WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 Empty(log) 2

more_horiz
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-01-15 61440]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\1154365368\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1154365368\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f816e9-20c0-11db-a73d-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{148a67e6-98fa-11dd-81ac-001676673357}]
shell\AutoRun\command - F:\LaunchU3.exe -a

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a001031-20b3-11db-b386-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88636a5e-20bc-11db-b389-00038a000015}]
shell\1\command - .\RECYCLER\RECYCLER\autorun.exe
shell\2\command - .\RECYCLER\RECYCLER\autorun.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3f14450-98ea-11dd-81a8-001676673357}]
shell\AutoRun\command - H:\LaunchU3.exe -a


======List of files/folders created in the last 1 months======

2008-12-06 16:57:23 ----D---- C:\rsit
2008-12-06 16:53:59 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-12-06 16:53:47 ----D---- C:\Program Files\AVG
2008-12-05 20:37:08 ----D---- C:\Program Files\Symantec
2008-12-05 20:37:03 ----D---- C:\WINDOWS\Sun
2008-12-05 20:36:37 ----D---- C:\Config.Msi
2008-12-05 19:41:15 ----D---- C:\!KillBox
2008-12-05 13:40:03 ----D---- C:\Program Files\Trend Micro
2008-12-05 13:24:26 ----D---- C:\WINDOWS\pss
2008-12-05 13:04:21 ----D---- C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-12-05 13:04:08 ----D---- C:\Program Files\Lavasoft
2008-12-05 12:50:14 ----D---- C:\Documents and Settings\Owner\Application Data\MSNInstaller
2008-12-05 12:42:34 ----D---- C:\Documents and Settings\All Users\Application Data\Avg8
2008-12-04 22:05:29 ----D---- C:\Documents and Settings\Owner\Application Data\Sun
2008-12-04 21:05:41 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-04 15:56:02 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-12-04 15:55:25 ----D---- C:\Program Files\Mozilla Firefox
2008-12-03 21:45:45 ----D---- C:\Documents and Settings\Owner\Application Data\Help
2008-12-03 20:47:27 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-03 16:47:10 ----A---- C:\LOG3.tmp
2008-12-03 09:43:11 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-03 09:41:58 ----D---- C:\Program Files\WebMediaViewer
2008-11-22 12:17:47 ----D---- C:\Program Files\Perfect World Entertainment
2008-11-22 12:16:12 ----A---- C:\WINDOWS\system32\unicows.dll
2008-11-22 12:01:10 ----D---- C:\PW_International
2008-11-20 00:37:20 ----D---- C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-11-19 00:32:10 ----A---- C:\LOG2E.tmp
2008-11-12 00:11:41 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-12 00:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-12 00:11:25 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-11-12 00:11:23 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
======List of files/folders modified in the last 1 months======

2008-12-06 16:53:59 ----D---- C:\WINDOWS\system32
2008-12-06 16:53:58 ----D---- C:\WINDOWS\system32\drivers
2008-12-06 16:53:47 ----D---- C:\Program Files
2008-12-06 16:52:47 ----D---- C:\WINDOWS
2008-12-05 20:40:51 ----D---- C:\WINDOWS\Temp
2008-12-05 20:40:46 ----A---- C:\WINDOWS\win.ini
2008-12-05 20:37:08 ----SHD---- C:\WINDOWS\Installer
2008-12-05 20:37:08 ----D---- C:\Documents and Settings\Owner\Application Data\SanDisk
2008-12-05 20:37:03 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-05 20:36:40 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-12-05 20:31:53 ----SHD---- C:\RECYCLER
2008-12-05 20:26:59 ----D---- C:\WINDOWS\Prefetch
2008-12-05 19:58:54 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2008-12-05 19:21:05 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-12-05 19:16:55 ----D---- C:\WINDOWS\system32\CatRoot2
2008-12-05 13:23:23 ----D---- C:\Documents and Settings\All Users\Application Data\QuickTime
2008-12-05 13:04:13 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-12-05 13:02:25 ----HD---- C:\WINDOWS\inf
2008-12-05 12:51:14 ----D---- C:\Documents and Settings\All Users\Application Data\Napster
2008-12-05 12:50:17 ----D---- C:\Program Files\MSN
2008-12-05 12:44:53 ----D---- C:\Program Files\Common Files
2008-12-04 22:24:07 ----A---- C:\WINDOWS\WinDrvGhost.ini
2008-12-04 22:19:35 ----RASH---- C:\boot.ini
2008-12-04 21:04:54 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2008-12-04 19:55:29 ----D---- C:\Program Files\Gateway Games
2008-12-04 16:19:37 ----D---- C:\Documents and Settings
2008-12-03 22:12:14 ----D---- C:\WINDOWS\network diagnostic
2008-12-03 20:19:23 ----D---- C:\Program Files\CyberLink
2008-12-03 20:19:02 ----HD---- C:\Program Files\InstallShield Installation Information
2008-12-03 17:00:14 ----D---- C:\WINDOWS\WinSxS
2008-12-03 17:00:14 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-12-03 16:47:50 ----D---- C:\Documents and Settings\Owner\Application Data\U3
2008-12-02 07:59:23 ----D---- C:\WINDOWS\system32\wbem
2008-12-02 07:59:23 ----AS---- C:\WINDOWS\system32\gtckad.dll
2008-12-02 07:59:22 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-12-02 07:59:20 ----SD---- C:\Documents and Settings\Owner\Application Data\Microsoft
2008-11-17 20:47:15 ----D---- C:\WINDOWS\Help
2008-11-12 00:11:44 ----A---- C:\WINDOWS\imsins.BAK
2008-11-12 00:11:40 ----HD---- C:\WINDOWS\$hf_mig$
2008-11-09 23:38:42 ----A---- C:\WINDOWS\PhotoSnapViewer.INI

======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2004-11-10 44288]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2004-11-10 24832]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 RTL8023xp;Realtek 10/100/1000 NIC Family all in one NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys [2006-01-18 80512]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
R3 WinDriver6;WinDriver6; C:\WINDOWS\system32\drivers\windrvr6.sys [2005-11-16 333620]
S1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-12-06 97928]
S1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-12-06 26824]
S1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
S2 EZUSB;Cypress General Purpose USB Driver (ezusb.sys); C:\WINDOWS\System32\drivers\ezusb.sys [2004-08-19 12307]
S2 ispDev;ispDev; C:\WINDOWS\System32\drivers\isp.sys [2004-08-19 72060]
S2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
S2 XilinxPC4Driver;XilinxPC4Driver; C:\WINDOWS\System32\drivers\XPC4DRVR.SYS [2005-11-16 16000]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
S3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2006-01-15 1477632]
S3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-13 13952]
S3 el575nd5;3Com Megahertz 10/100 LAN CardBus PC Card Driver; C:\WINDOWS\system32\DRIVERS\el575nd5.sys [2001-08-17 69692]
S3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.sys [2005-03-17 1033600]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2005-03-17 221440]
S3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-04-06 4258816]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
S3 NPDriver;Norton Unerase Protection Driver; \??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS []
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-13 79232]
S3 Ser2pl;Prolific Serial port driver; C:\WINDOWS\system32\DRIVERS\ser2pl.sys [2003-07-15 43264]
S3 sermouse;Serial Mouse Driver; C:\WINDOWS\system32\DRIVERS\sermouse.sys [2001-08-17 17664]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-03-17 705280]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]

======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

S2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2006-01-15 405504]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2006-01-26 520192]
S2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-12-06 231704]
S2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-02-22 38912]
S2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
S2 NProtectService;Norton Unerase Protection; C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE []
S2 PrismXL;PrismXL; C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS [2006-07-31 172032]
S2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 getPlus(R) Helper;getPlus(R) Helper; C:\Program Files\NOS\bin\getPlus_HelperSvc.exe [2008-08-29 33752]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]

-----------------EOF-----------------

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Hello.
Do you have any external drives, because they are infected.

Missed a few leftovers.

Please download the OTMoveIt3 by OldTimer.

  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


    :processes
    explorer.exe

    :files
    C:\WINDOWS\tasks\Symantec NetDetect.job
    C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job
    C:\!KillBox
    C:\Program Files\WebMediaViewer

    :reg
    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "Advanced Tools Check"=-
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f816e9-20c0-11db-a73d-806d6172696f}]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a001031-20b3-11db-b386-806d6172696f}]
    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88636a5e-20bc-11db-b389-00038a000015}]

    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]



  • Return to OTMoveIt3, right click in the "Paste instructions for items to be Moved" window (under the light blue bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

Please post the OTMoveIt log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\WINDOWS\tasks\Symantec NetDetect.job moved successfully.
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job moved successfully.
C:\!KillBox\Symantec\LiveUpdate moved successfully.
C:\!KillBox\Symantec moved successfully.
C:\!KillBox\Norton AntiVirus\Quarantine\Portal moved successfully.
C:\!KillBox\Norton AntiVirus\Quarantine\Incoming moved successfully.
C:\!KillBox\Norton AntiVirus\Quarantine moved successfully.
C:\!KillBox\Norton AntiVirus\AdvTools moved successfully.
C:\!KillBox\Norton AntiVirus moved successfully.
C:\!KillBox\Logs moved successfully.
C:\!KillBox moved successfully.
C:\Program Files\WebMediaViewer moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Advanced Tools Check deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_BQ9yakkGBSQlKhcvImFV scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12062008_171620

Files moved on Reboot...
File C:\DOCUME~1\Owner\LOCALS~1\Temp\etilqs_BQ9yakkGBSQlKhcvImFV not found!
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Owner\Local Settings\Application Data\Mozilla\Firefox\Profiles\ams7gv7r.default\urlclassifier3.sqlite moved successfully.

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Should be okay now, any problems still going on?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Unfortunately it still doesn't work. Either that or Im impatient. The only way I can currently access the internet is through the "Safe Mode Networking" option on startup. If I startup normally, the firefox and internet explorer applications won't even open up. The task manager doesn't even recognize them as activated.

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Hmmm, then this isn't malwares fault.
The logs look clean, but I know the tdss rootkit can hide from tools, so lets see what this does.


  • Download combofix from here, use the top links - combofix.exe
  • Double click on ComboFix.exe.
  • Follow the prompts. NOTE:
  • ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
    ***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.


  • The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.

    My internet will not run properly after I removed VirusResponce2009 - Page 1 Rcauto10

  • Allow ComboFix to download the Recovery Console.
  • Accept the End-User License Agreement.
  • The Recovery Console will be installed.
  • You will this next prompt that asks if you want to continue the malware scan, select yes

    My internet will not run properly after I removed VirusResponce2009 - Page 1 Whatne10

  • Allow combofix to run
  • Post C:\combofix.txt back here.

    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Nothing changed. It's just really strange to me that there is a connection, but the applications will not open. If I can go online in safemode, then there is obviously something stopping me from doing it normally.

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Hello.
In safe mode, press Start > Run
Type this in:
sfc /scannow <== notepad the space after c and before /
Press enter.

Allow it to scan and try normal mode again.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Ok, after running that, a black window opened and closed quickly, so I don't know if it scanned or not. But, some progress has been made. I can open IE, but it still doesn't connect. It remains a blank page and has an error when I try to close it. Firefox still will not startup.

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
We may be able to repair the net connection, but I can only suggest uninstall Firefox then re-install it.

Let me know if you can get Firefox running, then we'll try to repair the net connection.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
No good. Nothing really changed at all. I think there are probably some damaged files concerning opening applications or something. Now how do we proceed?

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Download Winsock XPFix from here:
http://www.snapfiles.com/get/winsockxpfix.html

Open the program and select "Fix".
Try the net again.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Nothing. Like I said before, I can access the internet in the networking on safemode (Im on the same computer) so there is a connection. there is something there blocking me from utilizing the applications I think. I tried to open MSWord as a test and it began the startup then froze. I can't use my applications unless Im in safemode.

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Okay, give me a few hours and i'll do some research and ask around and see what I can dig up.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
My internet will not run properly after I removed VirusResponce2009 - Page 1 DXwU4
My internet will not run properly after I removed VirusResponce2009 - Page 1 VvYDg

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Ok thanks

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Hey, I had a friend format and reinstall Windows for me so all is well now. Thank you for all of your help! I'm sorry to have made you research for nothing....

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
Since this issue is resolved, this topic is closed.

If you need this topic reopened, please contact a staff member. This applies only to the original topic starter.

Everyone else, please open a new topic for your questions.

............................................................................................

Please be a GeekPolice fan on Facebook!

My internet will not run properly after I removed VirusResponce2009 - Page 1 Lambo-11

Have we helped you? Help us! | Doctor by day, ninja by night.

descriptionMy internet will not run properly after I removed VirusResponce2009 - Page 1 EmptyRe: My internet will not run properly after I removed VirusResponce2009

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum