![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#41 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 28
OS: Windows XP
|
Re: Need assistance removing NTOSKRNL-HOOK
Attachment
|
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#42 (permalink) | |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,948
OS: Windows 7 Ultimate
|
Re: Need assistance removing NTOSKRNL-HOOK
Hi rpaulie,
Open notepad and copy/paste the text in the quotebox below into it: Quote:
**** Disable your Anti-Virus software **** ![]() Referring to the picture above, drag CFScript into Combo-Fix.exe Follow the prompts, and post the resulting log, C:\ComboFix.txt Warning: Do not mouseclick combofix's window whilst it's running. That may cause it to stall -------------------------------------------------------------- Please go to Start-> run -> Copy and paste the following in bold into the text box: C:\Qoobox\ComboFix-quarantined-files.txt Click OK. Please post the results. -------------------------------------------------------------- Please reply back with the following: C:\ComboFix.txt C:\Qoobox\ComboFix-quarantined-files.txt
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum Last edited by forhockey; 07-18-2009 at 02:02 PM. |
|
|
|
|
|
#44 (permalink) |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,948
OS: Windows 7 Ultimate
|
Re: Need assistance removing NTOSKRNL-HOOK
Hi rpaulie,
Can you please post the results from: C:\Qoobox\ComboFix-quarantined-files.txt
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum |
|
|
|
|
#45 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 28
OS: Windows XP
|
Re: Need assistance removing NTOSKRNL-HOOK
Hello there.
Attached is the file you requested. Feel free to let me know if there is anything else you need 2009-07-18 02:38:08 . 2009-07-20 04 48 0 ----a-w- C:\Qoobox\Quarantine\catchme.txt2009-07-16 02:37:15 . 2009-07-16 02:37:15 750 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Notify-!SASWinLogon.reg.dat 2009-07-16 02:37:15 . 2009-07-16 02:37:15 916 ----a-w- C:\Qoobox\Quarantine\Registry_backups\ShellExecuteHooks-{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}.reg.dat 2009-07-16 02:37:11 . 2009-07-16 02:37:11 167 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-HostManager.reg.dat 2009-07-16 02:07:57 . 2009-07-16 02:07:57 1,205 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_UACd.sys.reg.dat 2009-07-15 15:14:01 . 2009-07-15 15:14:09 1,110,399 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\UACjjcuelwyexyxhnonk.db.vir 2009-07-15 15:13:59 . 2009-07-15 15:13:59 310 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\UACoqaoyxuwccnvooqcj.dat.vir 2009-07-15 15:13:58 . 2009-07-16 02:02:23 6,628 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\uacinit.dll.vir 2009-07-15 15:13:54 . 2009-07-15 15:14:12 54,784 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\UACpsejapywkixmasrln.sys.vir 2009-07-12 05:49:45 . 2009-07-12 05:49:51 1,110,399 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\UAClesijgsrtkdltgvuk.db.vir 2009-07-10 03:23:10 . 2009-07-10 03:23:10 1,010 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_ejqtsv_.dll.zip 2009-07-10 03:18:18 . 2009-07-13 04:44:46 400,651 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\_explorer_.exe.zip 2009-07-07 00:18:49 . 2009-07-15 05:23:39 96,063 ----a-w- C:\Qoobox\Quarantine\[4]-Submit_2009-07-06_20.18.31.zip 2009-07-05 14:40:20 . 2009-07-05 14:40:20 554 ----a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-mfetdik.sys.reg.dat 2009-07-05 14:40:20 . 2009-07-05 14:40:20 538 ----a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-mfetdik.reg.dat 2009-07-05 14:40:20 . 2009-07-05 14:40:20 538 ----a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-mferkdk.reg.dat 2009-07-05 14:40:20 . 2009-07-05 14:40:20 538 ----a-w- C:\Qoobox\Quarantine\Registry_backups\SafeBoot-mfehidk.reg.dat 2009-07-05 14:27:32 . 2009-07-05 14:27:32 1,305 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_hjgruiysvgrnmx.reg.dat 2009-07-03 18:00:02 . 2009-07-03 18:00:02 10,954,752 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\30ecd7.msi.vir 2009-06-29 20:41:42 . 2009-07-05 11:50:00 93 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\hjgruioentoyxr.dat.vir 2009-06-29 04:37:56 . 2009-07-05 11:50:00 89,258 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\hjgruihumhamxe.dat.vir 2009-06-29 04:37:55 . 2009-07-04 22:39:08 1 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\hjgruissamdvmq.sys.vir 2009-06-23 18:14:05 . 2009-06-23 18:14:05 110 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-sms.reg.dat 2009-06-23 18:14:05 . 2009-06-23 18:14:05 120 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-amoumain.reg.dat 2009-06-23 18:14:05 . 2009-06-23 18:14:05 111 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-odby.reg.dat 2009-06-23 18:14:05 . 2009-06-23 18:14:05 174 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-13525314.reg.dat 2009-06-23 18:14:05 . 2009-06-23 18:14:05 174 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-93535306.reg.dat 2009-06-23 18:14:04 . 2009-06-23 18:14:04 140 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-WinampAgent.reg.dat 2009-06-23 18:14:04 . 2009-06-23 18:14:04 140 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-lphc35cj0etcl.reg.dat 2009-06-23 18:14:04 . 2009-06-23 18:14:04 150 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SMrhc75cj0etcl.reg.dat 2009-06-23 18:14:04 . 2009-06-23 18:14:04 178 ----a-w- C:\Qoobox\Quarantine\Registry_backups\HKLM-Run-SpyHunter Security Suite.reg.dat 2009-06-23 18:03:09 . 2009-06-23 18:03:09 700 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_clbdriver.reg.dat 2009-06-23 18:03:09 . 2009-06-23 18:03:09 1,232 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_CLBDRIVER.reg.dat 2009-06-23 18:02:50 . 2009-07-20 04:11:42 7,503 ----a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg 2009-06-23 17:54:23 . 2009-06-23 17:54:23 1,305 ----a-w- C:\Qoobox\Quarantine\Registry_backups\Service_SKYNETounagmxs.reg.dat 2009-06-23 17:53:22 . 2009-06-23 17:53:22 169,813 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\_sdra64_.exe.zip 2009-06-23 17:46:34 . 2009-06-23 17:46:34 93 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETdtektfsx.dat.vir 2009-06-23 17:44:10 . 2009-07-20 04:05:37 2,234 ----a-w- C:\Qoobox\Quarantine\catchme.log 2009-06-21 15:37:27 . 2009-06-21 15:37:27 1,850 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Desktop\System Security 2009.lnk.vir 2009-06-21 15:30:17 . 2009-06-21 15:30:58 109 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\3905853504.dat.vir 2009-06-21 15:30:13 . 2009-06-21 15:30:13 0 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\93535306.ini.vir 2009-06-21 15:30:10 . 2009-06-21 15:30:06 40,960 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\activedsp.exe.vir 2009-06-21 15:30:07 . 2009-06-23 17:46:19 3,600 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\lowsec\local.ds.vir 2009-06-21 15:30:07 . 2009-06-23 17:52:27 4,634 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\lowsec\user.ds.lll.vir 2009-06-21 15:30:07 . 2009-06-23 17:55:11 275 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\lowsec\user.ds.vir 2009-06-17 03:12:10 . 2009-06-23 17:46:34 84,027 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\SKYNETewttewmg.dat.vir 2009-06-11 23:01:34 . 2009-06-11 23:01:34 672 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\active\cache.dat.vir 2009-06-11 23:01:34 . 2009-06-11 23:01:34 13 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\friends.config.vir 2009-06-11 23:01:34 . 2009-06-11 23:01:34 10,302 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\dht\general.dat.vir 2009-06-11 23:01:34 . 2009-06-11 23:01:34 2,762 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\net\pm_33287.dat.vir 2009-06-11 23:01:32 . 2009-06-11 23:01:32 65 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\sidebarauto.config.vir 2009-06-11 23:01:32 . 2009-06-11 23:01:32 104 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\timingstats.dat.vir 2009-06-11 23:01:25 . 2009-06-11 23:01:34 21 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\dht\diverse.dat.vir 2009-06-11 23:01:25 . 2009-06-11 23:01:34 548 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\dht\contacts.dat.vir 2009-06-11 22:56:07 . 2009-06-11 22:56:07 5,928 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22437.tmp.vir 2009-06-11 22:56:07 . 2009-06-11 22:56:07 201,271 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22436.tmp.vir 2009-06-11 22:55:59 . 2009-06-11 23:01:34 602 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\downloads.config.bak.vir 2009-06-11 22:55:07 . 2009-06-11 22:55:07 55,510 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22435.tmp.vir 2009-06-11 22:53:09 . 2009-06-11 23:01:34 150 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\azureus.statistics.bak.vir 2009-06-11 22:52:40 . 2009-06-11 22:52:40 20 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\dht\version.dat.vir 2009-06-11 22:52:39 . 2009-06-11 23:01:34 602 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\downloads.config.vir 2009-06-11 22:52:35 . 2009-06-11 22:52:35 386 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\subscriptions.config.vir 2009-06-11 22:52:35 . 2009-06-11 22:52:35 1,097 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\subs\B4AB7A24BB81B47B5226.vuze.vir 2009-06-11 22:52:34 . 2009-06-11 22:52:34 141 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\v3.Stream_1.log.vir 2009-06-11 22:52:34 . 2009-06-11 22:56:15 336 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\v3.ads_1.log.vir 2009-06-11 22:52:33 . 2009-06-11 23:00:59 8,315 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\active\AD9A604A3F94C1C03DE3FEB27839D7D73E72C434.dat.bak.vir 2009-06-11 22:52:33 . 2009-06-11 23:01:34 8,615 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\active\AD9A604A3F94C1C03DE3FEB27839D7D73E72C434.dat.vir 2009-06-11 22:52:33 . 2009-06-11 22:52:33 7,326 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\torrents\ATK_Hairy_Fun_Cameron__295.4899899.TPB.torrent.vir 2009-06-11 22:52:19 . 2009-06-11 23:01:34 14 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tracker.config.bak.vir 2009-06-11 22:52:09 . 2009-06-11 23:01:34 150 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\azureus.statistics.vir 2009-06-11 22:51:45 . 2009-06-11 22:51:45 43 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tables.config.vir 2009-06-11 22:51:40 . 2009-06-11 22:51:40 89 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\NetStatus_1.log.vir 2009-06-11 22:51:30 . 2009-06-11 22:51:30 204 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\devices.config.bak.vir 2009-06-11 22:51:25 . 2009-06-11 22:51:26 2,819 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\metasearch.config.bak.vir 2009-06-11 22:51:25 . 2009-06-11 22:51:26 3,721 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\metasearch.config.vir 2009-06-11 22:51:25 . 2009-06-11 22:51:25 65 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\dht\addresses.dat.vir 2009-06-11 22:51:24 . 2009-06-11 22:54:25 867 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\Subscriptions_1.log.vir 2009-06-11 22:51:24 . 2009-06-11 22:51:26 6,024 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\MetaSearch_1.log.vir 2009-06-11 22:51:20 . 2009-06-11 22:51:30 415 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\devices.config.vir 2009-06-11 22:51:20 . 2009-06-11 22:51:30 119 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\Devices_1.log.vir 2009-06-11 22:51:20 . 2009-06-11 22:51:20 732 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\VuzeActivities.config.vir 2009-06-11 22:51:20 . 2009-06-11 22:51:20 191 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\cnetworks.config.vir 2009-06-11 22:51:19 . 2009-06-11 22:51:19 133 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\plugins\azupnpav\cd.dat.vir 2009-06-11 22:51:19 . 2009-06-11 23:01:34 14 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tracker.config.vir 2009-06-11 22:51:15 . 2009-06-11 22:51:15 12 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\unsentdata.config.vir 2009-06-11 22:51:14 . 2009-06-11 22:54:02 820 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\v3.CMsgr_1.log.vir 2009-06-11 22:51:12 . 2009-06-11 22:51:12 195 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log.vir 2009-06-11 22:51:12 . 2009-06-11 22:51:12 117 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\net\pm_default.dat.vir 2009-06-11 22:51:11 . 2009-06-11 22:51:11 13 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\v3.Friends.dat.bak.vir 2009-06-11 22:51:10 . 2009-06-11 22:51:13 542 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\debug_1.log.vir 2009-06-11 22:51:10 . 2009-06-11 22:51:11 13 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\v3.Friends.dat.vir 2009-06-11 22:51:10 . 2009-06-11 22:56:40 1,939 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\v3.Friends_1.log.vir 2009-06-11 22:51:10 . 2009-06-11 23:01:34 395 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\Friends_1.log.vir 2009-06-11 22:51:10 . 2009-06-11 22:52:36 39 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22434.tmp.vir 2009-06-11 22:51:10 . 2009-06-11 23:01:34 557 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22432.tmp.vir 2009-06-11 22:51:10 . 2009-06-11 22:51:10 0 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22433.tmp.vir 2009-06-11 22:51:09 . 2009-06-11 23:01:28 10,641 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22431.tmp.vir 2009-06-11 22:51:09 . 2009-06-11 22:51:26 4,269 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22429.tmp.vir 2009-06-11 22:51:09 . 2009-06-11 23:01:34 4,473 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22430.tmp.vir 2009-06-11 22:51:09 . 2009-06-11 22:53:05 292 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22428.tmp.vir 2009-06-11 22:51:09 . 2009-06-11 22:51:17 36 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\tmp\AZU22427.tmp.vir 2009-06-11 22:51:09 . 2009-06-11 22:51:20 283 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\CNetworks_1.log.vir 2009-06-11 22:51:09 . 2009-06-11 22:51:09 20 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\All Users\Application Data\Azureus\azCID.txt.vir 2009-06-11 22:51:09 . 2009-06-11 22:52:34 14,102 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\v3.PMsgr_1.log.vir 2009-06-11 22:51:08 . 2009-06-11 22:51:08 0 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\ipfilter.cache.vir 2009-06-11 22:51:08 . 2009-06-11 22:51:27 6,701 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\seltrace_1.log.vir 2009-06-11 22:51:08 . 2009-06-11 23:01:28 7,473 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\logs\thread_1.log.vir 2009-06-11 22:51:08 . 2009-06-11 23:01:37 3,489 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\azureus.config.bak.vir 2009-06-11 22:51:07 . 2009-06-11 22:51:07 32 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\.certs.vir 2009-06-11 22:51:07 . 2009-06-11 22:51:07 32 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\.keystore.vir 2009-06-11 22:51:06 . 2009-06-11 23:01:37 3,489 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\azureus.config.vir 2009-06-11 22:51:06 . 2009-06-11 22:51:06 0 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Azureus\.lock.vir 2009-06-06 05:35:02 . 2009-07-07 00:18:44 16,141 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Apple Computer\lego.exe.vir 2009-06-06 05:35:02 . 2009-07-07 00:18:40 145,131 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\AdobeUM\nomad.exe.vir 2009-06-06 05:35:01 . 2009-06-06 05:35:01 422 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\Adobe\socks1.exe.vir 2009-06-06 05:35:01 . 2009-07-07 00:18:36 11,232 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\acccore\shalom.exe.vir 2009-05-25 23:22:14 . 2009-05-29 21:43:12 4 ----a-w- C:\Qoobox\Quarantine\C\Documents and Settings\Paul Jacobsen\Application Data\wiaserva.log.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\12b14613.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1447d5.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\14750a9.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\148e646c.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\163ffbe.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\169ba1c.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\187834b.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\18ec15c.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\19b53a8e.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\19fb5.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1a4ab48.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1a831.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1aac51c.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1b67a.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1d5c9.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1d925.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1ea325b.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1edc0e2f.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\1f87e25.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\21217.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\21ec9.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\22f43.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\2402a7f3.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\28ae1.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\28f36.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\2928c40c.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\2a514.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\2ab1b.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\2e4f1b1a.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\3269317.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\3375b349.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\33856c3.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\33951.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\389c3c54.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\3d7da3.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\3deff5.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4006a.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\43c17a6.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4913e99.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\4d26bb.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\51b4001.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\6497f.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\66dca72.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\6737f3.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\7070e9.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\7e576.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\801be.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\8d570b.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\923bba.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\9d20ca.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\a41665b.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\c667fe.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\f1ba.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\f680fa0.msp.vir 2009-05-12 17:01:38 . 2009-05-12 17:01:38 6,818,816 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\Installer\fa1cd2.msp.vir 2008-07-11 19:04:06 . 2008-07-11 19:30:37 1,774,066 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\iwyfgbyr.ini.vir 2008-07-07 21:11:50 . 2008-07-11 18:59:36 1,701,955 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\fvkojnwj.ini.vir 2008-07-03 15:10:48 . 2008-07-03 15:13:49 1,597,283 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\ouxeniew.ini.vir 2008-06-29 23:59:54 . 2008-07-03 15:10:36 1,597,163 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\ibfauvsr.ini.vir 2008-06-29 19:29:30 . 2008-07-11 19:30:55 2,228 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\cookies.ini.vir 2008-06-29 16:10:57 . 2008-06-29 22:51:28 1,624,691 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\dvydgjgx.ini.vir 2008-06-20 11:51:12 . 2008-06-20 11:51:12 361,600 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\dllcache\tcpip.sys.vir 2006-12-29 22:54:52 . 2006-03-21 03:23:12 23,040 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\kb913800.exe.vir 2005-08-16 09:18:45 . 2008-04-14 00:12:39 512,000 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\winlogon.exe.vir 2005-08-16 09:18:41 . 2008-06-20 11:51:12 361,600 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\tcpip.sys.vir 2005-08-16 09:18:40 . 2009-07-08 07:20:40 16,896 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\svchost.exe.vir 2005-08-16 09:18:40 . 2009-07-03 16:58:40 58,368 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\spoolsv.exe.vir 2005-08-16 09:18:36 . 2009-07-07 07:29:39 112,640 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\services.exe.vir 2005-08-16 09:18:22 . 2009-07-07 07:29:39 14,336 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\lsass.exe.vir 2005-08-16 09:18:21 . 2009-03-21 14 58 32,768 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\ejqtsv.dll.vir2005-08-16 09:18:17 . 2008-04-14 00:12:19 1,033,728 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\explorer.exe.vir 2005-08-16 04:27:00 . 2009-07-18 02:43:32 8,388,608 ----a-w- C:\Qoobox\Quarantine\C\WINDOWS\ERDNT\MoveEx_SysHive_link.vir |
|
|
|
|
#46 (permalink) |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,948
OS: Windows 7 Ultimate
|
Re: Need assistance removing NTOSKRNL-HOOK
Hello,
Things are looking good. Now to scan for any remnants that may have been missed. Perform an online scan with Panda ActiveScan
* Turn off the real time scanner of any existing antivirus program while performing the online scan Also, if you can update me on how your system is behaving
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum Last edited by forhockey; 07-21-2009 at 10:01 PM. |
|
|
|
|
#47 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 28
OS: Windows XP
|
Re: Need assistance removing NTOSKRNL-HOOK
Hello there,
Attached is the report you requested. My PC is running ok, but very sluggish. Commands take longer than they normally would, but I'm just happy everything is working to be honest. Thanks again |
|
|
|
|
#48 (permalink) |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,948
OS: Windows 7 Ultimate
|
Re: Need assistance removing NTOSKRNL-HOOK
Hello rpaulie,
What do you mean by "Commands take longer than they normally would"?
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum |
|
|
|
|
#49 (permalink) |
|
Registered User
Join Date: Jul 2009
Posts: 28
OS: Windows XP
|
Re: Need assistance removing NTOSKRNL-HOOK
Hello forhockey,
My apologies, after a few days everything appears great! At first I thought the computer itself was just running slower but it all seems to be working properly. THANK YOU SO MUCH!!!! |
|
|
|
|
#50 (permalink) |
|
Analyst, Security Team
Join Date: Sep 2006
Location: Ontario, Canada
Posts: 2,948
OS: Windows 7 Ultimate
|
Re: Need assistance removing NTOSKRNL-HOOK
Well done, your logs are clean! There are just a few more things I would like you to do.
The following procedure will clear out ComboFix.exe, as well as the backups and quarantines created by the fix. It will also reset your System Restore by flushing out previous restore points (which contain the infections) and create a new restore point. Click Start > Run and copy/paste, or type the following bolded text into the Run box and click OK: ComboFix /u ---------------------------------------------------------------- Microsoft Updates It is very important that you get all of the critical updates for your Operating System and Internet Explorer. Keeping your OS and browser up to date will help make you less susceptible to attacks by Trojans and viruses. Please go to Microsoft and download all the critical updates to help prevent possible re-infection. Malware Prevention Tools These programs configure your computer to prevent known malware-related changes. You can have more than one of these at a time and they take up minimal resources.
Alternative Web Browsers Using an alternative browser can help prevent malware from being installed without your knowledge, but may not work on all websites. Firewalls If you do not have a firewall, here are a few free ones available for personal use: Understanding and Using Firewalls Informational Reading In light of your recent troubles, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles:
Please respond to this thread one more time so we can mark this thread as resolved.
__________________
![]() Proud Member of ASAP Proud Member of UNITE Keep this forum alive - if you've been helped at this forum, please do consider a donation. Thank you for your support. Donation link for Tech Support Forum Last edited by forhockey; 08-04-2009 at 06:05 PM. |
|
|
| Thread Tools | |
|
|