Spywareblaster_use
September 26th, 2009, 05:10 PM
Dell Precision 340 Workstation
_______________________________________
Windows 2000 Professional
5.00.2195
Service Pack 4
_______________________________________
Mozilla FireFox
Version: 3.5.3
_______________________________________
Internet Explorer
Version: 6.0.2800.1106
_______________________________________
ESET NOD32 Antivirus 4.0.417.0
_______________________________________
SUPERAntiSpyware
_______________________________________
Malwarebytes' Anti-Malware
_______________________________________
SysInspector by ESET
_______________________________________
Avenger
_______________________________________
GMER
_______________________________________
ComboFix
_______________________________________
SpywareBlaster
version 4.2
______________________________________________________________
After re-starting SpywareBlaster I repeatedly notice under "SpywareBlaster Protection Status" on the "Restricted Sites" line the following message..........
"1 items have protection disabled".
The item is as follows:
ITEM NAME: AntiMalwareGuard
ADDRESS: antimalwareguard.com
This is happening despite the fact that I (earlier) in the same day already clicked on "Enable all protection" link in SpywareBlaster.
1) Why is this occurring?
2) What can I do to solve this problem?
3) Is this related to the following message that I keep seeing after running ComboFix as in the ComboFix Log:
"c:\winnt\system32\comres.dll . . . is infected!!"
4) Is this related to the messages that I receive after running Avenger?
"Error: file "C:\WINNT\system32\CF15096.exe" not found!
Deletion of file "C:\WINNT\system32\CF15096.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF25469.exe" not found!
Deletion of file "C:\WINNT\system32\CF25469.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF9828.exe" not found!
Deletion of file "C:\WINNT\system32\CF9828.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF6762.exe" not found!
Deletion of file "C:\WINNT\system32\CF6762.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF9462.exe" not found!
Deletion of file "C:\WINNT\system32\CF9462.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist"
5) Is this related to the following results that I receive after opening GMER:
TYPE: "Service"
Name: "C:\WINNT\system32\clipsrv.exe? (*** hidden ***)"
Value: "(MANUAL)" ClipSrv
-------------------------------------------------------------------------
TYPE: "Service"
Name: "C:\WINNT\system32\MSTask.exe? (*** hidden ***)"
Value: "(AUTO)" Schedule
PS. GMER typically highlights the above results in RED.
_______________________________________
Windows 2000 Professional
5.00.2195
Service Pack 4
_______________________________________
Mozilla FireFox
Version: 3.5.3
_______________________________________
Internet Explorer
Version: 6.0.2800.1106
_______________________________________
ESET NOD32 Antivirus 4.0.417.0
_______________________________________
SUPERAntiSpyware
_______________________________________
Malwarebytes' Anti-Malware
_______________________________________
SysInspector by ESET
_______________________________________
Avenger
_______________________________________
GMER
_______________________________________
ComboFix
_______________________________________
SpywareBlaster
version 4.2
______________________________________________________________
After re-starting SpywareBlaster I repeatedly notice under "SpywareBlaster Protection Status" on the "Restricted Sites" line the following message..........
"1 items have protection disabled".
The item is as follows:
ITEM NAME: AntiMalwareGuard
ADDRESS: antimalwareguard.com
This is happening despite the fact that I (earlier) in the same day already clicked on "Enable all protection" link in SpywareBlaster.
1) Why is this occurring?
2) What can I do to solve this problem?
3) Is this related to the following message that I keep seeing after running ComboFix as in the ComboFix Log:
"c:\winnt\system32\comres.dll . . . is infected!!"
4) Is this related to the messages that I receive after running Avenger?
"Error: file "C:\WINNT\system32\CF15096.exe" not found!
Deletion of file "C:\WINNT\system32\CF15096.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF25469.exe" not found!
Deletion of file "C:\WINNT\system32\CF25469.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF9828.exe" not found!
Deletion of file "C:\WINNT\system32\CF9828.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF6762.exe" not found!
Deletion of file "C:\WINNT\system32\CF6762.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist
Error: file "C:\WINNT\system32\CF9462.exe" not found!
Deletion of file "C:\WINNT\system32\CF9462.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist"
5) Is this related to the following results that I receive after opening GMER:
TYPE: "Service"
Name: "C:\WINNT\system32\clipsrv.exe? (*** hidden ***)"
Value: "(MANUAL)" ClipSrv
-------------------------------------------------------------------------
TYPE: "Service"
Name: "C:\WINNT\system32\MSTask.exe? (*** hidden ***)"
Value: "(AUTO)" Schedule
PS. GMER typically highlights the above results in RED.