This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virusremover2009 & Renos.BAH Infection

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please go to Jotti's and click on the Browse… button at the top and navigate to the following file and then click on Submit:

C:\WINDOWS\system32\userinit.exe

When all the scans have been completed, please copy and paste the results into your next reply.

If this site is busy, try VirusTotal: Click the Browse … button, navigate to the file and double click it and then click the Send button.

You may need to set Windows to show All Hidden Files and Folders - Instructions can be found here.
* These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after you have done.
*
Scan taken on 16 Mar 2009 01:35:25 (GMT) A-Squared Found Trojan-Downloader.Win32.FraudLoad!IK AntiVir Found TR/Dldr.FraudLoad.dst ArcaVir Found nothing Avast Found Win32:Trojan-gen {Other} AVG Antivirus Found nothing BitDefender Found Trojan.Downloader.Agent.AAIB ClamAV Found nothing CPsecure Found nothing Dr.Web Found nothing F-Prot Antivirus Found nothing F-Secure Anti-Virus Found Trojan-Downloader.Win32.FraudLoad.dst Ikarus Found Trojan-Downloader.Win32.FraudLoad Kaspersky Anti-Virus Found Trojan-Downloader.Win32.FraudLoad.dst NOD32 Found Win32/TrojanDownloader.Zlob.CZG Norman Virus Control Found nothing Panda Antivirus Found nothing Quick Heal Found TrojanDownloader.FraudLoad.ds Sophos Antivirus Found Mal/EncPk-HJ VirusBuster Found Trojan.DL.FraudLoad.CMH VBA32 Found Win32.TrojanDownloader.Zlob.CZG
OK, we'll see if we can replace the infected file with a legitimate version.

Copy and paste the following into Notepad (Start > All Programs > Accessories > Notepad):

FCopy::
c:\windows\ServicePackFiles\i386\userinit.exe | c:\windows\system32\userinit.exe
c:\windows\ServicePackFiles\i386\userinit.exe | c:\windows\system32\dllcache\userinit.exe


Save it to your Desktop with the following filename: CFScript
Drag and drop CFScript.txt onto your copy of Combofix and let it do it's thing.

Let me have the log produced, as before, as well as a fresh HJT log and a description of how the PC is behaving.
Seems to run OK, I'll check it in a bit. Checked it with windows defender and found nothing. No popups, so looks good :thumbup:

ComboFix 09-03-15.01 - Gregg 2009-03-16 18:59:55.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3071.2398 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Gregg\Desktop\cfscript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated)
FW: McAfee Personal Firewall *enabled*
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

.
————— FCopy —————

c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\system32\userinit.exe
c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\system32\dllcache\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-02-17 to 2009-03-17 )))))))))))))))))))))))))))))))
.

2009-03-14 18:39 . 2009-03-14 18:39 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-03-14 18:38 . 2009-03-14 18:38 d——– c:\windows\ERUNT
2009-03-14 18:37 . 2009-03-14 19:29 d——– C:\SDFix
2009-03-12 17:15 . 2009-03-12 17:15 d——– c:\windows\Sun
2009-03-12 17:12 . 2009-03-12 17:12 d——– c:\program files\Java
2009-03-12 17:12 . 2009-03-12 17:12 73,728 –a—— c:\windows\system32\javacpl.cpl
2009-03-12 16:11 . 2009-03-12 16:11 d——– C:\rsit
2009-03-11 15:44 . 2009-03-11 15:44 d——– c:\program files\Trend Micro
2009-03-11 07:22 . 2009-03-11 07:23 d——– c:\program files\Windows Live Safety Center
2009-03-11 07:14 . 2009-03-11 07:14 d——– c:\documents and settings\Gregg\Application Data\McAfee
2009-03-11 07:13 . 2006-03-03 08:07 143,360 –a—— c:\windows\system32\dunzip32.dll
2009-03-11 07:13 . 2009-03-16 19:03 9,523 –a—— c:\windows\system32\Config.MPF
2009-03-11 07:10 . 2007-11-22 06:44 201,320 –a—— c:\windows\system32\drivers\mfehidk.sys
2009-03-11 07:10 . 2007-07-13 06:20 113,952 –a—— c:\windows\system32\drivers\Mpfp.sys
2009-03-11 07:10 . 2007-11-22 06:44 79,304 –a—— c:\windows\system32\drivers\mfeavfk.sys
2009-03-11 07:10 . 2007-12-02 12:51 40,488 –a—— c:\windows\system32\drivers\mfesmfk.sys
2009-03-11 07:10 . 2007-11-22 06:44 35,240 –a—— c:\windows\system32\drivers\mfebopk.sys
2009-03-11 07:10 . 2007-11-22 06:44 33,832 –a—— c:\windows\system32\drivers\mferkdk.sys
2009-03-11 07:09 . 2009-03-11 07:09 d——– c:\program files\McAfee.com
2009-03-11 07:09 . 2009-03-11 16:20 d——– c:\program files\McAfee
2009-03-11 07:09 . 2009-03-11 07:10 d——– c:\program files\Common Files\McAfee
2009-03-10 09:16 . 2009-03-11 08:48 d——– c:\windows\system32\ZoneLabs
2009-03-10 09:16 . 2009-03-10 09:16 d——– c:\documents and settings\All Users\Application Data\MailFrontier
2009-03-10 09:16 . 2004-04-27 04:40 11,264 –a—— c:\windows\system32\SpOrder.dll
2009-03-10 09:16 . 2009-03-10 11:58 4,212 –ah—– c:\windows\system32\zllictbl.dat
2009-03-10 09:15 . 2009-03-11 08:48 d——– c:\windows\Internet Logs
2009-03-10 08:17 . 2009-03-10 11:55 d——– c:\program files\Advanced Spyware Remover
2009-03-09 20:48 . 2008-04-13 18:12 159,232 –a—— c:\windows\system32\ptpusd.dll
2009-03-09 20:48 . 2008-04-13 12:45 15,104 –a—— c:\windows\system32\drivers\usbscan.sys
2009-03-09 20:48 . 2008-04-13 12:45 15,104 –a–c— c:\windows\system32\dllcache\usbscan.sys
2009-03-09 20:48 . 2001-08-17 22:36 5,632 –a—— c:\windows\system32\ptpusb.dll
2009-03-09 20:14 . 2009-03-09 20:14 d——– c:\program files\Windows Defender
2009-03-09 19:25 . 2009-03-09 20:30 d——– c:\program files\Lavasoft
2009-03-09 19:25 . 2009-03-09 20:30 d——– c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-09 18:14 . 2009-03-09 19:09 d-a—— c:\documents and settings\All Users\Application Data\TEMP
2009-03-08 20:09 . 2009-03-08 20:09 d——– c:\program files\Malwarebytes' Anti-Malware
2009-03-08 20:09 . 2009-03-08 20:09 d——– c:\documents and settings\Gregg\Application Data\Malwarebytes
2009-03-08 20:09 . 2009-03-08 20:09 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-08 20:09 . 2009-02-11 10:19 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-08 20:09 . 2009-02-11 10:19 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-02-25 04:05 . 2009-02-25 10:07 664 –a—— c:\windows\system32\d3d9caps.dat
2009-02-24 23:35 . 2009-01-09 14:19 1,089,593 —–c— c:\windows\system32\dllcache\ntprint.cat
2009-02-22 08:56 . 2009-02-22 08:56 d——– c:\documents and settings\All Users\Application Data\Amazon
2009-02-22 08:55 . 2009-02-22 08:55 d——– c:\windows\Downloaded Installations
2009-02-22 08:55 . 2009-02-22 08:55 d——– c:\program files\Amazon
2009-02-19 08:31 . 2009-02-19 08:31 d——– c:\program files\Acertant
2009-02-19 08:31 . 2009-02-19 08:31 d——– c:\documents and settings\Gregg\Application Data\Acertant

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-16 14:37 ——— d—–w c:\program files\Common Files\Adobe
2009-03-11 12:15 ——— d—–w c:\documents and settings\All Users\Application Data\McAfee
2009-03-10 17:01 ——— d—–w c:\program files\V CAST Music with Rhapsody
2009-02-22 13:56 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-07 00:37 ——— d—–w c:\program files\Reference Assemblies
2009-02-07 00:37 ——— d—–w c:\program files\MSBuild
2009-02-03 01:04 ——— d—–w c:\documents and settings\Gregg\Application Data\CyberLink
2009-02-03 01:01 ——— d—–w c:\program files\CyberLink
2009-02-03 01:01 ——— d—–w c:\program files\Common Files\InstallShield
2009-02-03 01:01 ——— d—–w c:\documents and settings\All Users\Application Data\CyberLink
2009-02-01 09:28 ——— d—–w c:\documents and settings\LocalService\Application Data\iolo
2009-01-30 23:09 ——— d—–w c:\documents and settings\Gregg\Application Data\BVRP Software
2009-01-30 21:15 ——— d—–w c:\program files\WinASPI
2009-01-30 21:15 ——— d—–w c:\program files\TransferMy DVD
2009-01-30 21:15 ——— d—–w c:\program files\AviSynth 2.5
2009-01-30 21:15 ——— d—–w c:\program files\Avanquest update
2009-01-30 21:13 ——— d—–w c:\documents and settings\All Users\Application Data\BVRP Software
2009-01-24 21:45 ——— d—–w c:\program files\Windows Media Connect 2
2009-01-24 20:03 ——— d—–w c:\program files\Google
2009-01-20 12:34 ——— d—–w c:\program files\activePDF
2009-01-18 03:06 ——— d—–w c:\documents and settings\Gregg\Application Data\DivX
2009-01-18 02:45 ——— d—–w c:\program files\DivX
2009-01-17 21:22 ——— d—–w c:\program files\Common Files\Real
2009-01-17 21:14 ——— d—–w c:\program files\LG Electronics
.

((((((((((((((((((((((((((((( SnapShot@2009-03-11_18.44.21.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-03-13 01:12:11 110,592 —-a-w c:\windows\assembly\GAC\ADODB\7.0.3300.0__b03f5f7f11d50a3a\adodb.dll
+ 2009-03-13 01:12:03 88,776 —-a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath.Xml\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.Xml.dll
+ 2009-03-13 01:12:03 101,064 —-a-w c:\windows\assembly\GAC\Microsoft.Office.Interop.InfoPath\11.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.InfoPath.dll
+ 2009-03-13 01:12:10 64,088 —-a-w c:\windows\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2009-03-13 01:12:11 4,096 —-a-w c:\windows\assembly\GAC\MSDATASRC\7.0.3300.0__b03f5f7f11d50a3a\msdatasrc.dll
+ 2009-03-13 01:12:10 223,800 —-a-w c:\windows\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2009-03-13 01:12:11 16,384 —-a-w c:\windows\assembly\GAC\stdole\7.0.3300.0__b03f5f7f11d50a3a\stdole.dll
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX\ERDNT.EXE
+ 2009-03-14 23:38:19 2,965,504 —-a-w c:\windows\ERUNT\SDFIX\Users\00000001\NTUSER.DAT
+ 2009-03-14 23:38:19 184,320 —-a-w c:\windows\ERUNT\SDFIX\Users\00000002\UsrClass.dat
+ 2008-08-07 20:27:04 163,328 —-a-w c:\windows\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2009-03-14 23:38:14 2,965,504 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000001\NTUSER.DAT
+ 2009-03-14 23:38:15 184,320 —-a-w c:\windows\ERUNT\SDFIX_First_Run\Users\00000002\UsrClass.dat
- 2009-01-11 03:14:23 593,920 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2009-03-13 01:12:31 593,920 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2009-01-11 03:14:23 12,288 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2009-03-13 01:12:31 12,288 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2009-01-11 03:14:23 86,016 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2009-03-13 01:12:31 86,016 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2009-01-11 03:14:23 135,168 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2009-03-13 01:12:30 135,168 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2009-01-11 03:14:23 11,264 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2009-03-13 01:12:31 11,264 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2009-01-11 03:14:23 27,136 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2009-03-13 01:12:31 27,136 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2009-01-11 03:14:23 4,096 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-03-13 01:12:31 4,096 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2009-01-11 03:14:23 794,624 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2009-03-13 01:12:31 794,624 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2009-01-11 03:14:23 249,856 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2009-03-13 01:12:30 249,856 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2009-01-11 03:14:23 61,440 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2009-03-13 01:12:30 61,440 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2009-01-11 03:14:23 23,040 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2009-03-13 01:12:31 23,040 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2009-01-11 03:14:23 286,720 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2009-03-13 01:12:30 286,720 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2009-01-11 03:14:23 409,600 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2009-03-13 01:12:30 409,600 —-a-r c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2009-03-11 21:15:28 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-03-16 23:52:01 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-03-11 21:15:28 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-16 23:52:01 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-01-26 03:04:10 410,984 —-a-w c:\windows\system32\deploytk.dll
+ 2009-03-12 22:12:14 410,984 —-a-w c:\windows\system32\deploytk.dll
+ 2009-03-12 22:12:14 144,792 —-a-w c:\windows\system32\java.exe
+ 2009-03-12 22:12:14 144,792 —-a-w c:\windows\system32\javaw.exe
+ 2009-03-12 22:12:14 148,888 —-a-w c:\windows\system32\javaws.exe
- 2009-03-11 23:20:50 72,050 —-a-w c:\windows\system32\perfc009.dat
+ 2009-03-17 00:07:18 72,050 —-a-w c:\windows\system32\perfc009.dat
- 2009-03-11 23:20:50 443,918 —-a-w c:\windows\system32\perfh009.dat
+ 2009-03-17 00:07:18 443,918 —-a-w c:\windows\system32\perfh009.dat
+ 2004-03-22 20:17:04 765,680 —-a-w c:\windows\system32\spool\drivers\w32x86\mdigraph.dll
+ 2004-03-22 20:17:10 42,224 —-a-w c:\windows\system32\spool\drivers\w32x86\mdiui.dll
.
– Snapshot reset to current date –
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-01-21 68856]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2007-10-04 8491008]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2007-11-01 582992]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-12 148888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"nwiz"="nwiz.exe" [2007-10-04 c:\windows\system32\nwiz.exe]

c:\documents and settings\Gregg\Start Menu\Programs\Startup\
Windows Explorer.lnk - c:\windows\explorer.exe [2001-08-23 1033728]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
–a—— 2007-04-20 09:03 149024 c:\program files\Common Files\Maxtor\Schedule2\schedhlp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
–a—— 2007-04-20 09:09 1945712 c:\program files\Maxtor\MaxBlast\TimounterMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
–a—— 2008-11-20 14:20 290088 c:\program files\iTunes\iTunesHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MaxBlastMonitor.exe]
–a—— 2007-04-20 08:59 1169720 c:\program files\Maxtor\MaxBlast\MaxBlastMonitor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2008-11-04 11:30 413696 c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
–a—— 2003-10-31 20:42 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
–a—— 2009-01-21 11:06 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SysTrayApp]
–a—— 2008-09-18 20:23 442470 c:\program files\IDT\wdm\sttray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TuneRanger]
–a—— 2008-09-11 10:43 946176 c:\program files\Acertant\TuneRanger\TuneRangerHelper.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Acertant\\TuneRanger\\TuneRangerHelper.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=

R2 ioloFileInfoList;iolo FileInfoList Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [2009-01-11 712048]
R2 ioloSystemService;iolo System Service;c:\program files\iolo\Common\Lib\ioloServiceManager.exe [2009-01-11 712048]
R2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
R3 NVHDA;Service for NVIDIA HDMI Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2009-01-11 26272]

— Other Services/Drivers In Memory —

*Deregistered* - mchInjDrv

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{22291fc7-e4b8-11dd-9441-001e906a7960}]
\Shell\AutoRun\command - E:\USBAutoRun.exe
.
Contents of the 'Scheduled Tasks' folder

2009-03-10 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe []

2009-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-03-11 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]

2009-03-17 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 19:20]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-combofix - c:\windows\system32\CF5588.exe


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://news.yahoo.com/i/964
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver; - c:\windows\system32\GPhotos.scr/200
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: internet
Trusted Zone: mcafee.com
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-03-16 19:12:39
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'lsass.exe'(800)
c:\windows\system32\relog_ap.dll
.
———————— Other Running Processes ————————
.
c:\program files\IDT\5902XP_6033V_012208\WDM\stacsv.exe
c:\program files\Common Files\Maxtor\Schedule2\schedul2.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\progra~1\COMMON~1\McAfee\MNA\McNASvc.exe
c:\progra~1\COMMON~1\McAfee\McProxy\McProxy.exe
c:\progra~1\McAfee\VIRUSS~1\Mcshield.exe
c:\program files\McAfee\MPF\MpfSrv.exe
c:\windows\system32\nvsvc32.exe
c:\progra~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2009-03-16 19:14:19 - machine was rebooted [Gregg]
ComboFix-quarantined-files.txt 2009-03-17 00:14:15
ComboFix2.txt 2009-03-11 23:45:07

Pre-Run: 177,627,029,504 bytes free
Post-Run: 177,819,123,712 bytes free

265 — E O F — 2009-03-13 23:45:39


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:19:13, on 3/16/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\idt\5902xp_6033v_012208\wdm\STacSV.exe
C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iolo\common\lib\ioloServiceManager.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.yahoo.com/i/964
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google; Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - Startup: Windows Explorer.lnk = C:\WINDOWS\explorer.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6662.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1231643705906
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD7/JSCDL/jdk…ows-i586-jc.cab
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Maxtor\Schedule2\schedul2.exe
O23 - Service: Amazon Unbox Video Service (ADVService) - Amazon.com - C:\Program Files\Amazon\Amazon Unbox Video\ADVWindowsClientService.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iolo System Service (ioloSystemService) - Unknown owner - C:\Program Files\iolo\common\lib\ioloServiceManager.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Audio Service (STacSV) - IDT, Inc. - c:\program files\idt\5902xp_6033v_012208\wdm\STacSV.exe

–
End of file - 7509 bytes
I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Go to Start > Run, enter the following into the textbox and click OK: combofix /u
This will uninstall Combofix and do a little housework besides.

Create a new Restore Point - this will give a clean one should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI