![]() ![]() |
Jul 14 2009, 07:06 AM
Post
#1
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
I am running Vista Ultimate 32 bit system with service pack 1. I have already ran the ATF Cleaner on my system. and rebooted the computer. What do I need to do to get a file log. |
|
|
|
Jul 14 2009, 07:43 AM
Post
#2
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
Just a little more information. TrendMicro didn't find any viruses so I went to the microsoft web site and ran the onecare live program. This ran and came up with the following:
Trojandownloader:Win32/Renos.gen!BE When I tried to follow the removal process a pop up said this program is not compatible with Vista 64 bit systems. I am running the 32 bit system and that was what it was supposed to work with. I went to What the tech and followed the steps for removing this virus. That is when I couldn't get the Malwarebytes Anti-Malware to work. So I am waiting for someone to help me with the next step. Thanks David |
|
|
|
Jul 14 2009, 07:53 AM
Post
#3
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi and Welcome,
NOTE:
Please do the following: STEP #1 Please download DDS and save it to your desktop.
Please include the contents of the following in your next reply: DDS.txt Attach.txt. STEP #2 (NOTE: If GMER won't run in normal mode, try it in safe mode) ![]() Download GMER Rootkit Scanner from here or here.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries . |
|
|
|
Jul 14 2009, 08:21 AM
Post
#4
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
I have attached the DDS.txt and the Attach.txt logs
DDS (Ver_09-06-26.01) - NTFSx86 Run by ensign at 10:11:22.18 on Tue 07/14/2009 Internet Explorer: 8.0.6001.18783 Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2045.1213 [GMT -4:00] AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Program Files\Trend Micro\BM\TMBMSRV.exe C:\Windows\Explorer.EXE C:\Program Files\Linksys\Linksys Updater\bin\LinksysUpdater.exe C:\Windows\system32\java.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\taskeng.exe C:\Program Files\Zune\ZuneLauncher.exe C:\Program Files\Maxtor\OneTouch Status\MaxMenuMgr.exe C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe C:\Program Files\SigmaTel\C-Major Audio\WDM\sttray.exe C:\Windows\system32\STacSV.exe C:\Windows\ehome\ehtray.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Trend Micro\Internet Security\TmProxy.exe C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\Trend Micro\Internet Security\TmPfw.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Program Files\Internet Explorer\Iexplore.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\WUDFHost.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\ensign\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: MJCore class: {d88e1558-7c2d-407a-953a-c044f5607cea} - c:\program files\jcore\Jcore2.dll TB: {A057A204-BACC-4D26-9990-79A187E2698E} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [Zune Launcher] "c:\program files\zune\ZuneLauncher.exe" mRun: [mxomssmenu] "c:\program files\maxtor\onetouch status\maxmenumgr.exe" mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [UfSeAgnt.exe] "c:\program files\trend micro\internet security\UfSeAgnt.exe" mRun: [StartCCC] c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe mRun: [SigmatelSysTrayApp] c:\program files\sigmatel\c-major audio\wdm\sttray.exe mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~3.0_0\bin\ssv.dll IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office12\REFIEBAR.DLL DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/C/0/C/C0CBBA88-A6F2-48D9-9B0E-1719D1177202/LegitCheckControl.cab DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} - hxxp://support.dell.com/systemprofiler/SysProExe.CAB DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_06-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL STS: Windows DreamScene: {e31004d1-a431-41b8-826f-e902f9d95c81} - %SystemRoot%\System32\DreamScene.dll ============= SERVICES / DRIVERS =============== R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\system32\drivers\tmlwf.sys [2008-7-29 145424] R2 LinksysUpdater;Linksys Updater;c:\program files\linksys\linksys updater\bin\LinksysUpdater.exe [2008-1-15 204800] R2 Maxtor Sync Service;Maxtor Service;c:\program files\maxtor\sync\SyncServices.exe [2007-9-28 156976] R2 tmevtmgr;tmevtmgr;c:\windows\system32\drivers\tmevtmgr.sys [2008-7-29 50192] R2 TmPfw;Trend Micro Personal Firewall;c:\program files\trend micro\internet security\TmPfw.exe [2009-1-18 497008] R2 tmpreflt;tmpreflt;c:\windows\system32\drivers\tmpreflt.sys [2009-3-19 36368] R2 TmProxy;Trend Micro Proxy Service;c:\program files\trend micro\internet security\TmProxy.exe [2009-1-18 677128] R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\system32\drivers\tmwfp.sys [2008-7-29 256528] =============== Created Last 30 ================ 2009-07-13 07:12 <DIR> --d----- c:\programdata\Windows Genuine Advantage 2009-07-13 07:03 142,829,963 a------- c:\windows\MEMORY.DMP 2009-07-09 17:42 <DIR> --d----- c:\program files\WWShow 2009-07-09 17:37 <DIR> --d----- c:\program files\Jcore 2009-07-09 17:36 <DIR> --d----- c:\users\ensign\appdata\roaming\pridl 2009-06-23 17:53 30,568 a------- c:\windows\system32\mdimon.dll ==================== Find3M ==================== 2009-06-10 22:35 86,016 a------- c:\windows\inf\infstrng.dat 2009-06-10 22:35 51,200 a------- c:\windows\inf\infpub.dat 2009-06-10 22:35 86,016 a------- c:\windows\inf\infstor.dat 2009-05-09 01:50 915,456 a------- c:\windows\system32\wininet.dll 2009-05-09 01:34 71,680 a------- c:\windows\system32\iesetup.dll 2009-04-30 08:37 293,376 a------- c:\windows\system32\psisdecd.dll 2009-04-30 08:37 428,544 a------- c:\windows\system32\EncDec.dll 2009-04-23 08:43 784,896 a------- c:\windows\system32\rpcrt4.dll 2009-04-23 08:42 636,928 a------- c:\windows\system32\localspl.dll 2009-04-21 07:55 2,033,152 a------- c:\windows\system32\win32k.sys 2008-06-14 23:38 665,600 a------- c:\windows\inf\drvindex.dat 2008-06-13 18:16 174 a--sh--- c:\program files\desktop.ini 2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 08:40 287,440 a------- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 08:40 30,674 a------- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 05:20 287,440 a------- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 05:20 30,674 a------- c:\windows\inf\perflib\0000\perfc.dat 2006-11-22 10:58 8,192 a--sh--- c:\windows\users\default\NTUSER.DAT ============= FINISH: 10:14:00.73 ===============
Attached File(s)
|
|
|
|
Jul 14 2009, 08:42 AM
Post
#5
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Any luck getting the GMER scan to run?
|
|
|
|
Jul 14 2009, 09:16 AM
Post
#6
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
I downloaded the gmer and unzipped it but when I tried to run it I got the blue screen of death.
I have to run to work now so please leave me my next option and I will get back to work on it when I get home. |
|
|
|
Jul 14 2009, 10:24 AM
Post
#7
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
One or more of the identified infections is a backdoor trojan and password stealer.
This type of infection allows hackers to access and remotely control your computer, log keystrokes, steal critical system information, and download and execute files without your knowledge. If you do any banking or other financial transactions on the PC or if it contains any other sensitive information, then from a clean computer, change all passwords where applicable. It would also be wise to contact those same financial institutions to appraise them of your situation. Please read this: How Do I Handle Possible Identify Theft, Internet Fraud, and CC Fraud? Please do the following: Download Combofix from either of the links below. You must rename it before saving it. Save it to your desktop. **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved and renamed following this process directly to your desktop**
Link 1 Link 2 During the download, rename Combofix to Combo-Fix as follows: ![]() ![]() --------------------------------------------------------------------
-----------------------------------------------------------
|
|
|
|
Jul 14 2009, 06:48 PM
Post
#8
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
I started to run combo-fix and all of a sudden the computer shut down and rebooted. A box popped up and said windows experienced a unexpected shutdown. Should I delete the combo-fix reinstall it then disconnect my computer from the internet while combo-fix runs. That way no one can take control of the computer and interrupt combo-fix.
|
|
|
|
Jul 14 2009, 07:00 PM
Post
#9
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Yes, please do, delete the copy you have download a fresh copy
make sure all your security programs are disabled so they do not interfere with combo-fix |
|
|
|
Jul 14 2009, 07:43 PM
Post
#10
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
here is the combo fix notepad file
ComboFix 09-07-14.07 - ensign 07/14/2009 21:19.3.2 - NTFSx86 Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.2045.1303 [GMT -4:00] Running from: c:\users\ensign\Desktop\Combo-Fix.exe AV: Trend Micro Internet Security *On-access scanning disabled* (Updated) {7D2296BC-32CC-4519-917E-52E652474AF5} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} . ((((((((((((((((((((((((( Files Created from 2009-06-15 to 2009-07-15 ))))))))))))))))))))))))))))))) . 2009-07-14 14:23 . 2009-07-14 17:38 -------- d-----w- c:\users\ensign\AppData\Local\Adobe 2009-07-12 00:54 . 2009-07-12 00:55 -------- d-----w- c:\program files\Windows Live Safety Center 2009-07-09 21:36 . 2009-07-12 03:50 -------- d-----w- c:\users\ensign\AppData\Roaming\pridl 2009-06-27 08:05 . 2009-06-27 08:05 746744 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll 2009-06-23 21:53 . 2008-11-04 07:30 30568 ----a-w- c:\windows\system32\mdimon.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-07-02 00:30 . 2009-06-03 21:54 -------- d-----w- c:\users\ensign\AppData\Roaming\Skype 2009-07-01 20:00 . 2009-06-03 22:01 -------- d-----w- c:\users\ensign\AppData\Roaming\skypePM 2009-06-23 21:54 . 2008-06-14 09:42 -------- d-----w- c:\programdata\Microsoft Help 2009-06-11 02:39 . 2009-06-11 02:39 -------- d-----w- c:\users\ensign\AppData\Roaming\ATI 2009-06-11 02:33 . 2009-06-11 02:33 -------- d-----w- c:\program files\SigmaTel 2009-06-11 02:33 . 2008-06-14 10:12 -------- d--h--w- c:\program files\InstallShield Installation Information 2009-06-11 02:33 . 2009-06-11 02:33 -------- d-----w- c:\program files\Common Files\InstallShield 2009-06-11 02:30 . 2009-06-11 02:27 -------- d-----w- c:\program files\ATI Technologies 2009-06-11 02:27 . 2009-06-11 02:27 -------- d-----w- c:\program files\ATI 2009-06-11 02:17 . 2009-06-11 02:17 -------- d-----w- c:\program files\Intel 2009-06-03 22:01 . 2009-06-03 22:01 56 ---ha-w- c:\windows\system32\ezsidmv.dat 2009-06-03 21:53 . 2009-06-03 21:53 -------- d-----w- c:\program files\Common Files\Skype 2009-06-03 21:53 . 2009-06-03 21:53 -------- d-----r- c:\program files\Skype 2009-06-03 21:53 . 2009-06-03 21:53 -------- d-----w- c:\programdata\Skype 2009-05-31 21:23 . 2009-05-31 21:23 -------- d-----w- c:\users\ensign\AppData\Roaming\PeerNetworking 2009-05-25 17:51 . 2008-06-13 17:16 100256 ----a-w- c:\users\ensign\AppData\Local\GDIPFONTCACHEV1.DAT 2009-05-25 17:40 . 2008-06-14 09:46 -------- d-----w- c:\program files\Microsoft Works 2009-05-19 00:36 . 2009-05-19 00:36 -------- d-----w- c:\programdata\WindowsSearch 2009-05-16 00:25 . 2009-05-16 00:25 416128 ----a-w- c:\programdata\Microsoft\eHome\Packages\NetTV\Browse\NetTVResources.dll 2009-05-12 14:04 . 2009-05-12 14:04 34062 ----a-w- c:\users\ensign\AppData\Roaming\Move Networks\ie_bin\Uninst.exe 2009-05-09 05:50 . 2009-06-11 01:47 915456 ----a-w- c:\windows\system32\wininet.dll 2009-05-09 05:34 . 2009-06-11 01:47 71680 ----a-w- c:\windows\system32\iesetup.dll 2009-04-30 12:37 . 2009-06-13 21:27 293376 ----a-w- c:\windows\system32\psisdecd.dll 2009-04-30 12:37 . 2009-06-13 21:27 428544 ----a-w- c:\windows\system32\EncDec.dll 2009-04-23 12:43 . 2009-06-11 01:24 784896 ----a-w- c:\windows\system32\rpcrt4.dll 2009-04-23 12:42 . 2009-06-11 01:34 636928 ----a-w- c:\windows\system32\localspl.dll 2009-04-21 11:55 . 2009-06-11 01:44 2033152 ----a-w- c:\windows\system32\win32k.sys 2006-11-22 14:58 . 2006-11-22 14:58 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT . ((((((((((((((((((((((((((((( SnapShot@2009-07-15_00.26.56 ))))))))))))))))))))))))))))))))))))))))) . + 2008-06-13 21:17 . 2009-07-15 01:16 41004 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2006-11-02 13:03 . 2009-07-15 01:16 62952 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin - 2006-11-02 13:00 . 2009-07-14 23:49 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2006-11-02 13:00 . 2009-07-15 01:16 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2006-11-02 13:00 . 2009-07-15 01:16 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2006-11-02 13:00 . 2009-07-14 23:49 81920 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2006-11-02 13:00 . 2009-07-14 23:49 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2006-11-02 13:00 . 2009-07-15 01:16 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-06-13 18:02 . 2009-07-15 01:16 9642 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-4225793217-963442044-4212106655-1000_UserData.bin - 2009-07-14 14:55 . 2009-07-15 00:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-07-15 01:14 . 2009-07-15 01:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-07-15 01:14 . 2009-07-15 01:14 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-07-14 14:55 . 2009-07-15 00:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2006-11-02 10:33 . 2009-07-15 01:22 598350 c:\windows\System32\perfh009.dat - 2006-11-02 10:33 . 2009-07-15 00:23 598350 c:\windows\System32\perfh009.dat + 2006-11-02 10:33 . 2009-07-15 01:22 101988 c:\windows\System32\perfc009.dat - 2006-11-02 10:33 . 2009-07-15 00:23 101988 c:\windows\System32\perfc009.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952] "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184] "Zune Launcher"="c:\program files\Zune\ZuneLauncher.exe" [2008-11-10 157312] "mxomssmenu"="c:\program files\Maxtor\OneTouch Status\maxmenumgr.exe" [2007-09-06 169264] "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2009-04-01 995528] "StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 90112] "SigmatelSysTrayApp"="c:\program files\SigmaTel\C-Major Audio\WDM\sttray.exe" [2007-05-06 405504] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKEY_LOCAL_MACHINE\software\microsoft\security center] "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{C40920AC-DB07-490B-A8E4-6DE7D7E0ACA6}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{2E869305-F402-484B-8428-8479C7F1BD45}"= c:\program files\Windows Live\Sync\WindowsLiveSync.exe:Windows Live Sync "{61B4DDB1-8E0D-44FD-AA5A-67CEB23870AE}"= c:\program files\Skype\Phone\Skype.exe:Skype "{701BE77C-A7E0-459B-8896-C8196A6C630D}"= c:\program files\Skype\Phone\Skype.exe:Skype "{1881B864-D50B-4410-A762-557DAE8B523A}"= c:\program files\Skype\Phone\Skype.exe:Skype "{B98F6DC0-8441-46D7-AFED-6C0A38AC6EB5}"= c:\program files\Skype\Phone\Skype.exe:Skype "{F0D0ED47-E81C-470F-A5C3-50B39C658885}"= c:\program files\Skype\Phone\Skype.exe:Skype R1 tmlwf;Trend Micro NDIS 6.0 Filter Driver;c:\windows\System32\drivers\tmlwf.sys [7/29/2008 12:06 PM 145424] R2 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [1/15/2008 10:28 AM 204800] R2 tmevtmgr;tmevtmgr;c:\windows\System32\drivers\tmevtmgr.sys [7/29/2008 12:06 PM 50192] R2 TmPfw;Trend Micro Personal Firewall;c:\program files\Trend Micro\Internet Security\TmPfw.exe [1/18/2009 10:34 AM 497008] R2 tmpreflt;tmpreflt;c:\windows\System32\drivers\tmpreflt.sys [3/19/2009 9:23 AM 36368] R2 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe [1/18/2009 10:34 AM 677128] R2 tmwfp;Trend Micro WFP Callout Driver;c:\windows\System32\drivers\tmwfp.sys [7/29/2008 12:06 PM 256528] [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}] "c:\windows\System32\rundll32.exe" "c:\windows\System32\iedkcs32.dll",BrandIEActiveSetup SIGNUP [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}] %SystemRoot%\system32\soundschemes.exe /AddRegistration . . ------- Supplementary Scan ------- . IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-07-14 21:27 Windows 6.0.6001 Service Pack 1 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2009-07-15 21:28 ComboFix-quarantined-files.txt 2009-07-15 01:28 Pre-Run: 149,629,210,624 bytes free Post-Run: 149,609,496,576 bytes free 135 --- E O F --- 2009-06-24 07:00
Attached File(s)
|
|
|
|
Jul 14 2009, 08:58 PM
Post
#11
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following:
Copy/paste the text inside the Codebox below into notepad: Here's how to do that: Click Start > Run type Notepad click OK. This will open an empty notepad file: Copy all the text inside of the code box - Press Ctrl+C (or right click on the highlighted section and choose 'copy') CODE Folder:: c:\users\ensign\AppData\Roaming\pridl c:\program files\WWShow c:\program files\Jcore Now paste the copied text into the open notepad - press CTRL+V (or right click and choose 'paste') Save this file to your desktop, Save this as "CFScript" Here's how to do that: 1.Click File; 2.Click Save As... Change the directory to your desktop; 3.Change the Save as type to "All Files"; 4.Type in the file name: CFScript 5.Click Save ... ![]()
CAUTION: Do not mouse-click ComboFix's window while it is running. That may cause it to stall. NEXT Download TFC to your desktop
It's normal after running TFC cleaner that the PC will be slower to boot the first time. NEXT Please download Malwarebytes' Anti-Malware
Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately. NEXT **Vista users - right click on the IE icon and run as administrator Run an on-line scan with Kaspersky Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner 1. Click Accept, when prompted to download and install the program files and database of malware definitions. 2. To optimize scanning time and produce a more sensible report for review:
3. Click Run at the Security prompt. The program will then begin downloading and installing and will also update the database. Please be patient as this can take several minutes.
In your next reply please include
|
|
|
|
Jul 15 2009, 11:07 AM
Post
#12
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
Here are the three reports
Attached File(s)
combofix_log.txt ( 11.57K )
Number of downloads: 3
Kaspersky_report.txt ( 42.83K )
Number of downloads: 22
mbam_log_2009_07_15__10_06_03_.txt ( 893bytes )
Number of downloads: 4 |
|
|
|
Jul 15 2009, 12:02 PM
Post
#13
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do the following: It appears from the Kaspersky log that the C:\Users\ensign\AppData\Local\Microsoft\Windows\WER directory is infected. Please navigate to that directory and delete it and all the files contained within it (use windows explorer (windows key +E), right click the folder > delete). (the other items found by Kaspersky are in quarantine, which we will be clearing up now) Next Visit ADOBEand download the latest version of Acrobat Reader (version 9.1) Having the latest updates ensures there are no security vulnerabilities in your system. NEXT Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
NEXT Follow these steps to uninstall Combofix
![]() NEXT Now to remove the rest of the tools that we have used in fixing your machine:
NEXT Below I have included a number of recommendations for how to protect your computer against malware infections.
**Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them. Thank you for your patience, and performing all of the procedures requested. Please respond one last time so we can consider the thread resolved and close it, thank-you. |
|
|
|
Jul 15 2009, 07:04 PM
Post
#14
|
|
|
New Member ![]() Group: Authentic Member Posts: 19 Joined: 6-January 05 Member No.: 22,271 |
I went to my C drive and can't find the exact file listed in the Kaspersky log.
I can find C:\Users\ensign and that is all. When I search my computer for the exact directory. I type in the directory just as it is shown and it comes up with ERC What am i doing wrong? I'm not exactly a computer guy. |
|
|
|
Jul 15 2009, 07:20 PM
Post
#15
|
|
![]() Classroom Administrator Assistant Group: Classroom Teacher Posts: 6,930 Joined: 18-November 04 From: Canada Member No.: 18,614 Operating System: xp sp3 |
Hi,
Please do this: Please download OTM by OldTimer.
CODE :Processes explorer.exe :Files C:\Users\ensign\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0c3a2fe1\Report.cab C:\Users\ensign\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report14750e28\Report.cab C:\Users\ensign\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report15ee4ffe\Report.cab C:\Users\ensign\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report17acd52e\Report.cab :Commands [purity] [emptytemp] [start explorer] [Reboot]
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post. |
|
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies | Topic Starter | Views | Last Action | |||
|---|---|---|---|---|---|---|---|
![]() |
0 | kt_crow | 6 | Today, 12:32 PM Last post by: kt_crow |
|||
![]() |
12 | miller2644 | 150 | Today, 12:05 PM Last post by: Tomk |
|||
![]() |
211 | AplusWebMaster | 7,834 | Today, 06:09 AM Last post by: AplusWebMaster |
|||
![]() |
16 | ciacia | 167 | Today, 05:33 AM Last post by: CatByte |
|||
|
Time is now: 21st November 2009 - 02:32 PM |