islandbitpusher
Topic Starter
Hi I saw a similar post about this threat on this site. The Trojan.Flush.M which has been updated and released back into the wild has taken hold of my bosses computer and I have been put in charge of getting rid of it. I have done a lot of searching on forums and found little information on how to actually remove this threat. Most removal programs either lock up while scanning, because they are blocked or they don't find the threat at all (that is if they even run). In the other topic the guy who was infected stated that he just reformatted his HD and did a fresh install of windows XP. I on the other hand would like to avoid this at almost any cost and the computer is running VISTA. Norton offered to remove it for $99.99, but I think that it should never have made it past Norton in the first place. I understand that these things can happen but if you pay for protection then the removal of something that makes it past that protection should be done at no cost. I am very dissapointed in Norton, but then again I always have been. Anyhow I had taken the advice given to the user of the XP computer in the other forum topic, and ran combofix. It states that it found a root kit and removed these two files from the computer.
1. Windows\system32\drivers\gxvxcfkxcvvqbivbvsfrydoeqythwftyqmbpu.sys
2. Windows\system32\gxvxcyymcxpxgsowepqehyueopptqyatfqehh.dll
Upon restarting the computer I tried to access a web site in both IE and Firefox. It seems that something has happened to my DNS configuration.
The following is the contents of combofix.txt:
ComboFix 09-05-07.01 - jason 05/07/2009 14:17.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3325.2718 [GMT -3:00]
Running from: F:\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\gxvxcfkxcvvqbivbvsfrydoeqythwftyqmbpu.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcyymcxpxgsowepqehyueopptqyatfqehh.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_GXVXCSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-04-07 to 2009-05-07 )))))))))))))))))))))))))))))))
.
2009-05-07 14:11 . 2009-05-07 15:31 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-07 14:11 . 2009-05-07 14:11 ——– d—–w c:\users\jason\AppData\Roaming\SUPERAntiSpyware.com
2009-05-07 14:10 . 2009-05-07 14:10 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-07 13:33 . 2009-05-07 14:01 ——– d—–w c:\program files\a-squared Free
2009-05-06 18:38 . 2009-05-06 18:36 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-06 18:36 . 2009-05-06 18:35 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-04 19:28 . 2009-05-05 16:25 ——– d—–w c:\windows\BDOSCAN8
2009-05-04 14:55 . 2009-05-07 16:05 ——– d—–w c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-04 14:55 . 2009-05-07 16:05 ——– d—–w c:\users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-04 14:55 . 2009-05-04 14:55 ——– d—–w c:\users\jason\AppData\Local\Downloaded Installations
2009-05-04 14:54 . 2009-05-07 16:06 ——– d—–w c:\program files\Symantec
2009-05-04 14:41 . 2009-05-04 14:41 ——– d—–w c:\programdata\PCSettings
2009-05-04 14:41 . 2009-05-04 14:41 ——– d—–w c:\users\All Users\PCSettings
2009-05-04 14:40 . 2009-05-07 16:06 ——– d—–w c:\programdata\Norton
2009-05-04 14:40 . 2009-05-07 16:06 ——– d—–w c:\users\All Users\Norton
2009-05-04 14:40 . 2009-05-07 15:45 ——– d—–w c:\programdata\NortonInstaller
2009-05-04 14:40 . 2009-05-07 15:45 ——– d—–w c:\users\All Users\NortonInstaller
2009-05-04 14:38 . 2009-05-07 15:47 ——– d—–w c:\users\jason\AppData\Roaming\GetRightToGo
2009-04-30 18:25 . 2009-05-01 18:29 ——– d—–w c:\users\jason\.housecall6.6
2009-04-30 18:17 . 2009-05-07 17:14 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-30 12:10 . 2009-05-07 16:21 ——– d—–w c:\programdata\Spybot - Search & Destroy
2009-04-30 12:10 . 2009-05-07 16:21 ——– d—–w c:\users\All Users\Spybot - Search & Destroy
2009-04-24 18:50 . 2009-04-24 18:50 ——– d—–w c:\users\jason\AppData\Roaming\Sierra Wireless
2009-04-24 18:50 . 2009-04-24 18:50 ——– d—–w c:\program files\Sierra Wireless
2009-04-24 18:50 . 2009-04-24 18:50 ——– d—–w c:\program files\Sierra Wireless Inc
2009-04-24 14:56 . 2008-10-17 22:22 16896 —-a-w c:\windows\system32\drivers\VirtualAudio.sys
2009-04-24 14:52 . 2009-04-24 14:52 ——– d—–w c:\users\jason\AppData\Roaming\AVS4YOU
2009-04-24 14:52 . 2009-04-24 14:52 ——– d—–w c:\programdata\AVS4YOU
2009-04-24 14:52 . 2009-04-24 14:52 ——– d—–w c:\users\All Users\AVS4YOU
2009-04-24 14:51 . 2009-04-24 14:56 ——– d—–w c:\program files\Common Files\AVSMedia
2009-04-24 14:51 . 2009-01-28 23:49 974848 —-a-w c:\windows\system32\mfc70.dll
2009-04-24 14:51 . 2009-01-28 23:49 487424 —-a-w c:\windows\system32\msvcp70.dll
2009-04-24 14:51 . 2009-01-28 23:49 344064 —-a-w c:\windows\system32\msvcr70.dll
2009-04-24 14:51 . 2009-04-24 14:56 ——– d—–w c:\program files\AVS4YOU
2009-04-24 14:40 . 2009-04-24 14:40 ——– d—–w c:\program files\Search Settings
2009-04-24 14:40 . 2009-04-24 14:40 ——– d—–w c:\program files\Dealio Toolbar
2009-04-24 14:30 . 2009-04-24 14:30 ——– d—–w c:\users\jason\AppData\Local\Video Converter
2009-04-24 14:30 . 2009-04-24 14:46 ——– d—–w c:\program files\Free Video Converter
2009-04-24 14:30 . 2009-04-24 14:30 ——– d—–w c:\programdata\VideoConverter
2009-04-24 14:30 . 2009-04-24 14:30 ——– d—–w c:\users\All Users\VideoConverter
2009-04-24 14:26 . 2009-04-24 14:28 ——– d—–w c:\users\jason\AppData\Local\Extensions
2009-04-24 14:25 . 2008-10-21 15:58 6569984 —-a-w c:\windows\system32\toolkitpro1202vc80.dll
2009-04-24 14:25 . 2001-07-31 01:40 24576 —-a-w c:\windows\system32\msxml3a.dll
2009-04-24 14:25 . 2009-04-24 14:28 ——– d—–w c:\programdata\Extensions
2009-04-24 14:25 . 2009-04-24 14:28 ——– d—–w c:\users\All Users\Extensions
2009-04-24 14:22 . 2009-04-24 14:24 ——– d—–w c:\users\jason\AppData\Roaming\Any Video Converter
2009-04-24 14:22 . 2009-04-24 14:24 ——– d—–w c:\program files\Any Video Converter
2009-04-24 13:21 . 2009-04-24 14:44 ——– d—–w c:\users\jason\Movies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 17:14 . 2008-07-02 17:58 12 —-a-w c:\windows\bthservsdp.dat
2009-05-07 16:29 . 2009-01-10 20:33 256 —-a-w c:\windows\system32\pool.bin
2009-05-07 16:06 . 2008-07-02 18:59 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-07 16:06 . 2006-11-02 10:25 86016 —-a-w c:\windows\inf\infstor.dat
2009-05-07 16:06 . 2006-11-02 10:25 51200 —-a-w c:\windows\inf\infpub.dat
2009-05-07 16:06 . 2006-11-02 10:25 143360 —-a-w c:\windows\inf\infstrng.dat
2009-05-07 12:26 . 2008-07-02 17:39 1356 —-a-w c:\users\jason\AppData\Local\d3d9caps.dat
2009-05-04 13:07 . 2009-05-04 13:07 ——– d—–w c:\program files\Lavasoft
2009-05-04 12:24 . 2009-05-04 12:24 ——– d—–w c:\program files\Bazooka Scanner
2009-05-01 14:21 . 2009-05-01 14:02 ——– d—–w c:\program files\PCPitstop
2009-04-30 18:25 . 2009-05-01 16:12 102664 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-24 18:48 . 2008-07-10 16:04 ——– d—–w c:\program files\Java
2009-04-17 12:33 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-14 19:36 . 2009-01-10 20:24 ——– d—–w c:\program files\Common Files\Research In Motion
2009-04-03 13:28 . 2008-07-03 13:42 ——– d—–w c:\program files\Common Files\Adobe
2009-03-25 15:18 . 2009-03-25 15:17 ——– d—–w c:\program files\IRISCard 4 Mini
2009-03-17 03:38 . 2009-04-16 15:25 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 15:25 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-12 16:59 . 2009-03-12 16:59 ——– d—–w c:\program files\Gimp-2.0
2009-03-09 08:19 . 2008-12-31 19:06 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-03 04:46 . 2009-04-16 15:25 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 15:25 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-16 15:25 827392 —-a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-16 15:25 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 15:25 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 15:25 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 15:25 78336 —-a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-16 15:25 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 15:25 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-16 15:25 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 15:25 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 15:25 17408 —-a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-16 15:25 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-02-13 08:49 . 2009-04-16 15:25 72704 —-a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-16 15:25 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 10:32 2033152 —-a-w c:\windows\system32\win32k.sys
2008-08-12 12:58 . 2006-11-02 12:49 174 –sha-w c:\program files\desktop.ini
2009-04-01 01:47 . 2009-05-01 16:42 324976 —-a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-02-21 19:50 . 2007-02-21 19:50 8192 –sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
2009-04-09 23:09 688128 —-a-w c:\program files\Dealio Toolbar\DealioToolbarIE.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
2009-04-09 23:10 1091584 —-a-w c:\program files\Search Settings\kb128\SearchSettings.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}"= "c:\program files\Dealio Toolbar\DealioToolbarIE.dll" [2009-04-09 688128]
[HKEY_CLASSES_ROOT\clsid\{01398b87-61af-4ffb-9ab5-1a1c5fb39a9c}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"GoToMeeting"="c:\program files\Citrix\GoToMeeting\320\g2mstart.exe" [2008-07-07 31552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2008-11-03 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2009-04-09 970240]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-08-26 236016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-23 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-23 13535776]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"DellNSCST_GRNCH"="c:\program files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" [2006-12-05 278528]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-03-26 615696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-06 516440]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" - c:\windows\System32\HCIMNTR.DLL [2006-12-07 9728]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-13 715568]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2009-3-25 1545488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\eudora\EuShlExt.dll" [2006-08-17 86016]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\beep.sys]
@="beep"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D3FF4B8E-7429-4EEF-B8CD-34526BFB72C4}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BE54B738-574B-4C1D-BB74-01EDEEBD5D25}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{AC4CC041-820F-41D2-AB7F-76A6611EFAD7}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{3DA35D26-69BC-4D3D-8E79-DEDDB04BBE70}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{C01FBC51-5491-4D5D-B795-778FA42EA2D1}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{6DABC2E6-3C62-46D6-8DF5-FEECE3341F6E}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{41B6C620-1C99-4144-A7A6-99AA8A102B54}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{623AA82D-A229-4146-8293-D4D5ACD3A3BF}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{EE5B3947-097B-450F-9F14-325B47BCDC40}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{00160BC3-7D72-4586-B445-FD3A6B02A363}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8D35E423-DF3E-49A8-8771-219CD6D6F693}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
""=
"c:\\Program Files\\Sierra Wireless Inc\\Watcher\\SwiApiMux.exe"= c:\program files\Sierra Wireless Inc\Watcher\SwiApiMux.exe:*:Enabled:SwiApiMux
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [5/6/2009 3:36 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 4:06 PM 953168]
R2 SSPORT;SSPORT;c:\windows\System32\drivers\ssport.sys [9/4/2008 12:25 PM 5120]
R3 wsvad_driver;WS Audio Device;c:\windows\System32\drivers\VirtualAudio.sys [4/24/2009 11:56 AM 16896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{483322a8-e337-11dd-8f9a-001e4ce720b1}]
\shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5dd7d30b-1eb6-11de-9440-001e4ce720b1}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb8bb989-f1fb-11dd-bc67-001e4ce720b1}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-05-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:35]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AirCardEnabler - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} - hxxp://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\users\jason\AppData\Roaming\Mozilla\Firefox\Profiles\0hbx6tml.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=
FF - component: c:\program files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\DealioToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\SearchSettingsFF.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-07 14:20
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-05-07 14:22
ComboFix-quarantined-files.txt 2009-05-07 17:21
Pre-Run: 374,129,356,800 bytes free
Post-Run: 374,116,933,632 bytes free
236 — E O F — 2009-05-07 13:00
****************************************************
Small update on my status
After taking a few moments to post this topic I went back to said computer and it does seem to be connecting to the internet at the moment. I am currently re-installing norton. Will update when I have found conclusive evidence that Flush.M is either removed or still active.
1. Windows\system32\drivers\gxvxcfkxcvvqbivbvsfrydoeqythwftyqmbpu.sys
2. Windows\system32\gxvxcyymcxpxgsowepqehyueopptqyatfqehh.dll
Upon restarting the computer I tried to access a web site in both IE and Firefox. It seems that something has happened to my DNS configuration.
The following is the contents of combofix.txt:
ComboFix 09-05-07.01 - jason 05/07/2009 14:17.1 - NTFSx86
Microsoft® Windows Vista™ Ultimate 6.0.6001.1.1252.1.1033.18.3325.2718 [GMT -3:00]
Running from: F:\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\system32\drivers\gxvxcfkxcvvqbivbvsfrydoeqythwftyqmbpu.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcyymcxpxgsowepqehyueopptqyatfqehh.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_GXVXCSERV.SYS
((((((((((((((((((((((((( Files Created from 2009-04-07 to 2009-05-07 )))))))))))))))))))))))))))))))
.
2009-05-07 14:11 . 2009-05-07 15:31 ——– d—–w c:\program files\SUPERAntiSpyware
2009-05-07 14:11 . 2009-05-07 14:11 ——– d—–w c:\users\jason\AppData\Roaming\SUPERAntiSpyware.com
2009-05-07 14:10 . 2009-05-07 14:10 ——– d—–w c:\program files\Common Files\Wise Installation Wizard
2009-05-07 13:33 . 2009-05-07 14:01 ——– d—–w c:\program files\a-squared Free
2009-05-06 18:38 . 2009-05-06 18:36 15688 —-a-w c:\windows\system32\lsdelete.exe
2009-05-06 18:36 . 2009-05-06 18:35 64160 —-a-w c:\windows\system32\drivers\Lbd.sys
2009-05-04 19:28 . 2009-05-05 16:25 ——– d—–w c:\windows\BDOSCAN8
2009-05-04 14:55 . 2009-05-07 16:05 ——– d—–w c:\programdata\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-04 14:55 . 2009-05-07 16:05 ——– d—–w c:\users\All Users\{7B6BA59A-FB0E-4499-8536-A7420338BF3B}
2009-05-04 14:55 . 2009-05-04 14:55 ——– d—–w c:\users\jason\AppData\Local\Downloaded Installations
2009-05-04 14:54 . 2009-05-07 16:06 ——– d—–w c:\program files\Symantec
2009-05-04 14:41 . 2009-05-04 14:41 ——– d—–w c:\programdata\PCSettings
2009-05-04 14:41 . 2009-05-04 14:41 ——– d—–w c:\users\All Users\PCSettings
2009-05-04 14:40 . 2009-05-07 16:06 ——– d—–w c:\programdata\Norton
2009-05-04 14:40 . 2009-05-07 16:06 ——– d—–w c:\users\All Users\Norton
2009-05-04 14:40 . 2009-05-07 15:45 ——– d—–w c:\programdata\NortonInstaller
2009-05-04 14:40 . 2009-05-07 15:45 ——– d—–w c:\users\All Users\NortonInstaller
2009-05-04 14:38 . 2009-05-07 15:47 ——– d—–w c:\users\jason\AppData\Roaming\GetRightToGo
2009-04-30 18:25 . 2009-05-01 18:29 ——– d—–w c:\users\jason\.housecall6.6
2009-04-30 18:17 . 2009-05-07 17:14 ——– d—–w c:\program files\Spybot - Search & Destroy
2009-04-30 12:10 . 2009-05-07 16:21 ——– d—–w c:\programdata\Spybot - Search & Destroy
2009-04-30 12:10 . 2009-05-07 16:21 ——– d—–w c:\users\All Users\Spybot - Search & Destroy
2009-04-24 18:50 . 2009-04-24 18:50 ——– d—–w c:\users\jason\AppData\Roaming\Sierra Wireless
2009-04-24 18:50 . 2009-04-24 18:50 ——– d—–w c:\program files\Sierra Wireless
2009-04-24 18:50 . 2009-04-24 18:50 ——– d—–w c:\program files\Sierra Wireless Inc
2009-04-24 14:56 . 2008-10-17 22:22 16896 —-a-w c:\windows\system32\drivers\VirtualAudio.sys
2009-04-24 14:52 . 2009-04-24 14:52 ——– d—–w c:\users\jason\AppData\Roaming\AVS4YOU
2009-04-24 14:52 . 2009-04-24 14:52 ——– d—–w c:\programdata\AVS4YOU
2009-04-24 14:52 . 2009-04-24 14:52 ——– d—–w c:\users\All Users\AVS4YOU
2009-04-24 14:51 . 2009-04-24 14:56 ——– d—–w c:\program files\Common Files\AVSMedia
2009-04-24 14:51 . 2009-01-28 23:49 974848 —-a-w c:\windows\system32\mfc70.dll
2009-04-24 14:51 . 2009-01-28 23:49 487424 —-a-w c:\windows\system32\msvcp70.dll
2009-04-24 14:51 . 2009-01-28 23:49 344064 —-a-w c:\windows\system32\msvcr70.dll
2009-04-24 14:51 . 2009-04-24 14:56 ——– d—–w c:\program files\AVS4YOU
2009-04-24 14:40 . 2009-04-24 14:40 ——– d—–w c:\program files\Search Settings
2009-04-24 14:40 . 2009-04-24 14:40 ——– d—–w c:\program files\Dealio Toolbar
2009-04-24 14:30 . 2009-04-24 14:30 ——– d—–w c:\users\jason\AppData\Local\Video Converter
2009-04-24 14:30 . 2009-04-24 14:46 ——– d—–w c:\program files\Free Video Converter
2009-04-24 14:30 . 2009-04-24 14:30 ——– d—–w c:\programdata\VideoConverter
2009-04-24 14:30 . 2009-04-24 14:30 ——– d—–w c:\users\All Users\VideoConverter
2009-04-24 14:26 . 2009-04-24 14:28 ——– d—–w c:\users\jason\AppData\Local\Extensions
2009-04-24 14:25 . 2008-10-21 15:58 6569984 —-a-w c:\windows\system32\toolkitpro1202vc80.dll
2009-04-24 14:25 . 2001-07-31 01:40 24576 —-a-w c:\windows\system32\msxml3a.dll
2009-04-24 14:25 . 2009-04-24 14:28 ——– d—–w c:\programdata\Extensions
2009-04-24 14:25 . 2009-04-24 14:28 ——– d—–w c:\users\All Users\Extensions
2009-04-24 14:22 . 2009-04-24 14:24 ——– d—–w c:\users\jason\AppData\Roaming\Any Video Converter
2009-04-24 14:22 . 2009-04-24 14:24 ——– d—–w c:\program files\Any Video Converter
2009-04-24 13:21 . 2009-04-24 14:44 ——– d—–w c:\users\jason\Movies
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-07 17:14 . 2008-07-02 17:58 12 —-a-w c:\windows\bthservsdp.dat
2009-05-07 16:29 . 2009-01-10 20:33 256 —-a-w c:\windows\system32\pool.bin
2009-05-07 16:06 . 2008-07-02 18:59 ——– d—–w c:\program files\Common Files\Symantec Shared
2009-05-07 16:06 . 2006-11-02 10:25 86016 —-a-w c:\windows\inf\infstor.dat
2009-05-07 16:06 . 2006-11-02 10:25 51200 —-a-w c:\windows\inf\infpub.dat
2009-05-07 16:06 . 2006-11-02 10:25 143360 —-a-w c:\windows\inf\infstrng.dat
2009-05-07 12:26 . 2008-07-02 17:39 1356 —-a-w c:\users\jason\AppData\Local\d3d9caps.dat
2009-05-04 13:07 . 2009-05-04 13:07 ——– d—–w c:\program files\Lavasoft
2009-05-04 12:24 . 2009-05-04 12:24 ——– d—–w c:\program files\Bazooka Scanner
2009-05-01 14:21 . 2009-05-01 14:02 ——– d—–w c:\program files\PCPitstop
2009-04-30 18:25 . 2009-05-01 16:12 102664 —-a-w c:\windows\system32\drivers\tmcomm.sys
2009-04-24 18:48 . 2008-07-10 16:04 ——– d—–w c:\program files\Java
2009-04-17 12:33 . 2006-11-02 11:18 ——– d—–w c:\program files\Windows Mail
2009-04-14 19:36 . 2009-01-10 20:24 ——– d—–w c:\program files\Common Files\Research In Motion
2009-04-03 13:28 . 2008-07-03 13:42 ——– d—–w c:\program files\Common Files\Adobe
2009-03-25 15:18 . 2009-03-25 15:17 ——– d—–w c:\program files\IRISCard 4 Mini
2009-03-17 03:38 . 2009-04-16 15:25 13824 —-a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-16 15:25 24064 —-a-w c:\windows\system32\amxread.dll
2009-03-12 16:59 . 2009-03-12 16:59 ——– d—–w c:\program files\Gimp-2.0
2009-03-09 08:19 . 2008-12-31 19:06 410984 —-a-w c:\windows\system32\deploytk.dll
2009-03-03 04:46 . 2009-04-16 15:25 3599328 —-a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-16 15:25 3547632 —-a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-16 15:25 827392 —-a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-16 15:25 183296 —-a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-16 15:25 551424 —-a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-16 15:25 26112 —-a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-16 15:25 78336 —-a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-16 15:25 98304 —-a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-16 15:25 54784 —-a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-16 15:25 44032 —-a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-16 15:25 666624 —-a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-16 15:25 17408 —-a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-16 15:25 26624 —-a-w c:\windows\system32\ieUnatt.exe
2009-02-13 08:49 . 2009-04-16 15:25 72704 —-a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-16 15:25 1255936 —-a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 10:32 2033152 —-a-w c:\windows\system32\win32k.sys
2008-08-12 12:58 . 2006-11-02 12:49 174 –sha-w c:\program files\desktop.ini
2009-04-01 01:47 . 2009-05-01 16:42 324976 —-a-w c:\program files\mozilla firefox\components\coFFPlgn.dll
2007-02-21 19:50 . 2007-02-21 19:50 8192 –sha-w c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}]
2009-04-09 23:09 688128 —-a-w c:\program files\Dealio Toolbar\DealioToolbarIE.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
2009-04-09 23:10 1091584 —-a-w c:\program files\Search Settings\kb128\SearchSettings.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}"= "c:\program files\Dealio Toolbar\DealioToolbarIE.dll" [2009-04-09 688128]
[HKEY_CLASSES_ROOT\clsid\{01398b87-61af-4ffb-9ab5-1a1c5fb39a9c}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-09-23 21755688]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480]
"GoToMeeting"="c:\program files\Citrix\GoToMeeting\320\g2mstart.exe" [2008-07-07 31552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WatcherHelper"="c:\program files\Sierra Wireless Inc\Watcher\WaHelper.exe" [2008-11-03 114688]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2009-04-09 970240]
"RoxWatchTray"="c:\program files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2008-08-26 236016]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-08-23 92704]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-08-23 13535776]
"LVCOMSX"="c:\program files\Common Files\Logitech\LComMgr\LVComSX.exe" [2006-06-26 243248]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam10\QuickCam10.exe" [2006-06-26 614960]
"LogitechCommunicationsManager"="c:\program files\Common Files\Logitech\LComMgr\Communications_Helper.exe" [2006-06-26 497200]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-10-01 289576]
"DellNSCST_GRNCH"="c:\program files\DELL\Dell Laser MFP 1815\NetworkScan\DNSCST.exe" [2006-12-05 278528]
"BlackBerryAutoUpdate"="c:\program files\Common Files\Research In Motion\Auto Update\RIMAutoUpdate.exe" [2009-03-26 615696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-06 516440]
"Bluetooth HCI Monitor"="HCIMNTR.DLL" - c:\windows\System32\HCIMNTR.DLL [2006-12-07 9728]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2007-2-13 715568]
Desktop Manager.lnk - c:\program files\Research In Motion\BlackBerry\DesktopMgr.exe [2009-3-25 1545488]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\eudora\EuShlExt.dll" [2006-08-17 86016]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\beep.sys]
@="beep"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{D3FF4B8E-7429-4EEF-B8CD-34526BFB72C4}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{BE54B738-574B-4C1D-BB74-01EDEEBD5D25}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{AC4CC041-820F-41D2-AB7F-76A6611EFAD7}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{3DA35D26-69BC-4D3D-8E79-DEDDB04BBE70}"= Disabled:TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{C01FBC51-5491-4D5D-B795-778FA42EA2D1}"= Disabled:UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{6DABC2E6-3C62-46D6-8DF5-FEECE3341F6E}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{41B6C620-1C99-4144-A7A6-99AA8A102B54}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{623AA82D-A229-4146-8293-D4D5ACD3A3BF}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{EE5B3947-097B-450F-9F14-325B47BCDC40}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{00160BC3-7D72-4586-B445-FD3A6B02A363}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8D35E423-DF3E-49A8-8771-219CD6D6F693}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
""=
"c:\\Program Files\\Sierra Wireless Inc\\Watcher\\SwiApiMux.exe"= c:\program files\Sierra Wireless Inc\Watcher\SwiApiMux.exe:*:Enabled:SwiApiMux
R0 Lbd;Lbd;c:\windows\System32\drivers\Lbd.sys [5/6/2009 3:36 PM 64160]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 4:06 PM 953168]
R2 SSPORT;SSPORT;c:\windows\System32\drivers\ssport.sys [9/4/2008 12:25 PM 5120]
R3 wsvad_driver;WS Audio Device;c:\windows\System32\drivers\VirtualAudio.sys [4/24/2009 11:56 AM 16896]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{483322a8-e337-11dd-8f9a-001e4ce720b1}]
\shell\AutoRun\command - J:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5dd7d30b-1eb6-11de-9440-001e4ce720b1}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cb8bb989-f1fb-11dd-bc67-001e4ce720b1}]
\shell\AutoRun\command - K:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
2009-05-04 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 18:35]
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-AirCardEnabler - (no file)
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
DPF: {32305793-C19A-48E7-AD2F-D87FF7B264A4} - hxxp://download.tenebril.com/pub/bin/scanner2008/TenebrilSpywareScanner.ocx
DPF: {6824D897-F7E1-4E41-B84B-B1D3FA4BF1BD} - hxxp://utilities.pcpitstop.com/Exterminate2/pcpitstopAntiVirus.dll
FF - ProfilePath - c:\users\jason\AppData\Roaming\Mozilla\Firefox\Profiles\0hbx6tml.default\
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=867034&p=
FF - component: c:\program files\Mozilla Firefox\extensions\{01398B87-61AF-4FFB-9AB5-1A1C5FB39A9C}\components\DealioToolbarFF.dll
FF - component: c:\program files\Mozilla Firefox\extensions\[removed]\components\SearchSettingsFF.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-05-07 14:20
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-05-07 14:22
ComboFix-quarantined-files.txt 2009-05-07 17:21
Pre-Run: 374,129,356,800 bytes free
Post-Run: 374,116,933,632 bytes free
236 — E O F — 2009-05-07 13:00
****************************************************
Small update on my status
After taking a few moments to post this topic I went back to said computer and it does seem to be connecting to the internet at the moment. I am currently re-installing norton. Will update when I have found conclusive evidence that Flush.M is either removed or still active.