Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: Virtumonde assistant plead

  1. #11
    Malware Team-Emeritus
    Join Date
    Jul 2007
    Location
    Little Red Dot
    Posts
    507

    Default

    Yup, it's safe to post logs directly from that computer from now on, although it's no longer required now. Your computer is clean as far as I can see.

    Unless there are more issues, you needn't post more logs. You can also re-enable your Internet connection.

    Just some cleaning up to do.

    Now that your computer is clean, we no longer need to keep the removal tools downloaded. They will need to be removed.

    Remove Combofix

    Click on Start > Run. Copy and paste in ComboFix /u and click OK. An image is below for reference.



    Create a new, clean System Restore point

    1. Click on Start > All Programs > Accessories > System Tools > System Restore.
    2. On the Welcome Page, select Create a restore point. Click Next.
    3. Give this restore point a descriptive name and click Create.
    4. When done, click Close.


    Warning: Do not clear infected System Restore points before creating a new System Restore point first!

    Please read the above to create a new System Restore point first, then clear out the infected System Restore points.


    Clear infected System Restore points

    1. Click on Start > All Programs > Accessories > System Tools > Disk Cleanup.
    2. Select C drive and click OK.
    3. Select the More Options tab.
    4. Under System Restore, click on Clean up....
    5. You will be prompted. Click Yes.
    6. When done, click OK.
    7. You will be prompted again. Press Yes to confirm.
    8. When done, Disk Cleanup will close automatically.


    Here are some tips to prevent another infection again. There's no need to install all programs recommended.

    Keep your system updated

    Microsoft releases patches for Windows and Office products regularly to patch up Windows and Office products loopholes and fix any bugs found. Please ensure that you visit the following websites regularly or do update your system regularly.

    Install the updates immediately if they are found. Reboot your computer if necessary, revisit Windows Update and Office update sites until there are no more updates to be installed.

    To update Windows

    Go to Start > All Programs > Windows Update

    To update Office

    Open up any Office program.

    Go to Help > Check for Updates

    Alternatively, you can visit the links below to update Windows and Office products.

    Windows Update
    Office Update

    If you are forgetful, you can change some settings so that you will be informed of updates. Here's how:

    1. Go to Start > Control Panel > Automatic Updates
    2. Select Automatic (recommended) radio button if you want the updates to be downloaded and installed without prompting you.
    3. Select Download updates for me, but let me chose when to install them radio button if you want the updates to be downloaded automatically but to be installed at another time.
    4. Select Notify me but don't automatically download or install them radio button if you want to be notified of the updates.


    Besides Windows that needs regular updating, antivirus, anti-spyware and firewall programs update regularly too.

    Please make sure that you update your antivirus, firewall and anti-spyware programs at least once a week.

    Be careful when opening attachments and downloading files.

    1. Never open email attachments, not even if they are from someone you know. If you need to open them, scan them with your antivirus program before opening.
    2. Never open emails from unknown senders.
    3. Beware of emails that warn about viruses that are spreading, especially those from antivirus vendors. These email addresses can be easily spoofed. Check the antivirus vendor websites to be sure.
    4. Be careful of what you download. Only download files from known sources. Also, avoid cracked programs. If you need a particular program that costs too much for you, try finding free alternatives on Sourceforge or Pricelessware.


    Surf safely

    Many of the exploits are directed to users of Internet Explorer and Firefox.

    Using Firefox with NoScript add-on helps to prevent most exploits from running as NoScript by default disables all scripts on all websites. If you trust the website, you can manually allow it.

    If you prefer to use Internet Explorer, here are some settings to change to improve the security of Internet Explorer.

    For Internet Explorer 7

    Please read this article to configure Internet Explorer 7 properly.

    Stop malicious scripts

    Windows by default allow scripts (which is VBScript and JavaScript) to run and some of these scripts are malicious. Use Noscript by Symantec or Script Defender by AnalogX to handle these scripts.

    Backup regularly

    You never know when your PC will become unstable or become so infected that you can't recover it. Follow this Microsoft article to learn how to backup. Follow this article by Microsoft to restore your backups.

    Alternatively, you can use 3rd-party programs to back up your data. One example can be found at Bleeping Computer.

    Avoid P2P

    P2P may be a great way to get lots of stuffs, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. If you do need to use them, use them sparingly. Check this list of clean and infected P2P programs if you need to use one.

    Prevent a re-infection

    1. Winpatrol
      Winpatrol is heuristic protection program, meaning it looks for patterns in codes that work like malware. It also takes a snapshot of your system's critical resources and alerts you to any changes that may occur without you knowing. You can read more about Winpatrol's features here.

      You can get a free copy of Winpatrol or use the Plus version for more features.

      You can read Winpatrol's FAQ if you run into problems.

    2. Spyware Blaster
      SpywareBlaster is a program that is used to secure Internet Explorer by making it harder for ActiveX programs to run on your computer. It does this by disabling known offending ActiveX programs from running at all.

      You can download SpywareBlaster from Javacool.

      If you need help in using SpywareBlaster, you can read SpywareBlaster's tutorial at Bleeping Computer.

    3. SpywareGuard
      Just as an antivirus program scans a file for viruses before opening it, SpywareGuard does the same thing, except that it scans it for spywares.

      You can download SpywareGuard from Javacool.

      If you need help in using SpywareGuard, you can SpywareGuard's tutorial at Bleeping Computer.

    4. Spybot Search and Destroy
      Spybot Search & Destroy is another program for scanning spywares and adwares. Not only so, it has other preventive options as well. You are strongly encouraged to run a scan at least once per week.

      Spybot Search & Destroy can be downloaded from here.

      If you need help in using Spybot Search & Destroy, you can read Spybot Search and Destroy tutorial at Bleeping Computer.

    5. Malwarebytes' Anti-Malware
      Malwarebytes' Anti-Malware is a new and powerful anti-malware program. It scans and removes malware for free, but if you want real-time protection, you can pay a small one-time fee.

      Remember to update and scan with it regularly. A tutorial for using Malwarebytes' Anti-Malware can be found on BFC Computer Help.

      Before downloading any anti-spyware programs, always check the Rogue/Suspect list of anti-spyware programs and Malwarebytes RogueNET. This will save you from a lot of trouble. If in doubt, don't ever download it.

    6. SiteHound Toolbar
      SiteHound is a toolbar that warns you if you go to a site that is known to scam people, that has potentially lots of viruses or spywares or has questionable contents. If you know the site, you can enter it; if you don't, it will bring you back to the previous page. Currently, SiteHound works for Internet Explorer and Firefox only.


    Use an alternative email client

    If you are using Outlook Express as your default email client, try using Thunderbird or Pegasus Mail instead.

    Here are some more things to read about:

    List of clean and infected download managers
    Configuring Skype
    Greater email safety
    Phishing - what is it?
    Configuring Outlook Express
    The Unofficial Cookie FAQ
    Securing your home wireless network
    80 Super Security Tips
    The different classes of security softwares
    扎西德勒 微笑中有阳光 不放弃的人都拥有希望

    Please do not message me for help. Create a new topic in the Malware Removal room instead.

  2. #12
    Junior Member
    Join Date
    Jun 2008
    Posts
    9

    Default

    ComboFix removed and Restore Points handled as instructed.

    I think you guys are awesome, seriously. I felt all the time in capable hands, I don't know what I'd have done without your help.

    Yesterday I was reading around this forum, and somebody said that if he had brought the computer to a shop, they would probably have handed him back a wiped computer and a service bill for the troubles. I cannot agree more with that.

    You have helped me without asking questions or judging me at any point. You have fixed my computer and saved me God knows how many headaches. And yet you haven't even asked for a donation. Well I'm going to do the same as the person above, and find my way to the donate button (tomorrow, because today I'm poorer than the rats :P). A site like this simply cannot disappear.

    Just a couple of small issues before I leave. I think I should be fine, but better safe than sorry.

    After removing ComboFix, it seems some of its files are not completely gone, especifically:

    C:\...
    ...\cmdcons folder (inside:.SY_ and .dll files, BIOSINFO.INF and a \system32 folder with NTDLL.DLL and SMSS.EXE inside)
    ...\comboFix (empty folder)
    cmldr file
    Bug.txt

    Also I have followed some of your advised links and installed Malwarebytes' Anti-Malware, Winpatrol and Script Defender. After a scan with Malwarebytes' it found a couple of trojans, one of them seems a Vundo leftover. This is the log:

    Malwarebyte's log

    Malwarebytes' Anti-Malware 1.18
    Database version: 871

    20:33:55 20/06/2008
    mbam-log-6-20-2008 (20-33-55).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 183444
    Time elapsed: 44 minute(s), 27 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 2

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\pc\Mis documentos\My Games\Morrowind\Building a New Game\Mods\Quest\wizards_islands_update_v105_pathfixed.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\clkcnt.txt (Trojan.Vundo) -> Quarantined and deleted successfully.


    HijackThis log

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 22:31:18, on 20/06/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Archivos de programa\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\Archivos de programa\WIDCOMM\Software Bluetooth\bin\btwdins.exe
    C:\Archivos de programa\Nero 8\InCD\InCDsrv.exe
    C:\Archivos de programa\Archivos comunes\InterVideo\RegMgr\iviRegMgr.exe
    C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Archivos de programa\Nero 8\Nero BackItUp\NBService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\ISUSPM.exe
    C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\WINDOWS\explorer.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Archivos de programa\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe
    C:\Archivos de programa\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\pc\Escritorio\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.es/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Archivos de programa\Real\RealPlayer\rpbrowserrecordplugin.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.6.0_06\bin\ssv.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Archivos de programa\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ISUSPM] "C:\Archivos de programa\Archivos comunes\InstallShield\UpdateService\ISUSPM.exe" -scheduler
    O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Archivos de programa\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Archivos de programa\Archivos comunes\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Archivos de programa\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICIO LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Servicio de red')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Archivos de programa\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Archivos de programa\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Archivos de programa\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: &Download by Orbit - res://C:\Archivos de programa\Tools\Orbitdownloader\orbitmxt.dll/201
    O8 - Extra context menu item: &Grab video by Orbit - res://C:\Archivos de programa\Tools\Orbitdownloader\orbitmxt.dll/204
    O8 - Extra context menu item: Add to Anti-Banner - C:\Archivos de programa\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
    O8 - Extra context menu item: Append to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Archivos de programa\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Archivos de programa\Tools\Orbitdownloader\orbitmxt.dll/203
    O8 - Extra context menu item: Down&load all by Orbit - res://C:\Archivos de programa\Tools\Orbitdownloader\orbitmxt.dll/202
    O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\ARCHIV~1\MICROS~2\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Enviar a &Bluetooth - C:\Archivos de programa\WIDCOMM\Software Bluetooth\btsendto_ie_ctx.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.6.0_06\bin\ssv.dll
    O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Archivos de programa\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
    O9 - Extra button: Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: &Enviar a OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\ARCHIV~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\ARCHIV~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Software Bluetooth\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Archivos de programa\WIDCOMM\Software Bluetooth\btsendto_ie.htm
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Archivos de programa\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
    O12 - Plugin for .csm: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .csml: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .cub: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .cube: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .dx: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .emb: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .embl: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .gau: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .jdx: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .mol: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .mop: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .pdb: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .rxn: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .scr: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .skc: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .spt: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .tgf: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O12 - Plugin for .xyz: C:\Archivos de programa\Internet Explorer\Plugins\npchime.dll
    O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.nl/scanforvirus...an_unicode.cab
    O16 - DPF: {1C4C6BC7-91F1-4FD3-A208-B07B6C1BDBFA} (Firma1Fase Class) - http://www.juntadeandalucia.es/innov...firma/Sign.cab
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/micr...?1210535988171
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAV...oadManager.ocx
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7C9E2F7D-D3FB-480F-8F19-2C0DD3EFB3D6}: NameServer = 194.224.52.4,193.152.63.197
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Archivos de programa\Microsoft Office\Office12\GrooveSystemServices.dll
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\ARCHIV~1\ARCHIV~1\Skype\SKYPE4~1.DLL
    O20 - AppInit_DLLs: C:\ARCHIV~1\KASPER~1\KASPER~1.0\adialhk.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Archivos de programa\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
    O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Archivos de programa\WIDCOMM\Software Bluetooth\bin\btwdins.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Archivos de programa\Archivos comunes\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Archivos de programa\Hewlett-Packard\Shared\hpqwmiex.exe
    O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Archivos de programa\Nero 8\InCD\InCDsrv.exe
    O23 - Service: IviRegMgr - InterVideo - C:\Archivos de programa\Archivos comunes\InterVideo\RegMgr\iviRegMgr.exe
    O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Archivos de programa\Nero 8\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Archivos de programa\Archivos comunes\Nero\Lib\NMIndexingService.exe
    O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Archivos de programa\CyberLink\Shared files\RichVideo.exe (file missing)

    --
    End of file - 12394 bytes

  3. #13
    Malware Team-Emeritus
    Join Date
    Jul 2007
    Location
    Little Red Dot
    Posts
    507

    Default

    C:\cmdcons folder - This folder will be created when you install Recovery Console. I had you do this when you ran Combofix.

    C:\Combofix - Probably Combofix has some trouble removing itself. You can safely delete this folder.

    cmldr - Related to Recovery Console as well.

    Bug.txt - It's for troubleshooting purposes. Your system is fine, no worries.

    C:\Documents and Settings\pc\Mis documentos\My Games\Morrowind\Building a New Game\Mods\Quest\wizards_islands_update_v105_pathfixed.exe

    This is probably a false alarm. It's related to your game. Please restore it from the Quarantine.

    1. Open Malwarebytes' Anti-Malware.
    2. Select the Quarantine tab.
    3. Find C:\Documents and Settings\pc\Mis documentos\My Games\Morrowind\Building a New Game\Mods\Quest\wizards_islands_update_v105_pathfixed.exe and click on Restore to restore it.

    And yet you haven't even asked for a donation.
    Helpers don't ask for personal donations. You may donate to Spybot if you want to help us.

    Let me know if you have other questions.
    扎西德勒 微笑中有阳光 不放弃的人都拥有希望

    Please do not message me for help. Create a new topic in the Malware Removal room instead.

  4. #14
    Junior Member
    Join Date
    Jun 2008
    Posts
    9

    Default

    No more questions, just a big thank you to you all

    D.

  5. #15
    Malware Team-Emeritus
    Join Date
    Jul 2007
    Location
    Little Red Dot
    Posts
    507

    Default

    That's good to hear.

    As the issue is resolved... this topic is now closed. Please contact a member of the moderating team if you need it re-opened. This applies to the original topic starter.

    Everyone else please begin a new topic.
    扎西德勒 微笑中有阳光 不放弃的人都拥有希望

    Please do not message me for help. Create a new topic in the Malware Removal room instead.

  6. #16
    Malware Team-Emeritus
    Join Date
    Jul 2007
    Location
    Little Red Dot
    Posts
    507

    Default

    Hi,

    If you don't mind, we need one log to find out what's causing the false positive.

    Please follow this post and post back the Malwarebytes' Anti-Malware log - http://www.malwarebytes.org/forums/i...showtopic=3228
    扎西德勒 微笑中有阳光 不放弃的人都拥有希望

    Please do not message me for help. Create a new topic in the Malware Removal room instead.

  7. #17
    Junior Member
    Join Date
    Jun 2008
    Posts
    9

    Default

    I had it removed just in case, since I don't have time to play the game anyways. But I re-downloaded the file, to the desktop this time, and ran a full analysis just like before.

    This is the log produced, hope it helps:

    Malwarebyte's Anti-Malware log (developer mode)

    Malwarebytes' Anti-Malware 1.18
    Database version: 876

    13:46:44 22/06/2008
    mbam-log-6-22-2008 (13-46-44).txt

    Scan type: Full Scan (C:\|)
    Objects scanned: 183583
    Time elapsed: 48 minute(s), 49 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 1

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Documents and Settings\pc\Escritorio\wizards_islands_update_v105_pathfixed.exe (Trojan.Downloader) -> Quarantined and deleted successfully. [STRINGS=Trojan.Downloader, 1024, FFEFBEFDE80D0027C05005011F0E000090558BEC5356578B7D108B5D77EFFEFF0C8B75088BD3FF751468E54041006A018BC68BCF30437C81EEEEFEEDEB10012C74054B7414EB57216A66564221A2B8EEBFFFEF1500EB476681E7FFFF66FFCF74070423EB30688017C9EFB1EE68CC50466529126A013120F4DFFEC0DA155B0E0633C0EB02035F5E5B5D869009ECC21000]

  8. #18
    Malware Team-Emeritus
    Join Date
    Jul 2007
    Location
    Little Red Dot
    Posts
    507

    Default

    Thank you.

    I will get the developer to look at it and hopefully he has an answer soon.
    扎西德勒 微笑中有阳光 不放弃的人都拥有希望

    Please do not message me for help. Create a new topic in the Malware Removal room instead.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •