Jump to content

Malwarebytes

Need help

- - - - -

5 replies to this topic

#1
Tammy

    New Member

  • Members
  • Pip
  • 5 posts
  • Gender:Female
  • Location:USA
I think I know what to wipe from the list but I want to make sure because once its done it can't be fixed. Its the only one that says .sys right?




Path: c:\documents and settings\tammy\local settings\temp\~dfca20.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~df8ffe.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfa16.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfa8d0.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfaef6.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfaf09.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\UACmd.exe
Status: Invisible to the Windows API!

Path: c:\documents and settings\compaq_owner\local settings\history\history.ie5\index.dat
Status: Allocation size mismatch (API: 86016, Raw: 65536)

Path: c:\documents and settings\compaq_owner\local settings\temporary internet files\content.ie5\index.dat
Status: Allocation size mismatch (API: 724992, Raw: 708608)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1326.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1327.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1328.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1329.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\log[1]
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\getAds[1].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\story[1].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\ikonboard[1].txt
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Tammy\Application Data\Macromedia\Flash Player\#SharedObjects\U44G26LJ\redir.adap.tv
Status: Visible to the Windows API, but not on disk.




Thanks in Advance <_<

#2
Tammy

    New Member

  • Members
  • Pip
  • 5 posts
  • Gender:Female
  • Location:USA

View PostTammy, on Aug 2 2009, 08:52 PM, said:

I think I know what to wipe from the list but I want to make sure because once its done it can't be fixed. Its the only one that says .sys right?


ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/08/02 14:39
Program Version: Version 1.3.3.0
Windows Version: Windows XP SP3
==================================================

Hidden/Locked Files
-------------------
Path: C:\WINDOWS\Temp\UACdd8e.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\Temp\UACedcb.tmp
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACcbxdoouqav.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\uacinit.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACiwmjqkkspb.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UAClnqvnmbnev.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACmrfocetmtl.dll
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACrfwkeqdtkl.db
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACstnxgmbavj.dat
Status: Invisible to the Windows API!

Path: C:\WINDOWS\system32\UACxcxbirxcky.dll
Status: Invisible to the Windows API!

Path: C:\Program Files\Yahoo! Games\Elf Bowling 7 - The Last Insult\ElfBowling.exe:{E4F14643-2D6E-42E1-354B-B025A2387607}
Status: Visible to the Windows API, but not on disk.

Path: C:\WINDOWS\system32\drivers\UACwbutextpby.sys
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Compaq_Owner\Local Settings\Temp\UACe7c8.tmp
Status: Invisible to the Windows API!

Path: c:\documents and settings\kaitlin\local settings\temp\~df21e7.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\kaitlin\local settings\temp\~df2d82.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\kaitlin\local settings\temp\~df4bad.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\kaitlin\local settings\temp\~df4edd.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\networkservice\local settings\temp\perflib_perfdata_164.dat
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~df2897.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~df3b4e.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~df4e88.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfca20.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~df8ffe.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfa16.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfa8d0.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfaef6.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: c:\documents and settings\tammy\local settings\temp\~dfaf09.tmp
Status: Allocation size mismatch (API: 16384, Raw: 0)

Path: C:\Program Files\Microsoft SQL Server\90\Setup Bootstrap\UACmd.exe
Status: Invisible to the Windows API!

Path: c:\documents and settings\compaq_owner\local settings\history\history.ie5\index.dat
Status: Allocation size mismatch (API: 86016, Raw: 65536)

Path: c:\documents and settings\compaq_owner\local settings\temporary internet files\content.ie5\index.dat
Status: Allocation size mismatch (API: 724992, Raw: 708608)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1326.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1327.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1328.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: c:\program files\microsoft sql server\mssql.1\mssql\log\log_1329.trc
Status: Allocation size mismatch (API: 4096, Raw: 0)

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\log[1]
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\getAds[1].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\story[1].htm
Status: Invisible to the Windows API!

Path: C:\Documents and Settings\Tammy\Local Settings\Temporary Internet Files\Content.IE5\6VV267LJ\ikonboard[1].txt
Status: Visible to the Windows API, but not on disk.

Path: C:\Documents and Settings\Tammy\Application Data\Macromedia\Flash Player\#SharedObjects\U44G26LJ\redir.adap.tv
Status: Visible to the Windows API, but not on disk.




Thanks in Advance <_<


#3
Tammy

    New Member

  • Members
  • Pip
  • 5 posts
  • Gender:Female
  • Location:USA
Can someone help please...I've tried many things. Mbam won't finish installing or run. I'm out of options

#4
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Hi Tammy,

Sorry for the delay but we're just overflowing with requests for help from too many users.

[indent]Please visit this webpage for instructions for downloading ComboFix to your DESKTOP : how-to-use-combofix
Please ensure you read this guide carefully and install the Recovery Console first.
NOTE!!: You must save and run ComboFix.exe on your DESKTOP and not from any other folder.
Also, DO NOT click the mouse or launch any other applications while this is running or it may stall the program

Additional links to download the tool:
ComboFix.exe
ComboFix.exe
ComboFix.exe


Note: The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

Once installed, you should see a blue screen prompt that says:

The Recovery Console was successfully installed.

Please continue as follows:
  • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
  • Click Yes to allow ComboFix to continue scanning for malware.
  • When the tool is finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a new HijackThis log so we may continue cleaning the system.
[/indent]
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#5
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Hi Tammy,

Please post an update on this. Thanks.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.

#6
AdvancedSetup

    Forum Deity

  • Administrators
  • PipPipPipPipPipPip
  • 22,575 posts
  • Gender:Male
  • Location:US
Due to the lack of feedback this Topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

The fixes and advice in this thread are for this machine only. Do not apply the instructions from this thread to your own machine. Please start a new thread describing your issue and someone will be along to assist you.
Ron Lewis
Manager, Online Support

Posted Image

Follow us: Twitter, Become a fan: Facebook

If you've posted to the HJT forum and it has been over 5 days without a response please send a Private Message asking for assistance.





1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users

Follow Us