Forums
New posts
Search forums
News
Security News
Technology News
Giveaways
Giveaways, Promotions and Contests
Discounts & Deals
Reviews
Users Reviews
Video Reviews
Support
Windows Malware Removal Help & Support
Inactive Support Threads
Mac Malware Removal Help & Support
Mobile Malware Removal Help & Support
Blog
Log in
Register
What's new
Search
Search titles only
By:
Search titles only
By:
Reply to thread
Menu
Install the app
Install
JavaScript is disabled. For a better experience, please enable JavaScript in your browser before proceeding.
You are using an out of date browser. It may not display this or other websites correctly.
You should upgrade or use an
alternative browser
.
Forums
Support
Windows Malware Removal Help & Support
Win32 download virus/Rogue Agent/Gen-Nullo - Spybot & SAS not succeeding in removal
Message
<blockquote data-quote="pashatemur" data-source="post: 132085" data-attributes="member: 10581"><p>Here is the Farbar scan pasted in message:</p><p></p><p>Farbar Service Scanner Version: 04-08-2013</p><p>Ran by pashatemur (administrator) on 09-08-2013 at 22:25:47</p><p>Running from "C:\Users\pashatemur\Downloads"</p><p>Windows Vista (TM) Home Premium (X86)</p><p>Boot Mode: Normal</p><p>****************************************************************</p><p></p><p>Internet Services:</p><p>============</p><p></p><p>Connection Status:</p><p>==============</p><p>Localhost is accessible.</p><p>LAN connected.</p><p>Google IP is accessible.</p><p>Google.com is accessible.</p><p>Yahoo.com is accessible.</p><p></p><p></p><p>Windows Firewall:</p><p>=============</p><p></p><p>Firewall Disabled Policy: </p><p>==================</p><p></p><p></p><p>System Restore:</p><p>============</p><p></p><p>System Restore Disabled Policy: </p><p>========================</p><p></p><p></p><p>Security Center:</p><p>============</p><p></p><p></p><p>Windows Update:</p><p>============</p><p></p><p>Windows Autoupdate Disabled Policy: </p><p>============================</p><p></p><p></p><p>Windows Defender:</p><p>==============</p><p>WinDefend Service is not running. Checking service configuration:</p><p>The start type of WinDefend service is set to Demand. The default start type is Auto.</p><p>The ImagePath of WinDefend service is OK.</p><p>The ServiceDll of WinDefend service is OK.</p><p></p><p></p><p>Other Services:</p><p>==============</p><p></p><p></p><p>File Check:</p><p>========</p><p>C:\Windows\system32\nsisvc.dll => MD5 is legit</p><p>C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit</p><p>C:\Windows\system32\dhcpcsvc.dll => MD5 is legit</p><p>C:\Windows\system32\Drivers\afd.sys => MD5 is legit</p><p>C:\Windows\system32\Drivers\tdx.sys => MD5 is legit</p><p>C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit</p><p>C:\Windows\system32\dnsrslvr.dll => MD5 is legit</p><p>C:\Windows\system32\mpssvc.dll => MD5 is legit</p><p>C:\Windows\system32\bfe.dll => MD5 is legit</p><p>C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit</p><p>C:\Windows\system32\SDRSVC.dll => MD5 is legit</p><p>C:\Windows\system32\vssvc.exe => MD5 is legit</p><p>C:\Windows\system32\wscsvc.dll => MD5 is legit</p><p>C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit</p><p>C:\Windows\system32\wuaueng.dll => MD5 is legit</p><p>C:\Windows\system32\qmgr.dll => MD5 is legit</p><p>C:\Windows\system32\es.dll => MD5 is legit</p><p>C:\Windows\system32\cryptsvc.dll => MD5 is legit</p><p>C:\Program Files\Windows Defender\MpSvc.dll</p><p>[2007-10-18 17:12] - [2007-10-18 17:12] - 0265912 ____A (Microsoft Corporation) 0D5AD0E71FF5DDAC5DD2F443B499ABD0</p><p></p><p>C:\Windows\system32\ipnathlp.dll => MD5 is legit</p><p>C:\Windows\system32\iphlpsvc.dll</p><p>[2010-04-14 17:42] - [2010-02-18 07:19] - 0179712 ____A (Microsoft Corporation) ECC9AD72CFC4AB41CF6A9BCC11F9FEF6</p><p></p><p>C:\Windows\system32\svchost.exe => MD5 is legit</p><p>C:\Windows\system32\rpcss.dll => MD5 is legit</p><p></p><p></p><p>**** End of log ****</p></blockquote><p></p>
[QUOTE="pashatemur, post: 132085, member: 10581"] Here is the Farbar scan pasted in message: Farbar Service Scanner Version: 04-08-2013 Ran by pashatemur (administrator) on 09-08-2013 at 22:25:47 Running from "C:\Users\pashatemur\Downloads" Windows Vista (TM) Home Premium (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Demand. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll [2007-10-18 17:12] - [2007-10-18 17:12] - 0265912 ____A (Microsoft Corporation) 0D5AD0E71FF5DDAC5DD2F443B499ABD0 C:\Windows\system32\ipnathlp.dll => MD5 is legit C:\Windows\system32\iphlpsvc.dll [2010-04-14 17:42] - [2010-02-18 07:19] - 0179712 ____A (Microsoft Corporation) ECC9AD72CFC4AB41CF6A9BCC11F9FEF6 C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** [/QUOTE]
Insert quotes…
Verification
Post reply
Top