Page 1 of 3 123 LastLast
Results 1 to 10 of 25

Thread: Virtumonde.dll

  1. #1
    Member
    Join Date
    Feb 2010
    Posts
    37

    Default Virtumonde.dll

    Please help,

    i am trying to remove Virtumonde from a laptop running XP, at first i had no function from internet explorer, just kept trying to reload the page, i uninstalled iexplorer 8 and reinstalled it and its now working, run spybot S&D and noticed that it scans virtumonde.dll among others, tried to remove malware findings at end of scan, restarted, scanned again and they are still there.

    i then run a scan through malwarebytes anti malware (free download version) and fixed the problems it found, but i still think its on here. i have disabled tea timer and done a registry backup, this is the HiJackThis log:

    Logfile of Trend Micro HijackThis v2.0.3 (BETA)
    Scan saved at 16:31:29, on 15/02/2010
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Common Files\EPSON\eEBAPI\eEBSVC.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\Trigold\Update\TRUService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\HiJackThis\TrendMicro\HiJackThis\HiJackThis.exe
    C:\WINDOWS\system32\wuauclt.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.intrinsicfs.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.bbc.co.uk/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O1 - Hosts: ::1 localhost
    O1 - Hosts: 91.212.127.220 intsecure.microsoft.com
    O1 - Hosts: 91.212.127.220 intsecure-2009.com
    O1 - Hosts: 91.212.127.220 www.intsecure-2009.com
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Engine\3.8.0.41\IPSBHO.DLL
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
    O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
    O4 - HKLM\..\Run: [StartSQLManager] C:\Program Files\Microsoft SQL Server\90\Tools\Binn\sqlmangr.exe /n
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - S-1-5-18 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'SYSTEM')
    O4 - .DEFAULT Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User 'Default user')
    O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check(2).lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {0089F6EE-ED54-11D5-B0E7-00508B014C1D} (ExWebClientUtils Class) - https://exweb.exchange.uk.com/client...es/texInfo.CAB
    O16 - DPF: {034DA761-EDB7-11D7-A20A-000802318089} (EWGPHI.desInput) - https://exweb.exchange.uk.com/clientbinaries/EWGPHI.CAB
    O16 - DPF: {090EC279-1378-44B7-B521-888980212E7E} (Complist3 Class) - https://exweb.exchange.uk.com/client...bCListCtl3.CAB
    O16 - DPF: {2F6A847E-2EC2-11D3-AE1B-00508B014C1D} (Parser Class) - https://exweb.exchange.uk.com/client.../XMLParser.CAB
    O16 - DPF: {397F65A6-FD3C-438B-A7EB-3D2C0655189C} (EWGPensions.desInput) - https://exweb.exchange.uk.com/client...WGPensions.CAB
    O16 - DPF: {511835FF-EDC9-11D7-A20A-000802318089} (EWGWholeLife.desInput) - https://exweb.exchange.uk.com/client...GWholeLife.CAB
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/res...scbase6087.cab
    O16 - DPF: {61DA056C-EDE7-11D7-A20A-000802318089} (EWGBonds.desInput) - https://exweb.exchange.uk.com/client...s/EWGBonds.CAB
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
    O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1264868158828
    O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - https://exweb.exchange.uk.com/clientbinaries/msxml4.CAB
    O16 - DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} (VersionInfo.clsVersionInfo) - https://exweb.exchange.uk.com/client...ersionInfo.CAB
    O16 - DPF: {A74D724A-AB17-11D2-A96A-006097E20477} (eXwebUtils.HTMLUtils) - https://exweb.exchange.uk.com/client...eXwebUtils.CAB
    O16 - DPF: {DDECE2F5-AF1F-44E7-B37F-96B6630F5C60} (PrintComponent.clsVersionInfo) - https://exweb.exchange.uk.com/client...s/printdll.CAB
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://inertia.webex.com/client/T27...rt/ieatgpc.cab
    O16 - DPF: {E7FF5332-854E-11D2-A952-006097E20477} (eXwebOccList.clsOccRes) - https://exweb.exchange.uk.com/client...s/eXwebOcc.CAB
    O16 - DPF: {E9C9692E-F93C-11D1-ABB0-0040054FC6FB} (ProtoView DataTable Control 7.0 (OLEDB)) - https://exweb.exchange.uk.com/clientbinaries/pvdt70.CAB
    O18 - Protocol: symres - {AA1061FE-6C41-421F-9344-69640C9732AB} - C:\Program Files\Norton 360\Engine\3.8.0.41\coIEPlg.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: EpsonBidirectionalService - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\eEBAPI\eEBSVC.exe
    O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
    O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
    O23 - Service: Trigold Update Service (TRUService) - Trigold - C:\Program Files\Trigold\Update\TRUService.exe

    --
    End of file - 10307 bytes



    thank you for any help

  2. #2
    Member
    Join Date
    Feb 2010
    Posts
    37

    Unhappy can anyone help

    Please help, Malwarebytes said its clean but its not as spybot scans virtumonde.dll, virtumonde.sdc among many others!!!! i think its deep in the registry...........Please Help

  3. #3
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Download DDS and save it to your desktop from here or here or here.
    Disable any script blocker, and then double click dds.scr to run the tool.
    • When done, DDS will open two (2) logs:
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop. Post them back to your topic.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  4. #4
    Member
    Join Date
    Feb 2010
    Posts
    37

    Default Dds

    DDS (Ver_09-12-01.01) - NTFSx86
    Run by Any Authorised User at 10:53:56.21 on 20/02/2010
    Internet Explorer: 8.0.6001.18702
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.99 [GMT 0:00]

    AV: Norton 360 *On-access scanning enabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton 360 *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}

    ============== Running Processes ===============

    C:\WINDOWS\system32\svchost -k DcomLaunch
    svchost.exe
    C:\WINDOWS\System32\svchost.exe -k netsvcs
    C:\Program Files\Ahead\InCD\InCDsrv.exe
    svchost.exe
    svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    svchost.exe
    C:\Program Files\Common Files\EPSON\eEBAPI\eEBSVC.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre6\bin\jqs.exe
    C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
    C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\Trigold\Update\TRUService.exe
    C:\Program Files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe
    C:\WINDOWS\system32\igfxtray.exe
    C:\WINDOWS\sm56hlpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\Ahead\InCD\InCD.exe
    C:\Program Files\QuickTime\QTTask.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\WINDOWS\System32\svchost.exe -k HTTPFilter
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\Program Files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Any Authorised User\Desktop\dds.scr

    ============== Pseudo HJT Report ===============

    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.intrinsicfs.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.bbc.co.uk/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\engine\3.8.0.41\IPSBHO.DLL
    BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.4.4525.1752\swg.dll
    BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
    BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\engine\3.8.0.41\coIEPlg.dll
    TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
    uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background
    uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
    mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
    mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
    mRun: [SMSERIAL] sm56hlpr.exe
    mRun: [SynTPLpr] c:\program files\synaptics\syntp\SynTPLpr.exe
    mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe
    mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
    mRun: [InCD] c:\program files\ahead\incd\InCD.exe
    mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
    mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
    mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
    mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
    dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
    StartupFolder: c:\docume~1\anyaut~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
    StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\epsons~1.lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
    IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
    IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

    ============= SERVICES / DRIVERS ===============

    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0308000.029\SymEFA.sys [2010-2-5 310320]
    R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\n360\0308000.029\BHDrvx86.sys [2010-2-5 259632]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0308000.029\cchpx86.sys [2010-2-5 482432]
    R1 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\ipsdefs\20100218.001\IDSXpx86.sys [2010-2-20 329592]
    R2 MSSQL$INERTIA3_SQL2005;SQL Server (INERTIA3_SQL2005);c:\program files\microsoft sql server\mssql.1\mssql\binn\sqlservr.exe [2008-11-24 29263712]
    R2 N360;Norton 360;c:\program files\norton 360\engine\3.8.0.41\ccSvcHst.exe [2010-2-5 117640]
    R2 TRUService;Trigold Update Service;c:\program files\trigold\update\TRUService.exe [2008-7-14 135816]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-2-10 102448]
    R3 NAVENG;NAVENG;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100217.069\NAVENG.SYS [2010-2-18 84912]
    R3 NAVEX15;NAVEX15;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\norton\definitions\virusdefs\20100217.069\NAVEX15.SYS [2010-2-18 1324720]

    =============== Created Last 30 ================

    2010-02-18 16:10:44 0 d-sha-r- C:\cmdcons
    2010-02-18 16:07:19 98816 ----a-w- c:\windows\sed.exe
    2010-02-18 16:07:19 77312 ----a-w- c:\windows\MBR.exe
    2010-02-18 16:07:19 261632 ----a-w- c:\windows\PEV.exe
    2010-02-18 16:07:19 161792 ----a-w- c:\windows\SWREG.exe
    2010-02-15 14:01:49 0 d-----w- c:\docume~1\anyaut~1\applic~1\Malwarebytes
    2010-02-15 14:01:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-02-15 14:01:36 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
    2010-02-15 14:01:33 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-02-15 14:01:33 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-02-14 21:20:06 0 dc-h--w- c:\windows\ie8
    2010-02-14 19:42:08 0 d-----w- c:\program files\Spybot - Search & Destroy
    2010-02-14 19:42:08 0 d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
    2010-02-14 19:24:45 48544 ---ha-w- c:\windows\system32\mlfcache.dat
    2010-02-05 21:35:53 0 d-----w- c:\documents and settings\any authorised user\C
    2010-02-05 19:07:24 0 d-----w- c:\program files\iTunes
    2010-02-05 19:07:24 0 d-----w- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-02-05 19:06:10 0 d-----w- c:\program files\Bonjour
    2010-02-05 19:03:41 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2010-02-05 19:03:41 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
    2010-01-31 16:45:02 0 d-----w- c:\windows\SQLTools9_KB970892_ENU
    2010-01-31 14:19:55 0 d-----w- c:\windows\system32\Registry Patrol
    2010-01-31 14:18:56 0 d-----w- c:\program files\Registry Patrol
    2010-01-31 13:45:51 0 d-----r- c:\program files\Norton Support
    2010-01-30 17:39:15 0 d-----w- C:\f71b5c25fa32883ca5706365d257924a
    2010-01-30 17:23:14 0 d-----w- C:\b3c4cb4810021e8ab02912d6
    2010-01-30 16:38:56 274288 ----a-w- c:\windows\system32\mucltui.dll
    2010-01-30 16:38:56 16736 ----a-w- c:\windows\system32\mucltui.dll.mui
    2010-01-30 15:36:55 0 d-----w- C:\spoolerlogs
    2010-01-30 14:38:00 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
    2010-01-30 14:37:50 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
    2010-01-30 14:37:50 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
    2010-01-30 14:37:49 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
    2010-01-30 14:37:49 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-01-30 14:37:49 0 d-----w- c:\program files\Symantec
    2010-01-30 14:37:10 0 d-----w- c:\windows\system32\drivers\N360
    2010-01-30 14:37:07 0 d-----w- c:\program files\Norton 360
    2010-01-30 14:37:06 0 d-----w- c:\docume~1\alluse~1\applic~1\Norton
    2010-01-30 14:33:16 0 d-----w- c:\program files\NortonInstaller
    2010-01-30 14:33:16 0 d-----w- c:\docume~1\alluse~1\applic~1\NortonInstaller

    ==================== Find3M ====================

    2010-01-30 14:37:41 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-01-30 14:37:32 107368 ----a-r- c:\windows\system32\GEARAspi.dll
    2010-01-05 10:00:21 78336 ------w- c:\windows\system32\ieencode.dll
    2010-01-05 10:00:21 78336 ------w- c:\windows\system32\dllcache\ieencode.dll
    2010-01-05 10:00:21 133120 ----a-w- c:\windows\system32\dllcache\extmgr.dll
    2009-12-31 16:50:03 353792 ----a-w- c:\windows\system32\drivers\srv.sys
    2009-12-31 16:50:03 353792 ------w- c:\windows\system32\dllcache\srv.sys
    2009-12-31 15:33:06 13824 ------w- c:\windows\system32\dllcache\ieudinit.exe
    2009-12-21 13:19:18 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
    2009-12-17 17:14:00 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-12-16 18:43:27 343040 ----a-w- c:\windows\system32\mspaint.exe
    2009-12-16 18:43:27 343040 ------w- c:\windows\system32\dllcache\mspaint.exe
    2009-12-14 07:08:23 33280 ----a-w- c:\windows\system32\csrsrv.dll
    2009-12-14 07:08:23 33280 ------w- c:\windows\system32\dllcache\csrsrv.dll
    2009-12-11 08:38:55 69120 ------w- c:\windows\system32\dllcache\iecompat.dll
    2009-12-08 19:27:51 2189184 ------w- c:\windows\system32\ntoskrnl.exe
    2009-12-08 19:27:51 2189184 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
    2009-12-08 19:26:15 2145280 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
    2009-12-08 18:43:51 2023936 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
    2009-12-08 18:43:50 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
    2009-12-08 18:43:50 2066048 ------w- c:\windows\system32\dllcache\ntkrnlpa.exe
    2009-12-04 18:22:22 455424 ------w- c:\windows\system32\dllcache\mrxsmb.sys
    2009-11-27 17:11:44 17920 ----a-w- c:\windows\system32\msyuv.dll
    2009-11-27 17:11:44 17920 ------w- c:\windows\system32\dllcache\msyuv.dll
    2009-11-27 17:11:44 1291776 ----a-w- c:\windows\system32\quartz.dll
    2009-11-27 17:11:44 1291776 ------w- c:\windows\system32\dllcache\quartz.dll
    2009-11-27 16:07:35 8704 ----a-w- c:\windows\system32\tsbyuv.dll
    2009-11-27 16:07:35 8704 ------w- c:\windows\system32\dllcache\tsbyuv.dll
    2009-11-27 16:07:35 28672 ----a-w- c:\windows\system32\msvidc32.dll
    2009-11-27 16:07:35 28672 ----a-w- c:\windows\system32\dllcache\msvidc32.dll
    2009-11-27 16:07:34 84992 ----a-w- c:\windows\system32\avifil32.dll
    2009-11-27 16:07:34 84992 ------w- c:\windows\system32\dllcache\avifil32.dll
    2009-11-27 16:07:34 48128 ----a-w- c:\windows\system32\iyuv_32.dll
    2009-11-27 16:07:34 48128 ------w- c:\windows\system32\dllcache\iyuv_32.dll
    2009-11-27 16:07:34 11264 ----a-w- c:\windows\system32\msrle32.dll
    2009-11-27 16:07:34 11264 ------w- c:\windows\system32\dllcache\msrle32.dll
    2008-09-18 11:33:34 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012008091820080919\index.dat

    ============= FINISH: 10:56:06.64 ===============

  5. #5
    Member
    Join Date
    Feb 2010
    Posts
    37

    Default Attatch

    UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
    IF REQUESTED, ZIP IT UP & ATTACH IT

    DDS (Ver_09-12-01.01)

    Microsoft Windows XP Professional
    Boot Device: \Device\HarddiskVolume1
    Install Date: 10/05/2006 18:50:12
    System Uptime: 20/02/2010 08:48:54 (2 hours ago)

    Motherboard: FUJITSU SIEMENS | | AMILO Pro V2060
    Processor: Intel(R) Pentium(R) M processor 1.70GHz | U1 | 593/400mhz

    ==== Disk Partitions =========================

    C: is FIXED (NTFS) - 56 GiB total, 27.405 GiB free.
    D: is CDROM ()

    ==== Disabled Device Manager Items =============

    ==== System Restore Points ===================

    RP185: 21/11/2009 14:12:40 - Norton 360 Registry Clean
    RP186: 25/11/2009 10:04:52 - Software Distribution Service 3.0
    RP187: 10/12/2009 10:08:14 - Software Distribution Service 3.0
    RP188: 10/12/2009 10:26:27 - Software Distribution Service 3.0
    RP189: 19/12/2009 13:09:29 - Norton 360 Registry Clean
    RP190: 26/12/2009 09:13:02 - Norton 360 Registry Clean
    RP191: 29/12/2009 12:21:01 - Norton 360 Registry Clean
    RP192: 13/01/2010 09:54:08 - Software Distribution Service 3.0
    RP193: 22/01/2010 10:47:45 - Software Distribution Service 3.0
    RP194: 22/01/2010 11:14:12 - Norton 360 Registry Clean
    RP195: 23/01/2010 12:18:05 - Norton 360 Registry Clean
    RP196: 27/01/2010 09:23:16 - Installed Java(TM) 6 Update 18
    RP197: 30/01/2010 15:56:45 - Restore Operation
    RP198: 30/01/2010 16:39:18 - Software Distribution Service 3.0
    RP199: 30/01/2010 17:02:16 - Software Distribution Service 3.0
    RP200: 30/01/2010 17:21:29 - Removed Abbey Introducer Offline
    RP201: 30/01/2010 17:22:59 - Software Distribution Service 3.0
    RP202: 30/01/2010 17:49:39 - Software Distribution Service 3.0
    RP203: 30/01/2010 22:27:27 - Software Distribution Service 3.0
    RP204: 30/01/2010 22:52:25 - Software Distribution Service 3.0
    RP205: 31/01/2010 11:28:10 - Software Distribution Service 3.0
    RP206: 31/01/2010 14:17:49 - Software Distribution Service 3.0
    RP207: 31/01/2010 14:34:29 - Software Distribution Service 3.0
    RP208: 31/01/2010 14:52:00 - Software Distribution Service 3.0
    RP209: 31/01/2010 15:32:12 - Removed Microsoft SQL Server Native Client
    RP210: 31/01/2010 16:39:52 - Software Distribution Service 3.0
    RP211: 01/02/2010 09:45:41 - Software Distribution Service 3.0
    RP212: 05/02/2010 17:10:55 - Removed Alliance and Leicester Online Forms
    RP213: 05/02/2010 17:12:02 - Removed Northern Rock Online
    RP214: 05/02/2010 17:14:24 - Configured Intermediary Mortgages Application
    RP215: 05/02/2010 19:07:06 - Installed iTunes
    RP216: 08/02/2010 10:49:07 - Printer Driver WebEx Document Loader Installed
    RP217: 08/02/2010 11:00:27 - Printer Driver WebEx Document Loader Installed
    RP218: 09/02/2010 23:04:00 - System Checkpoint
    RP219: 10/02/2010 15:59:27 - Software Distribution Service 3.0
    RP220: 14/02/2010 21:05:59 - Software Distribution Service 3.0
    RP221: 15/02/2010 16:20:24 - Installed HiJackThis
    RP222: 15/02/2010 17:09:19 - Removed Safari
    RP223: 16/02/2010 17:44:17 - Software Distribution Service 3.0
    RP224: 16/02/2010 17:56:54 - Zara - Virus Cleaning 16.02
    RP225: 16/02/2010 18:02:02 - Restore Operation
    RP226: 16/02/2010 18:06:23 - Restore Operation
    RP227: 18/02/2010 17:08:04 - System Checkpoint

    ==== Installed Programs ======================

    Acrobat.com
    Adobe AIR
    Adobe Flash Player 10 ActiveX
    Adobe Reader 9
    Adobe® Photoshop® Album Starter Edition 3.0
    ALCX11 Basic Operation Guide
    ALCX11 User's Guide
    Apple Application Support
    Apple Mobile Device Support
    Apple Software Update
    Bonjour
    Critical Update for Windows Media Player 11 (KB959772)
    EPSON Printer Software
    EPSON Scan
    EPSON Speed Dial Utility
    EpsonNet Print
    ERUNT 1.1j
    Exweb DE
    GearDrvs
    goal viewer (offline) Trigold Edition
    Google Toolbar for Internet Explorer
    High Definition Audio Driver Package - KB888111
    HiJackThis
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
    Hotfix for Windows Internet Explorer 7 (KB947864)
    Hotfix for Windows Media Format 11 SDK (KB929399)
    Hotfix for Windows Media Player 11 (KB939683)
    Hotfix for Windows XP (KB952287)
    Hotfix for Windows XP (KB954550-v5)
    Hotfix for Windows XP (KB961118)
    Hotfix for Windows XP (KB970653-v3)
    Hotfix for Windows XP (KB976098-v2)
    Inertia 3
    Intel(R) Graphics Media Accelerator Driver for Mobile
    Intrinsic iPoS
    iTunes
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java Auto Updater
    Java(TM) 6 Update 18
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1
    Malwarebytes' Anti-Malware
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Security Update (KB953297)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft Compression Client Pack 1.0 for Windows XP
    Microsoft Internationalized Domain Names Mitigation APIs
    Microsoft National Language Support Downlevel APIs
    Microsoft Office Small Business Edition 2003
    Microsoft SQL Server 2005
    Microsoft SQL Server 2005 Express Edition (INERTIA3_SQL2005)
    Microsoft SQL Server 2005 Tools Express Edition
    Microsoft SQL Server Native Client
    Microsoft SQL Server Setup Support Files (English)
    Microsoft SQL Server VSS Writer
    Microsoft User-Mode Driver Framework Feature Pack 1.0
    Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
    Microsoft Visual C++ 2005 Redistributable
    Microsoft WSE 2.0 SP3 Runtime
    Motorola SM56 Data Fax Modem
    MSN
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 4.0 SP2 (KB973688)
    MSXML 6.0 Parser (KB933579)
    Nero Suite
    Norton 360
    OGA Notifier 2.0.0048.0
    Prospector AAA
    Prospector Registry Tool
    QuickTime
    Security Update for Step By Step Interactive Training (KB898458)
    Security Update for Step By Step Interactive Training (KB923723)
    Security Update for Windows Internet Explorer 7 (KB928090)
    Security Update for Windows Internet Explorer 7 (KB929969)
    Security Update for Windows Internet Explorer 7 (KB931768)
    Security Update for Windows Internet Explorer 7 (KB933566)
    Security Update for Windows Internet Explorer 7 (KB937143)
    Security Update for Windows Internet Explorer 7 (KB938127)
    Security Update for Windows Internet Explorer 7 (KB939653)
    Security Update for Windows Internet Explorer 7 (KB942615)
    Security Update for Windows Internet Explorer 7 (KB944533)
    Security Update for Windows Internet Explorer 7 (KB950759)
    Security Update for Windows Internet Explorer 7 (KB953838)
    Security Update for Windows Internet Explorer 7 (KB956390)
    Security Update for Windows Internet Explorer 7 (KB958215)
    Security Update for Windows Internet Explorer 7 (KB960714)
    Security Update for Windows Internet Explorer 7 (KB961260)
    Security Update for Windows Internet Explorer 7 (KB963027)
    Security Update for Windows Internet Explorer 7 (KB969897)
    Security Update for Windows Internet Explorer 7 (KB978207)
    Security Update for Windows Internet Explorer 8 (KB971961)
    Security Update for Windows Internet Explorer 8 (KB976325)
    Security Update for Windows Internet Explorer 8 (KB978207)
    Security Update for Windows Media Player (KB911564)
    Security Update for Windows Media Player (KB952069)
    Security Update for Windows Media Player (KB954155)
    Security Update for Windows Media Player (KB968816)
    Security Update for Windows Media Player (KB973540)
    Security Update for Windows Media Player 10 (KB911565)
    Security Update for Windows Media Player 10 (KB917734)
    Security Update for Windows Media Player 11 (KB936782)
    Security Update for Windows Media Player 11 (KB954154)
    Security Update for Windows Media Player 6.4 (KB925398)
    Security Update for Windows XP (KB923561)
    Security Update for Windows XP (KB923689)
    Security Update for Windows XP (KB938464-v2)
    Security Update for Windows XP (KB938464)
    Security Update for Windows XP (KB941569)
    Security Update for Windows XP (KB946648)
    Security Update for Windows XP (KB950760)
    Security Update for Windows XP (KB950762)
    Security Update for Windows XP (KB950974)
    Security Update for Windows XP (KB951066)
    Security Update for Windows XP (KB951376-v2)
    Security Update for Windows XP (KB951376)
    Security Update for Windows XP (KB951698)
    Security Update for Windows XP (KB951748)
    Security Update for Windows XP (KB952004)
    Security Update for Windows XP (KB952954)
    Security Update for Windows XP (KB953839)
    Security Update for Windows XP (KB954211)
    Security Update for Windows XP (KB954459)
    Security Update for Windows XP (KB954600)
    Security Update for Windows XP (KB955069)
    Security Update for Windows XP (KB956391)
    Security Update for Windows XP (KB956572)
    Security Update for Windows XP (KB956744)
    Security Update for Windows XP (KB956802)
    Security Update for Windows XP (KB956803)
    Security Update for Windows XP (KB956841)
    Security Update for Windows XP (KB956844)
    Security Update for Windows XP (KB957095)
    Security Update for Windows XP (KB957097)
    Security Update for Windows XP (KB958644)
    Security Update for Windows XP (KB958687)
    Security Update for Windows XP (KB958690)
    Security Update for Windows XP (KB958869)
    Security Update for Windows XP (KB959426)
    Security Update for Windows XP (KB960225)
    Security Update for Windows XP (KB960715)
    Security Update for Windows XP (KB960803)
    Security Update for Windows XP (KB960859)
    Security Update for Windows XP (KB961371)
    Security Update for Windows XP (KB961373)
    Security Update for Windows XP (KB961501)
    Security Update for Windows XP (KB968537)
    Security Update for Windows XP (KB969059)
    Security Update for Windows XP (KB969898)
    Security Update for Windows XP (KB969947)
    Security Update for Windows XP (KB970238)
    Security Update for Windows XP (KB970430)
    Security Update for Windows XP (KB971468)
    Security Update for Windows XP (KB971486)
    Security Update for Windows XP (KB971557)
    Security Update for Windows XP (KB971633)
    Security Update for Windows XP (KB971657)
    Security Update for Windows XP (KB971961)
    Security Update for Windows XP (KB972270)
    Security Update for Windows XP (KB973346)
    Security Update for Windows XP (KB973354)
    Security Update for Windows XP (KB973507)
    Security Update for Windows XP (KB973525)
    Security Update for Windows XP (KB973869)
    Security Update for Windows XP (KB973904)
    Security Update for Windows XP (KB974112)
    Security Update for Windows XP (KB974318)
    Security Update for Windows XP (KB974392)
    Security Update for Windows XP (KB974571)
    Security Update for Windows XP (KB975025)
    Security Update for Windows XP (KB975467)
    Security Update for Windows XP (KB975560)
    Security Update for Windows XP (KB975713)
    Security Update for Windows XP (KB977165)
    Security Update for Windows XP (KB977914)
    Security Update for Windows XP (KB978037)
    Security Update for Windows XP (KB978251)
    Security Update for Windows XP (KB978262)
    Security Update for Windows XP (KB978706)
    SoundMAX
    Spybot - Search & Destroy
    Synaptics Pointing Device Driver
    Texas Instruments PCIxx21/x515 drivers.
    TIxx21/x515
    TRSoap
    Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
    Update for Windows Internet Explorer 8 (KB978506)
    Update for Windows XP (KB951072-v2)
    Update for Windows XP (KB951978)
    Update for Windows XP (KB955759)
    Update for Windows XP (KB955839)
    Update for Windows XP (KB967715)
    Update for Windows XP (KB968389)
    Update for Windows XP (KB971737)
    Update for Windows XP (KB973687)
    Update for Windows XP (KB973815)
    VoiceOver Kit
    WebEx
    WebFldrs XP
    Windows Genuine Advantage Notifications (KB905474)
    Windows Internet Explorer 7
    Windows Internet Explorer 8
    Windows Live OneCare safety scanner
    Windows Media Format 11 runtime
    Windows Media Player 11
    Windows XP Service Pack 3

    ==== Event Viewer Messages From Past Week ========

    18/02/2010 16:50:51, information: Windows File Protection [64002] - File replacement was attempted on the protected system file uploadm.exe. This file was restored to the original version to maintain system stability. The file version of the system file is 5.1.2600.5512.
    15/02/2010 16:28:50, error: Dhcp [1002] - The IP address lease 192.168.0.5 for the Network Card with network address 0013CEAD58D5 has been denied by the DHCP server 10.164.50.49 (The DHCP Server sent a DHCPNACK message).
    15/02/2010 13:49:33, error: Dhcp [1002] - The IP address lease 192.168.2.4 for the Network Card with network address 0013CEAD58D5 has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).

    ==== End Of File ===========================

  6. #6
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    Do NOT run 'FIXES' (ComboFix etc) without being asked

    It seems you have run ComboFix there. Kindly post contents of c:\ComboFix.txt file.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  7. #7
    Member
    Join Date
    Feb 2010
    Posts
    37

    Default

    Sorry, it was my last try before i restored from disks,

    log file:

    ComboFix 10-02-17.02 - Any Authorised User 18/02/2010 16:44:26.2.1 - x86
    Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.502.186 [GMT 0:00]
    Running from: c:\documents and settings\Any Authorised User\Desktop\ComboFix.exe
    AV: Norton 360 *On-access scanning disabled* (Updated) {E10A9785-9598-4754-B552-92431C1C35F8}
    FW: Norton 360 *disabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\windows\pchealth\UploadLB\Binaries\uploadm.exe
    c:\windows\pchealth\UploadLB\Config\config.xml
    c:\windows\pchealth\UploadLB . . . . failed to delete

    .
    ((((((((((((((((((((((((( Files Created from 2010-01-18 to 2010-02-18 )))))))))))))))))))))))))))))))
    .

    2010-02-15 16:16 . 2010-02-15 16:16 -------- d-----w- c:\program files\ERUNT
    2010-02-15 14:01 . 2010-02-15 14:01 -------- d-----w- c:\documents and settings\Any Authorised User\Application Data\Malwarebytes
    2010-02-15 14:01 . 2010-01-07 16:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
    2010-02-15 14:01 . 2010-02-15 14:01 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
    2010-02-15 14:01 . 2010-02-15 14:01 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
    2010-02-15 14:01 . 2010-01-07 16:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
    2010-02-14 21:39 . 2010-02-14 21:41 -------- d-----w- c:\program files\Windows Live Safety Center
    2010-02-14 21:20 . 2010-02-14 21:22 -------- dc-h--w- c:\windows\ie8
    2010-02-14 19:42 . 2010-02-14 20:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
    2010-02-14 19:42 . 2010-02-14 20:43 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2010-02-14 19:24 . 2010-02-14 19:24 48544 ---ha-w- c:\windows\system32\mlfcache.dat
    2010-02-05 21:35 . 2010-02-05 21:35 -------- d-----w- c:\documents and settings\Any Authorised User\C
    2010-02-05 19:07 . 2010-02-05 22:46 -------- d-----w- c:\program files\iTunes
    2010-02-05 19:07 . 2010-02-05 19:08 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
    2010-02-05 19:06 . 2010-02-05 19:06 -------- d-----w- c:\program files\Bonjour
    2010-02-05 19:04 . 2010-02-05 19:04 -------- d-----w- c:\documents and settings\Any Authorised User\Local Settings\Application Data\Apple
    2010-02-05 19:04 . 2010-02-05 19:04 -------- d-----w- c:\program files\Apple Software Update
    2010-02-05 19:03 . 2009-08-28 19:42 40448 ----a-w- c:\windows\system32\drivers\usbaapl.sys
    2010-02-05 19:03 . 2009-08-28 19:42 2065696 ----a-w- c:\windows\system32\usbaaplrc.dll
    2010-02-05 19:02 . 2010-02-05 19:07 -------- d-----w- c:\program files\Common Files\Apple
    2010-02-05 19:02 . 2010-02-05 19:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple
    2010-01-31 16:45 . 2010-01-31 16:45 -------- d-----w- c:\windows\SQLTools9_KB970892_ENU
    2010-01-31 14:19 . 2010-01-31 14:19 -------- d-----w- c:\windows\system32\Registry Patrol
    2010-01-31 14:18 . 2010-01-31 14:22 -------- d-----w- c:\program files\Registry Patrol
    2010-01-31 13:45 . 2010-01-31 13:45 -------- d-----r- c:\program files\Norton Support
    2010-01-30 17:47 . 2010-01-30 17:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
    2010-01-30 17:39 . 2010-01-30 17:39 -------- d-----w- C:\f71b5c25fa32883ca5706365d257924a
    2010-01-30 17:23 . 2010-01-30 17:23 -------- d-----w- C:\b3c4cb4810021e8ab02912d6
    2010-01-30 16:38 . 2009-08-06 19:23 274288 ----a-w- c:\windows\system32\mucltui.dll
    2010-01-30 15:36 . 2010-01-30 15:36 -------- d-----w- C:\spoolerlogs
    2010-01-30 14:38 . 2010-01-30 14:37 36400 ----a-r- c:\windows\system32\drivers\SymIM.sys
    2010-01-30 14:37 . 2010-01-30 14:37 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
    2010-01-30 14:37 . 2010-01-30 14:37 -------- d-----w- c:\program files\Symantec
    2010-01-30 14:37 . 2010-01-30 14:37 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-01-30 14:37 . 2010-02-05 18:16 -------- d-----w- c:\windows\system32\drivers\N360
    2010-01-30 14:37 . 2010-01-30 14:37 -------- d-----w- c:\program files\Norton 360
    2010-01-30 14:37 . 2010-01-30 14:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
    2010-01-30 14:33 . 2010-01-30 14:33 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
    2010-01-30 14:33 . 2010-01-30 14:33 -------- d-----w- c:\program files\NortonInstaller
    2010-01-30 13:47 . 2010-01-30 13:47 -------- d-----w- c:\documents and settings\Any Authorised User\Local Settings\Application Data\ICS

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2010-02-15 16:20 . 2010-02-15 16:20 388096 ----a-r- c:\documents and settings\Any Authorised User\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
    2010-02-14 19:23 . 2006-05-13 20:32 -------- d-----w- c:\documents and settings\Any Authorised User\Application Data\Apple Computer
    2010-02-09 21:07 . 2010-02-18 15:55 84912 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\NAVENG.SYS
    2010-02-09 21:07 . 2010-02-18 15:55 177520 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\NAVENG32.DLL
    2010-02-09 21:07 . 2010-02-18 15:55 1647984 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\NAVEX32A.DLL
    2010-02-09 21:07 . 2010-02-18 15:55 1324720 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\NAVEX15.SYS
    2010-02-09 21:07 . 2010-02-18 15:55 371248 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\EECTRL.SYS
    2010-02-09 21:07 . 2010-02-18 15:55 2747440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\CCERASER.DLL
    2010-02-09 21:07 . 2010-02-18 15:55 259440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\ECMSVR32.DLL
    2010-02-09 21:07 . 2010-02-18 15:55 102448 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100217.069\ERASER.SYS
    2010-02-05 19:07 . 2006-05-13 20:30 -------- d-----w- c:\program files\iPod
    2010-02-05 19:05 . 2006-05-13 20:31 -------- d-----w- c:\program files\QuickTime
    2010-02-05 19:04 . 2006-05-13 20:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Apple Computer
    2010-02-05 18:28 . 2006-05-15 14:35 -------- d-----w- c:\documents and settings\Any Authorised User\Application Data\objects
    2010-02-05 17:16 . 2006-05-12 17:23 64160 ----a-w- c:\documents and settings\Any Authorised User\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
    2010-02-05 17:14 . 2006-05-10 17:49 -------- d--h--w- c:\program files\InstallShield Installation Information
    2010-02-05 17:14 . 2006-06-29 11:38 -------- d-----w- c:\program files\Intermediary Mortgages
    2010-02-05 17:12 . 2006-06-29 11:02 -------- d-----w- c:\program files\Northern Rock Online
    2010-02-05 17:11 . 2006-07-29 12:03 -------- d-----w- c:\program files\Alliance and Leicester Online Forms
    2010-02-04 10:14 . 2006-05-13 20:31 -------- d-----w- c:\documents and settings\All Users\Application Data\QuickTime
    2010-01-31 16:55 . 2006-05-15 13:52 -------- d-----w- c:\program files\Microsoft SQL Server
    2010-01-31 11:59 . 2006-06-28 11:57 -------- d-----w- c:\documents and settings\Any Authorised User\Application Data\U3
    2010-01-30 17:22 . 2006-07-18 09:08 -------- d-----w- c:\program files\Abbey
    2010-01-30 15:47 . 2010-01-30 15:47 503808 ----a-w- c:\documents and settings\Any Authorised User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4478271f-n\msvcp71.dll
    2010-01-30 15:47 . 2010-01-30 15:47 499712 ----a-w- c:\documents and settings\Any Authorised User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4478271f-n\jmc.dll
    2010-01-30 15:47 . 2010-01-30 15:47 348160 ----a-w- c:\documents and settings\Any Authorised User\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-4478271f-n\msvcr71.dll
    2010-01-30 15:47 . 2010-01-30 15:47 61440 ----a-w- c:\documents and settings\Any Authorised User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7526f901-n\decora-sse.dll
    2010-01-30 15:47 . 2010-01-30 15:47 12800 ----a-w- c:\documents and settings\Any Authorised User\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-7526f901-n\decora-d3d.dll
    2010-01-30 15:15 . 2006-05-12 14:41 -------- d-----w- c:\program files\Common Files\Symantec Shared
    2010-01-30 14:37 . 2010-01-30 14:37 7456 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
    2010-01-30 14:37 . 2010-01-30 14:37 806 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
    2010-01-30 14:37 . 2008-01-29 11:01 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
    2010-01-30 14:37 . 2010-01-30 14:37 1291104 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\SyKnAppS.dll
    2010-01-30 14:37 . 2010-01-30 14:37 136840 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\SyKnAppS\patch25.dll
    2010-01-30 14:37 . 2008-01-29 11:02 107368 ----a-r- c:\windows\system32\GEARAspi.dll
    2010-01-30 14:37 . 2010-01-30 14:37 771440 ----a-w- c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\CLT\cltLMSx.dll
    2010-01-30 14:19 . 2006-05-12 14:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
    2010-01-30 14:17 . 2006-05-12 14:48 -------- d-----w- c:\documents and settings\Any Authorised User\Application Data\Symantec
    2010-01-27 09:25 . 2006-05-10 17:45 -------- d-----w- c:\program files\Common Files\Java
    2010-01-27 09:23 . 2006-05-10 17:45 -------- d-----w- c:\program files\Java
    2010-01-22 19:51 . 2010-01-22 19:51 72488 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.0.3.15\SetupAdmin.exe
    2010-01-05 10:00 . 2010-01-05 10:00 78336 ------w- c:\windows\system32\ieencode.dll
    2009-12-31 16:50 . 2005-02-02 19:01 353792 ----a-w- c:\windows\system32\drivers\srv.sys
    2009-12-21 19:14 . 2005-02-02 18:59 916480 ------w- c:\windows\system32\wininet.dll
    2009-12-17 17:14 . 2008-12-08 09:55 411368 ----a-w- c:\windows\system32\deploytk.dll
    2009-12-16 18:43 . 2005-02-02 18:58 343040 ----a-w- c:\windows\system32\mspaint.exe
    2009-12-14 07:08 . 2005-02-02 18:58 33280 ----a-w- c:\windows\system32\csrsrv.dll
    2009-12-08 19:27 . 2005-02-02 18:58 2189184 ------w- c:\windows\system32\ntoskrnl.exe
    2009-12-08 18:43 . 2005-02-02 18:58 2066048 ------w- c:\windows\system32\ntkrnlpa.exe
    2009-12-04 18:22 . 2005-02-02 19:01 455424 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
    2009-11-27 17:11 . 2005-02-02 18:59 1291776 ----a-w- c:\windows\system32\quartz.dll
    2009-11-27 17:11 . 2005-02-02 18:58 17920 ----a-w- c:\windows\system32\msyuv.dll
    2009-11-27 16:07 . 2005-02-02 18:59 8704 ----a-w- c:\windows\system32\tsbyuv.dll
    2009-11-27 16:07 . 2005-02-02 18:58 28672 ----a-w- c:\windows\system32\msvidc32.dll
    2009-11-27 16:07 . 2005-02-02 18:58 11264 ----a-w- c:\windows\system32\msrle32.dll
    2009-11-27 16:07 . 2005-02-02 18:58 48128 ----a-w- c:\windows\system32\iyuv_32.dll
    2009-11-27 16:07 . 2005-02-02 18:58 84992 ----a-w- c:\windows\system32\avifil32.dll
    2009-11-21 15:51 . 2005-02-02 18:53 471552 ----a-w- c:\windows\AppPatch\aclayers.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IgfxTray"="c:\windows\system32\igfxtray.exe" [2005-03-22 155648]
    "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-03-22 126976]
    "SMSERIAL"="sm56hlpr.exe" [2005-04-26 544768]
    "SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2004-10-05 98394]
    "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2004-10-05 688218]
    "NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
    "InCD"="c:\program files\Ahead\InCD\InCD.exe" [2005-07-25 1397760]
    "QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-11-10 417792]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 246504]
    "ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2004-06-16 81920]
    "iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-01-22 141608]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

    c:\documents and settings\Any Authorised User\Start Menu\Programs\Startup\
    ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

    c:\documents and settings\All Users\Start Menu\Programs\Startup\
    EPSON Status Monitor 3 Environment Check(2).lnk - c:\windows\system32\spool\drivers\w32x86\3\E_SRCV02.EXE [2006-5-12 131584]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
    @="FSFilter Activity Monitor"

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "c:\\WINDOWS\\system32\\spoolsv.exe"=
    "c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "c:\\Program Files\\iTunes\\iTunes.exe"=

    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0308000.029\SymEFA.sys [05/02/2010 18:09 310320]
    R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\system32\drivers\N360\0308000.029\BHDrvx86.sys [05/02/2010 18:09 259632]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0308000.029\cchpx86.sys [05/02/2010 18:09 482432]
    R1 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20100210.001\IDSXpx86.sys [14/02/2010 19:03 329592]
    R2 MSSQL$INERTIA3_SQL2005;SQL Server (INERTIA3_SQL2005);c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [24/11/2008 22:31 29263712]
    R2 N360;Norton 360;c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe [05/02/2010 18:08 117640]
    R2 TRUService;Trigold Update Service;c:\program files\Trigold\Update\TRUService.exe [14/07/2008 13:24 135816]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/02/2010 20:19 102448]
    .
    Contents of the 'Scheduled Tasks' folder

    2010-02-05 c:\windows\Tasks\AppleSoftwareUpdate.job
    - c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
    .
    .
    ------- Supplementary Scan -------
    .
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uStart Page = hxxp://www.intrinsicfs.com/
    uInternet Connection Wizard,ShellNext = hxxp://www.bbc.co.uk/
    uInternet Settings,ProxyOverride = *.local
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    DPF: {0089F6EE-ED54-11D5-B0E7-00508B014C1D} - hxxps://exweb.exchange.uk.com/clientbinaries/texInfo.CAB
    DPF: {034DA761-EDB7-11D7-A20A-000802318089} - hxxps://exweb.exchange.uk.com/clientbinaries/EWGPHI.CAB
    DPF: {090EC279-1378-44B7-B521-888980212E7E} - hxxps://exweb.exchange.uk.com/clientbinaries/eXwebCListCtl3.CAB
    DPF: {2F6A847E-2EC2-11D3-AE1B-00508B014C1D} - hxxps://exweb.exchange.uk.com/clientbinaries/XMLParser.CAB
    DPF: {397F65A6-FD3C-438B-A7EB-3D2C0655189C} - hxxps://exweb.exchange.uk.com/clientbinaries/EWGPensions.CAB
    DPF: {511835FF-EDC9-11D7-A20A-000802318089} - hxxps://exweb.exchange.uk.com/clientbinaries/EWGWholeLife.CAB
    DPF: {61DA056C-EDE7-11D7-A20A-000802318089} - hxxps://exweb.exchange.uk.com/clientbinaries/EWGBonds.CAB
    DPF: {8E95B0CA-EB6F-11D3-979B-00508B64538B} - hxxps://exweb.exchange.uk.com/clientbinaries/VersionInfo.CAB
    DPF: {A74D724A-AB17-11D2-A96A-006097E20477} - hxxps://exweb.exchange.uk.com/clientbinaries/eXwebUtils.CAB
    DPF: {DDECE2F5-AF1F-44E7-B37F-96B6630F5C60} - hxxps://exweb.exchange.uk.com/clientbinaries/printdll.CAB
    DPF: {E7FF5332-854E-11D2-A952-006097E20477} - hxxps://exweb.exchange.uk.com/clientbinaries/eXwebOcc.CAB
    DPF: {E9C9692E-F93C-11D1-ABB0-0040054FC6FB} - hxxps://exweb.exchange.uk.com/clientbinaries/pvdt70.CAB
    .

    **************************************************************************

    catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2010-02-18 17:17
    Windows 5.1.2600 Service Pack 3 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************

    [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\N360]
    "ImagePath"="\"c:\program files\Norton 360\Engine\3.8.0.41\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\3.8.0.41\diMaster.dll\" /prefetch:1"
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'explorer.exe'(2776)
    c:\windows\system32\WININET.dll
    c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
    c:\windows\system32\ieframe.dll
    c:\windows\system32\webcheck.dll
    c:\windows\system32\WPDShServiceObj.dll
    c:\windows\system32\PortableDeviceTypes.dll
    c:\windows\system32\PortableDeviceApi.dll
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Ahead\InCD\InCDsrv.exe
    c:\program files\Common Files\EPSON\eEBAPI\eEBSVC.exe
    c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    c:\program files\Bonjour\mDNSResponder.exe
    c:\program files\Java\jre6\bin\jqs.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
    c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    c:\windows\system32\wscntfy.exe
    c:\windows\sm56hlpr.exe
    c:\program files\iPod\bin\iPodService.exe
    .
    **************************************************************************
    .
    Completion time: 2010-02-18 17:23:58 - machine was rebooted
    ComboFix-quarantined-files.txt 2010-02-18 17:23
    ComboFix2.txt 2010-02-18 16:26

    Pre-Run: 29,475,581,952 bytes free
    Post-Run: 29,392,388,096 bytes free

    - - End Of File - - AB10ED0C5E351AB0632999CB210014FE

  8. #8
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi again,

    Do you have Spybot scan results handy? If you do, post those too, please.


    Open notepad and copy/paste the text in the quotebox below into it:

    Code:
    Dequarantine::
    c:\qoobox\quarantine\c\windows\pchealth\UploadLB\Binaries\uploadm.exe.vir
    c:\qoobox\quarantine\c\windows\pchealth\UploadLB\Config\config.xml.vir
    Ignore::
    c:\windows\pchealth\UploadLB\Binaries\uploadm.exe
    c:\windows\pchealth\UploadLB\Config\config.xml
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring"=dword:00000000
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring"=dword:00000000
    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring"=dword:00000000

    Save this as
    CFScript

    A word of warning: Neither I nor sUBs are responsible for any damage you may have caused your machine. This tool is not a toy and not for everyday use.



    Close all browser windows, disable protection software and refering to the picture above, drag CFScript into ComboFix.exe (let ComboFix update itself).
    Then post the resultant log.


    Uninstall old Adobe Reader versions and get the latest one (9.3 + update 9.3.1) here or get Foxit Reader here. Make sure you don't install toolbar if choose Foxit Reader! You may also check free readers introduced here.

    Uninstall vulnerable Flash versions by following instructions here. Fresh version can be obtained here.


    Uninstall these old Javas:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Java(TM) SE Runtime Environment 6 Update 1



    Download ATF (Atribune Temp File) Cleaner© by Atribune to your desktop.

    Double-click ATF Cleaner.exe to open it

    Under Main choose:
    Windows Temp
    Current User Temp
    All Users Temp
    Cookies
    Temporary Internet Files
    Prefetch
    Java Cache

    *The other boxes are optional*
    Then click the Empty Selected button.

    If you use Firefox:
    Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    If you use Opera:
    Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click NO at the prompt.

    Click Exit on the Main menu to close the program.


    Please run an online scan with Kaspersky Online Scanner as instructed in the screenshot here.


    Post back its report, a fresh dds.txt log and above mentioned ComboFix resultant log.
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

  9. #9
    Member
    Join Date
    Feb 2010
    Posts
    37

    Default

    i dragged the CFScript into combofix and the scan run as normal, however where the last log file was just on my c drive, i cant find the new log file, there is a combofix.txt in the combofix folder, but i dont know if that is the correct log file.

    Zara

  10. #10
    Security Expert: Emeritus Blade81's Avatar
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    25,288

    Default

    Hi,

    What's the timestamp of that log file in c:\ComboFix folder?
    Microsoft Windows Insider MVP 2016-2020
    Microsoft MVP Consumer Security 2008-2015
    UNITE member since 2006

    If you have problems create a thread in the forum, please.

    Malware removal instructions are for the correspondent user's case only.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •