This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virut 32? Terrified to use web.

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi CatByte,

Scan completed 8 hours…… :woot:

To answer your initial questions:

I am afraid I didn't save the log from the original Dr Web scan and I am not entirely sure where I got the idea of Virut from, I do remember AVG reported SHeur but I am unsure about virut. I seem to recall something like xxxxxx.Win32.i56 but cannot be sure if this was what came up in a search when I Googled SHeur.

Sorry for not being more specific but I was panicking at the time.

Anyway here are the logs:

ComboFix

ComboFix 09-04-01.01 - Administrator 2009-04-03 4:54:31.3 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1118 [GMT 1:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Administrator\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated)
* Created a new restore point

FILE ::
c:\windows\system32\30.tmp
c:\windows\system32\31.tmp
c:\windows\system32\32.tmp
c:\windows\system32\3B.tmp
c:\windows\system32\pqicgjmb.dll
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\30.tmp
c:\windows\system32\31.tmp
c:\windows\system32\32.tmp
c:\windows\system32\3B.tmp

c:\windows\explorer.exe . . . is infected!!

.
————— FCopy —————

c:\windows\ServicePackFiles\i386\explorer.exe –> c:\windows\explorer.exe
c:\windows\ServicePackFiles\i386\ctfmon.exe –> c:\windows\system32\ctfmon.exe
c:\windows\ServicePackFiles\i386\userinit.exe –> c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((( Files Created from 2009-03-03 to 2009-04-03 )))))))))))))))))))))))))))))))
.

2009-04-02 17:23 . 2009-04-02 17:23 578,560 –a–c— c:\windows\system32\dllcache\user32.dll
2009-04-02 17:20 . 2009-04-02 17:21 d——– c:\windows\ERUNT
2009-04-02 17:15 . 2009-04-02 17:49 d——– C:\SDFix
2009-04-02 09:40 . 2009-04-02 09:40 d——– c:\program files\Trend Micro
2009-04-02 08:49 . 2009-04-02 08:49 d——– c:\program files\ERUNT
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\program files\Malwarebytes' Anti-Malware
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-02 08:30 . 2009-04-02 08:30 d——– c:\documents and settings\Administrator\Application Data\Malwarebytes
2009-04-02 08:30 . 2009-03-26 16:49 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-02 08:30 . 2009-03-26 16:49 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2009-04-02 07:42 . 2008-07-12 08:18 3,851,784 –a—— c:\windows\system32\D3DX9_39.dll
2009-04-02 07:42 . 2008-07-12 08:18 1,493,528 –a—— c:\windows\system32\D3DCompiler_39.dll
2009-04-02 07:42 . 2008-07-12 08:18 467,984 –a—— c:\windows\system32\d3dx10_39.dll
2009-04-02 07:41 . 2009-04-02 07:41 d——– c:\program files\PerformanceTest
2009-04-02 07:41 . 2009-04-02 07:41 d——– c:\documents and settings\All Users\Application Data\PassMark
2009-04-01 12:05 . 2009-04-01 12:05 d——– C:\Oscar
2009-03-30 11:46 . 2009-03-30 11:57 d——– c:\windows\SxsCaPendDel
2009-03-30 11:46 . 2009-03-30 11:46 d——– C:\45bb6b287e696ff21d8f8dae445d
2009-03-30 11:41 . 2008-06-17 20:02 8,461,312 —–c— c:\windows\system32\dllcache\shell32.dll
2009-03-30 11:41 . 2008-12-05 07:54 144,896 —–c— c:\windows\system32\dllcache\schannel.dll
2009-03-30 11:35 . 2008-06-20 12:51 361,600 —–c— c:\windows\system32\dllcache\tcpip.sys
2009-03-30 11:35 . 2008-06-20 18:46 245,248 —–c— c:\windows\system32\dllcache\mswsock.dll
2009-03-30 11:35 . 2008-06-20 12:08 225,856 —–c— c:\windows\system32\dllcache\tcpip6.sys
2009-03-30 11:35 . 2008-06-20 18:46 147,968 —–c— c:\windows\system32\dllcache\dnsapi.dll
2009-03-30 11:28 . 2009-03-30 11:28 d——– c:\program files\Sun
2009-03-30 11:28 . 2009-03-30 11:27 410,984 –a—— c:\windows\system32\deploytk.dll
2009-03-30 11:22 . 2009-03-30 11:25 d——– c:\documents and settings\Administrator\.SunDownloadManager
2009-03-28 12:04 . 2009-02-25 16:15 593,920 ——— c:\windows\system32\ati2sgag.exe
2009-03-26 20:40 . 2009-03-28 08:05 d——– c:\documents and settings\Administrator\DoctorWeb
2009-03-24 21:55 . 2009-03-24 21:57 d——– c:\program files\Nexus Radio
2009-03-24 20:15 . 2009-03-24 20:15 d——– c:\windows\Replay Media Catcher
2009-03-24 20:15 . 2009-03-30 09:23 d——– c:\program files\Replay Media Catcher
2009-03-24 20:15 . 2009-03-30 08:58 323,584 –a—— c:\windows\system32\AUDIOGENIE2.DLL
2009-03-24 20:15 . 2009-03-30 08:58 237,568 –a—— c:\windows\system32\rmc_rtspdl.dll
2009-03-24 20:15 . 2009-03-30 08:58 156,672 –a—— c:\windows\system32\rmc_fixasf.exe
2009-03-24 19:44 . 2009-03-24 19:44 d——– c:\program files\Philips
2009-03-06 21:49 . 2009-03-06 21:49 d——– c:\documents and settings\Administrator\Application Data\Stellarium
2009-03-06 21:48 . 2009-03-06 21:49 d——– c:\program files\Stellarium

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-02 19:18 ——— d—–w c:\documents and settings\All Users\Application Data\TrackMania
2009-04-02 19:12 ——— d—–w c:\program files\Steam
2009-03-30 10:51 ——— d—–w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-30 10:27 ——— d—–w c:\program files\Java
2009-03-30 08:53 ——— d—–w c:\documents and settings\Administrator\Application Data\Spotify
2009-03-30 08:49 ——— d—–w c:\program files\Spotify
2009-03-28 08:50 ——— d—–w c:\program files\mIRC
2009-03-28 08:00 966,656 —-a-w c:\windows\UNRecode.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroVision.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroShowTime.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroMediaHome.exe
2009-03-28 08:00 966,656 —-a-w c:\windows\UNNeroBackItUp.exe
2009-03-28 08:00 283,648 —-a-w c:\windows\winhlp32.exe
2009-03-26 19:43 1,052,672 —-a-w c:\windows\explorer.exe
2009-03-26 18:07 ——— d—–w c:\documents and settings\All Users\Application Data\avg8
2009-03-26 18:06 325,128 —-a-w c:\windows\system32\drivers\avgldx86.sys
2009-03-24 20:49 ——— d—–w c:\documents and settings\Administrator\Application Data\NCH Swift Sound
2009-03-24 20:48 ——— d—–w c:\program files\NCH Software
2009-03-24 18:44 ——— d–h–w c:\program files\InstallShield Installation Information
2009-02-25 22:58 3,565,568 —-a-w c:\windows\system32\drivers\ati2mtag.sys
2009-02-25 20:37 53,248 —-a-w c:\windows\system32\drivers\ati2erec.dll
2009-02-22 09:50 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Swift Sound
2009-02-22 09:43 27,136 —-a-w c:\windows\system32\drivers\nchssvad.sys
2009-02-22 09:43 ——— d—–w c:\documents and settings\All Users\Application Data\NCH Software
2009-02-14 13:19 ——— d—–w c:\program files\AMD
2009-02-14 12:27 ——— d—–w c:\program files\TRUST 640U SILVERLINE HEADSET USB
2009-02-06 17:09 ——— d—–w c:\program files\Audio Recorder
2008-04-27 09:41 774,144 —-a-w c:\program files\RngInterstitial.dll
.

——- Sigcheck ——-

2009-03-26 20:43 1052672 c0e3ad1446ee377b603a767a551af1bf c:\windows\explorer.exe
2009-03-28 09:03 1033216 1dd6b3b2ac20843fa043009969ad62d3 c:\windows\$NtServicePackUninstall$\explorer.exe
2009-03-28 09:11 1033728 76afe06854aad9fb48834da6cdc44b42 c:\windows\$NtUninstallKB938828$\explorer.exe
2009-03-28 09:27 1033728 799770b46fa0a806a7a0f52e1a85e887 c:\windows\ServicePackFiles\i386\explorer.exe

2009-03-28 09:03 15360 edf00d5b9133d927adf802b1f7d7c259 c:\windows\$NtServicePackUninstall$\ctfmon.exe
2009-03-28 09:27 15360 6d550f617e0ab3629734c7363dcae628 c:\windows\ServicePackFiles\i386\ctfmon.exe
2009-03-28 09:27 15360 6d550f617e0ab3629734c7363dcae628 c:\windows\system32\ctfmon.exe

2009-03-28 09:09 25088 3ee9d7262239565fea14558f2cf81d68 c:\windows\$NtServicePackUninstall$\userinit.exe
2009-03-28 09:35 26624 1ff2ee91dd1b1bda034e56a03e633cef c:\windows\ServicePackFiles\i386\userinit.exe
2009-03-28 09:35 26624 1ff2ee91dd1b1bda034e56a03e633cef c:\windows\system32\userinit.exe
.
((((((((((((((((((((((((((((( SnapShot_2009-04-02_17.57.52.46 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-04-03 03:58:34 16,384 —-atw c:\windows\temp\Perflib_Perfdata_270.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2009-03-28 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-26 1601304]
"TI WLAN"="c:\program files\Wireless LAN Utility\TIWLANCu.exe" [2009-03-26 1171456]
"WheelMouse"="c:\advanced wheel mouse\wh_exec.exe" [2009-03-26 98304]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"amd_dc_opt"="c:\program files\AMD\Dual-Core Optimizer\amd_dc_opt.exe" [2009-03-26 77824]
"VTTimer"="VTTimer.exe" [2009-03-26 c:\windows\system32\VTTimer.exe]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2007-02-05 294400]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-03-26 19:06 10520 c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Steam\\steamapps\\calibrator67\\half-life 2 deathmatch\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\calibrator67\\counter-strike\\hl.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
"c:\\Program Files\\TmNationsForever\\TmForever.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2008-07-19 325128]
R1 eusk2par;EUTRON SmartKey Parallel Driver;c:\windows\system32\drivers\eusk2par.sys [2008-03-21 24786]
R2 avg8wd;avg8wd;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-07-19 298264]
R3 TNET1130;802.11 WLAN;c:\windows\system32\drivers\TNET1130.sys [2008-08-17 438912]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2007-07-20 84992]
S3 eusk3usb;SmartKey 3 USB;c:\windows\system32\drivers\eusk3usb.sys [2008-03-21 45534]
.
Contents of the 'Scheduled Tasks' folder

2009-03-30 c:\windows\Tasks\Uniblue SpeedUpMyPC Nag.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []

2007-07-09 c:\windows\Tasks\Uniblue SpeedUpMyPC.job
- c:\program files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe []
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.google.co.uk/
uInternet Settings,ProxyOverride =
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cgr16zu7.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie;=UTF-8&oe;=UTF-8&q;=
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk
FF - plugin: c:\program files\Mozilla Firefox\plugins\npyaxmpb.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-03 04:58:55
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-343818398-484763869-725345543-500\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(876)
c:\windows\system32\Ati2evxx.dll
.
———————— Other Running Processes ————————
.
c:\documents and settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Wireless LAN Utility\tiwlnsvc.exe
c:\windows\system32\searchindexer.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-04-03 5:02:05 - machine was rebooted
ComboFix-quarantined-files.txt 2009-04-03 04:02:03
ComboFix2.txt 2009-04-02 16:59:05
ComboFix3.txt 2009-03-30 09:34:12

Pre-Run: 277,698,134,016 bytes free
Post-Run: 277,702,606,848 bytes free

199

Kaspersky

Scanned: 837161
Detected: 19
Untreated: 0
Start time: 03/04/2009 05:23:16
Duration: 07:54:29
Finish time: 03/04/2009 13:17:45


Detected
——–
Status Object
—— ——
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\30.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\31.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\3B.tmp.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\Qoobox\Quarantine\C\WINDOWS\system32\7.tmp.vir
deleted: Trojan program Trojan.Win32.VB.mnr File: C:\Qoobox\Quarantine\C\WINDOWS\system32\dxonool32.sys.vir
deleted: Trojan program Trojan-Downloader.Win32.Agent.bpew File: C:\Qoobox\Quarantine\C\WINDOWS\system32\tpszxyd.sys.vir
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/10.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/11.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/12.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/15.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/16.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/17.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/18.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/1A.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/1B.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/24.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/25.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/2C.tmp
deleted: Trojan program Packed.Win32.Krap.i File: C:\SDFix\backups\backups.zip/backups/2D.tmp

HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:26:45, on 03/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\VTTimer.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Wireless LAN Utility\TIWLANCu.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Wireless LAN Utility\tiwlnsvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\SearchProtocolHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [TI WLAN] C:\Program Files\Wireless LAN Utility\TIWLANCu.exe
O4 - HKLM\..\Run: [WheelMouse] C:\Advanced Wheel Mouse\wh_exec.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/betapit/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupd…b?1229158219187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1229160138828
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/optimize2/pcpitstop2.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\Skype4COM.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avg8wd - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\Wireless LAN Utility\tiwlnsvc.exe

–
End of file - 6349 bytes

Shaun
Hi

I tried to copy uninfected copies of your explorer.exe
as well as the other two files, but it didn't work as combofix is still reporting

c:\windows\explorer.exe . . . is infected!!


This means that you still have the file infector inside your core system files.

I am very sorry, but this cannot be cleaned.

The reason the scans are coming up clean is because Dr. Web has cleaned it out enough not to show anything in the scans
BUT the file infector is still there and WILL re spawn and you will be infected all over again.

Personally I wouldn't trust this machine again if it were mine…..

take this opportunity while you can to copy your documents pictures and music - nothing else..then reinstall your OS
Hi CatByte, You can't win them all, I was hoping all was going to be OK. Anyways thanks for all your help, now if only Microsoft will send me an installation disc..or is it time for Vista? Cheers Shaun
Hi CatByte, You can't win them all, I was hoping all was going to be OK. Anyways thanks for all your help, now if only Microsoft will send me an installation disc..or is it time for Vista? Cheers Shaun
I'm holding out for Windows 7 myself…. they'll probably send you XP no charge…I'm sorry this didn't have a successful outcome, but when DR. Web finds that many files its a true indicator a file infector is there and combofix kept confirming it. I hope everything works out for you Good Luck CB
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI