...

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
it tells my that I dont have the recovery console, which I do I just disabled it. Can I just turn it on and will it detect it in safe mode? I dot want to hook the computer back to the internet with the virus still on

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Hello.
Yes, turn the console back on.
If you don't want the infected machine on the net, you will need the console should anything go wrong.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
oh well, I just tried to download it from the internet when I was prompted, it told me that it failed out and it began runnign on its own. Hopefully i dont lose everything. Its restarting now, fingers crossed

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
combo fix restarted my computer and now when I logged in, I have a blue command screen that says combo fix and a little underscore flasshing. what do I do?

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
now its says please wait and still flashing the underscore

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Okay, please wait for it to do it's run. Smile...

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
oh, ok, sorry, its running, did not realize that. Also, quick question, If i reformat this hard drive and reinstall a fresh install of windows xp, will it get rid of it? I just thinking worst case.


Now its preparig the log report.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Yes, a format would get rid of it.
But that is the last option.
We can clean it before we reach format.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
that sounds great! much better than doing that. ok, i still have mu blue screen that still says preparing log report, but it also now says do no run any progrms until ComboFix has finished.

How do i know when it is done?

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
It will open the report when it's done.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
ok, I just wanted to let you know that you and the other GP admin are really doing a great thing here. You are helping people out who dont know. I know I really appreciate it and im sure that here have been thousands that you guys have helped and there will be many more. There are just som many people out there out to harm other. I just wanted to tell you tahnk you, and you have good karma coming your way. Thank You!

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Heh, yes, I try my best.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
lol.

So its still has the blue screen. How long should it run for?

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
It sometimes takes along time.
Give it abit longer.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
so I need to leave for work unfortunately. Once this has finished, should it be gone? If not, if I come back on the forum here after work will you or somebody else be able to help me?

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Hello.
Before you leave.
There maybe an imcomplete log located here:
C:\combofix\combofix.txt

And no, I'm the only one here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
i had not clicked on anything on my computer so that I do not stall the run. I just clicked on my computer and nothing is popping up, seems to be really slow just like last time.

But the computer was really fast as usual in safe mode.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
i cant even get my computer to go to the c drive to come up. I think I will just let it run all through my shift?

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Okay.
If it's not done when your back, just close it and see if there's a log in the path I posted.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 DXwU4
Help me remove Trojan.Knowedel PLEASE!!! - Page 1 VvYDg

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
will do. Thank you very much for your help.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

............................................................................................

Please be a GeekPolice fan on Facebook!

Help me remove Trojan.Knowedel PLEASE!!! - Page 1 Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionHelp me remove Trojan.Knowedel PLEASE!!! - Page 1 EmptyRe: Help me remove Trojan.Knowedel PLEASE!!!

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum