Home > Need Help > Need Help Removing Cn911.exe

Need Help Removing Cn911.exe

Thread Status: Not open for further replies. CS:8e2e IP:0143 OP:Be ba 03 05 8e. Hear is what it looked like. ( I will post the new one after.)Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:54:37 AM, on 7/15/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\taskrgm.exe,O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dllO2 - BHO: (no this contact form

when i went E:/Tools/Folder Options and clicked “Show hidden files and folders” and uncheked “Hide protected operating system files", i saw the files: RavMonE which is an application, AUTORUN, msvcr71.dll and It is so USEFUL. Please re-enable javascript to access full functionality. TechEBlog Tutorials/Guides A Guide to removing Chinese popups A guide to removing RavMonE.exe!

i know u must be thinkin tht i have to go uncheck it in folder options thing.. Register Help Remember Me? The second time it just freezes up. It also logs keystrokes and steals sensitive information, which can be sent to a remote server.

Contents of the 'Scheduled Tasks' folder "2008-05-27 21:09:00 C:\WINDOWS\Tasks\MP Scheduled Scan.job" - C:\Program Files\Windows Defender\MpCmdRun.exe "2008-05-23 19:14:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job" - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe "2008-03-24 19:14:32 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job" - C:\Program Files\Uniblue\SpeedUpMyPC CS:c000 IP:0096 OP:ff ff ff ff ff\r\n\r\nThis is the error message that I get when I start a MS-DOS program on Windows XP Pro Problem was successfully solved. I thought that my thumb drive was the only infected media. Completion time: 2008-05-27 17:11:13 - machine was rebooted ComboFix-quarantined-files.txt 2008-05-27 21:11:08 Pre-Run: 33,808,950,784 bytes free Post-Run: 36,734,113,792 bytes free WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect

Delete the following folders that are assosiated with Downloader VB AJC Trojan: no information 3. Once again, congratulations! AVG is useless! To start viewing messages, select the forum that you want to visit from the selection below.

or read our Welcome Guide to learn how to use this site. This is giving me a headache. Problem was successfully solved. i went to WinRAR to view those files in C: drive i have the following files so plz guide me what to do : Documents and Settings Program Files RECYCLER System

By colleenAZ in forum OS X - Operating System Replies: 6 Last Post: 01-16-2011, 08:08 PM running ab exe file on my Mac By ozbuc in forum OS X - Operating Problem Summary: NTVDM CPU problem Every time when i try to tun Turbo C++, i got this error message"Turbo C++ IDE The NTVDM CPU has encountered an illegal instryction. Cookiegal, May 22, 2008 #5 Stomper9 Thread Starter Joined: Apr 30, 2008 Messages: 24 Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 8:28:03 AM, on 5/25/2008 Platform: Windows XP SP2 It was created after analyzing all versions and types of this threat on test PCs and every file and key was added to the database.

thank you so muck for the info!! http://diskpocalypse.com/need-help/need-help-removing-virtumondo.php Haha. Comment by Dan -- October 23, 2008 @ 5:28 pm | Reply thanks a lot..now i am free from the ravmone.exe problem now… Comment by harry5255 -- December 26, 2008 @ aRGH!!!!

Button up the group and upload here for the examiners to go over. Ohh 1 more thing before the Affect of the virus in the starting whenever i open any drives they open in another dialog.. plz anyone can shortout my problem Problem was successfully solved. navigate here I'm not sure if it was the virus or something else that screwed things up (I was running rootkitrevealer in conjunction with AVG virus scan to double check that nothing nefarious

C:\WINDOWS\system32\ODBCJET.exe [256] 0x828EC388 scanning hidden autostart entries ... I am a student in NIEC DElhi(IPU) Thanks SpankyJo is offline Reply With Quote Problem was successfully solved. Apple Hardware Apple Desktops Apple Notebooks Apple TV Other Hardware and Peripherals Developer Playground iOS Development OS X - Development and Darwin « Previous Thread | Next Thread » Thread Information

Download for free UnHackMe - Rootkit Killer RegRun Security Suite - powerful security suite Reanimator - free malware remover Improve Windows boot speed with BootRacer Links Malware Removal Blog New Virus

Currently from testing, only Kaspersky Products such as Kaspersky Internet Security & AOL Active Virus Shield, have successfully removed this "Autorun" problem. Attached Files: Mountpoints Diagnostic.zip File size: 1.2 KB Views: 10 Cookiegal, May 25, 2008 #7 Stomper9 Thread Starter Joined: Apr 30, 2008 Messages: 24 Diagnostic Report Tue 05/27/2008 16:33:43.30 Mountpoints > CS:c000 IP;0096 op:ff ff ff ff ff choose 'close' to terminate the application Problem was successfully solved. Attach suspicious files that you see that possibly a part of Downloader VB AJC Trojan.

Problem Summary: The NTVDM CPU has encountered an illegal instruction. if possible can u help me .. My antivirus NOD32 cant identify it as well even with the latest signature. his comment is here We recommend you to use Downloader VB AJC Trojan Removal Tool for safe problem solution.

Related Comments (36) 36 Comments » thank youuu so much! Problem Summary: CS:c000 IP:0096 OP:FF FF FF FF FF When I try to run graphics programs in c++ , it shows the following error n terminates.. : CPU has enconutered an just it display 'turbo c++ ide the ntvdm cpu has encountered an illegal instruction CS:c000IP:0096 OP:ff ff ff ff ff choose' turbo c++ ide the ntvdm cpu has encountered an illegal C:\WINDOWS\system32\ODBCJET.exe [256] 0x828EC388 scanning hidden autostart entries ...