This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] win32/renos.io trojan infected please help!

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My windows defender is saying that i am infected with trojandownloader:win32/renos.io on windows Vista operating system. I have removed it but it keeps coming back and is affecting my internet explorer and other functions on windows. I performed DDS and a GMER Rootkit Scanner on my laptop the results can be found below. Can someone please provide a step by step guide of what i need to do in order to get rid of this trojan. thanks. Neil. DDS DDS (Ver_09-05-14.01) - NTFSx86 Run by [removed] at 18:41:08.91 on 15/06/2009 Internet Explorer: 7.0.6000.16757 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.2045.1142 [GMT 1:00] ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k NetworkService C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe c:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\HP\QuickPlay\QPService.exe C:\Program Files\Napster\napster.exe C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files\Java\jre1.6.0\bin\jusched.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe C:\Program Files\HP\HP Software Update\hpwuSchd2.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Windows\ehome\ehtray.exe C:\Windows\ehome\ehmsas.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Windows\System32\rundll32.exe C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\rundll32.exe C:\Windows\system32\vssvc.exe C:\Windows\System32\svchost.exe -k swprv C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Neil\Desktop\dds.pif C:\Windows\system32\wbem\wmiprvse.exe ============== Pseudo HJT Report =============== uStart Page = hxxp://uk.yahoo.com/ uLocal Page = \blank.htm mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop mDefault_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop uInternet Settings,ProxyOverride = *.local BHO: MyWay Search Assistant BHO: {04079851-5845-4dea-848c-3ecd647aa554} - c:\program files\myway\srchastt\1.bin\MYSRCHAS.DLL BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {1e8a6170-7264-4d0f-beae-d42a53123c75} - c:\program files\common files\symantec shared\coshared\browser\1.0\NppBho.dll BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0\bin\ssv.dll BHO: {7E853D72-626A-48EC-A868-BA8D5E23E045} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll TB: Show Norton Toolbar: {90222687-f593-4738-b738-fbee9c7b26df} - c:\program files\common files\symantec shared\coshared\browser\1.0\UIBHO.dll uRun: [MsnMsgr] "c:\program files\msn messenger\MsnMsgr.Exe" /background uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [ccApp] "c:\program files\common files\symantec shared\ccApp.exe" mRun: [osCheck] "c:\program files\norton internet security\osCheck.exe" mRun: [QPService] "c:\program files\hp\quickplay\QPService.exe" mRun: [NapsterShell] c:\program files\napster\napster.exe /systray mRun: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start mRun: [HP Health Check Scheduler] c:\program files\hewlett-packard\hp health check\HPHC_Scheduler.exe mRun: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe mRun: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe mRun: [SunJavaUpdateSched] "c:\program files\java\jre1.6.0\bin\jusched.exe" mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot mRun: [NvSvc] RUNDLL32.EXE c:\windows\system32\nvsvc.dll,nvsvcStart mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe" mRun: [Symantec PIF AlertEng] "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\pifsvc.exe" /a /m "c:\program files\common files\symantec shared\pif\{b8e1dd85-8582-4c61-b58f-2f227fca9a08}\AlertEng.dll" mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\bin\AppleSyncNotifier.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe mRunOnce: [Malwarebytes' Anti-Malware] c:\program files\malwarebytes' anti-malware\mbamgui.exe /install /silent StartupFolder: c:\users\neil\appdata\roaming\micros~1\windows\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC} - c:\program files\java\jre1.6.0\bin\ssv.dll IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://a1540.g.akamai.net/7/1540/52/20061205/qtinstall.info.apple.com/qtactivex/qtplugin.cab DPF: {138E6DC9-722B-4F4B-B09D-95D191869696} - hxxp://www.bebo.com/files/BeboUploader.5.1.4.cab DPF: {15589FA1-C456-11CE-BF01-00AA0055595A} - hxxp://w4s2.work4sure.com/c/ge/w4sgeen9.exe DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} - hxxp://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} - hxxp://cid-ecc61d92de9fde3c.spaces.live.com/PhotoUpload/VistaMsnPUplden-gb.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/products/plugin/autodl/jinstall-160-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} - hxxp://messenger.zone.msn.com/binary/ZIntro.cab56649.cab DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} - hxxp://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab DPF: {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/products/plugin/autodl/jinstall-142-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} - hxxp://messenger.zone.msn.com/binary/Chess.cab57176.cab TCP: NameServer = 85.255.112.153,85.255.112.92 TCP: {D3AC4E97-26BF-47D0-8DAD-4398E9D5740C} = 85.255.112.153,85.255.112.92 TCP: {E2C0EBF6-2E4F-47AA-91B2-1CA035546ED9} = 85.255.112.153,85.255.112.92 Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll ============= SERVICES / DRIVERS =============== R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\symantec\defini~1\symcdata\idsdefs\20070612.005\IDSvix86.sys [2007-6-13 212280] R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2007-6-14 106808] R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\drivers\R5U870FLx86.sys [2006-12-18 73472] R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\drivers\R5U870FUx86.sys [2006-12-18 43904] R3 SYMNDISV;SYMNDISV;c:\windows\system32\drivers\symndisv.sys [2008-10-3 37936] ============== File Associations =============== regfile="regedit.exe" "%1" =============== Created Last 30 ================ 2009-06-15 18:29 40,160 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-06-15 18:29 19,096 a——- c:\windows\system32\drivers\mbam.sys 2009-06-15 18:29 –d—– c:\programdata\Malwarebytes 2009-06-15 18:29 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-06-15 18:29 –d—– c:\progra~2\Malwarebytes 2009-06-15 17:29 –d—– c:\program files\NoAdware 2009-06-11 10:47 –d—– c:\windows\system32\Adobe 2009-06-10 22:29 –d—– c:\users\neil\appdata\roaming\Spotify 2009-06-10 22:29 –d—– c:\program files\Spotify ==================== Find3M ==================== 2009-06-15 18:07 2,484 a——- c:\windows\bthservsdp.dat 2009-06-15 17:01 124,464 a——- c:\windows\system32\drivers\SYMEVENT.SYS 2009-06-15 17:01 10,635 a——- c:\windows\system32\drivers\SYMEVENT.CAT 2009-06-15 17:01 806 a——- c:\windows\system32\drivers\SYMEVENT.INF 2009-06-15 14:01 12,978 a——- c:\users\neil\appdata\roaming\nvModes.dat 2009-04-12 12:01 86,016 a——- c:\windows\inf\infstrng.dat 2009-04-12 12:01 86,016 a——- c:\windows\inf\infstor.dat 2009-04-12 12:01 51,200 a——- c:\windows\inf\infpub.dat 2009-03-26 15:23 1,900,544 a——- c:\windows\system32\usbaaplrc.dll 2008-07-11 11:31 174 a–sh— c:\program files\desktop.ini 2008-06-12 18:47 665,600 a——- c:\windows\inf\drvindex.dat 2007-04-29 19:09 87,608 a——- c:\users\neil\appdata\roaming\inst.exe 2007-04-29 19:09 47,360 a——- c:\users\neil\appdata\roaming\pcouffin.sys 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfi.dat 2006-11-02 13:42 287,440 a——- c:\windows\inf\perflib\0409\perfh.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfd.dat 2006-11-02 13:42 30,674 a——- c:\windows\inf\perflib\0409\perfc.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfi.dat 2006-11-02 10:20 287,440 a——- c:\windows\inf\perflib\0000\perfh.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfd.dat 2006-11-02 10:20 30,674 a——- c:\windows\inf\perflib\0000\perfc.dat ============= FINISH: 18:41:37.28 ===============
[external image: Posted Image]

Hi Neil, welcome to the WTT Forums. My username is Raktor, and I would be glad to take a look at your log.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

I will be back to you shortly with instructions. :)
Hi Neil,

Please download ComboFix to your desktop from one of these locations. You must rename it before saving it. Save it to your desktop.
Link 1
Link 2
Link 3

[external image: Posted Image]


[external image: Posted Image]

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Right-click on Combo-Fix.exe, select Run As Administrator & follow the prompts.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]

  • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]
  • Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. ComboFix may reset a number of Internet Explorer's settings, including making IE the default browser.
4. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please advise.
5. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Hi there thanks for your help. please find the contents of the ComboFix log below. please inform me of the next step i need to take.

Thanks.Neil.



ComboFix 09-06-15.06 - Neil 16/06/2009 12:38.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.44.1033.18.2045.993 [GMT 1:00]
Running from: c:\users\[removed]\Desktop\Combo-Fix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\MyWay
c:\program files\MyWay\SrchAstt\1.bin\MYSRCHAS.DLL
c:\program files\MyWay\SrchAstt\1.bin\PARTNER.DAT
c:\program files\MyWay\SrchAstt\1.bin\PARTNER2.DAT
c:\program files\MyWay\SrchAstt\Cache\00057DF5
c:\program files\MyWay\SrchAstt\Cache\0047DA58
c:\program files\MyWay\SrchAstt\Cache\files.ini
c:\users\Neil\AppData\Local\Temp\install_flash_player.exe
c:\users\Neil\AppData\Roaming\inst.exe
c:\users\Neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Download programs.url
c:\users\Neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games.url
c:\users\Neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Translator.url
c:\users\Neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Videos.url
c:\users\Neil\FAVORI~1\Download programs.url
c:\users\Neil\FAVORI~1\Games.url
c:\users\Neil\FAVORI~1\Translator.url
c:\users\Neil\FAVORI~1\Videos.url
c:\users\Neil\Favorites\Download programs.url
c:\users\Neil\Favorites\Games.url
c:\users\Neil\Favorites\Translator.url
c:\users\Neil\Favorites\Videos.url
c:\windows\system32\drivers\MSIVXywlxlgthfbxrvpojklaekreieuqxidcl.sys
c:\windows\system32\MSIVXcount
c:\windows\system32\MSIVXlqoobobsjgtccpdoixdqdhlubefdfsfx.dll
c:\windows\system32\MSIVXlrshivqkrmigksfesifoerpwootfrwlg.dll
c:\windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
D:\Desktop.ini

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Service_MSIVXserv.sys


((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.

2009-06-16 11:50 . 2009-06-16 11:51 ——– d—–w- c:\users\Neil\AppData\Local\temp
2009-06-16 11:33 . 2009-06-16 11:33 ——– d-sh–w- C:\found.000
2009-06-15 21:00 . 2009-06-15 21:00 ——– d—–w- c:\program files\AVG
2009-06-15 20:10 . 2009-06-15 20:13 ——– d—–w- c:\program files\Common Files\ParetoLogic
2009-06-15 20:09 . 2009-06-15 20:09 ——– d—–w- c:\users\Neil\AppData\Local\Downloaded Installations
2009-06-15 16:29 . 2009-06-15 16:29 ——– d—–w- c:\program files\NoAdware
2009-06-11 09:47 . 2009-06-11 09:48 ——– d—–w- c:\windows\system32\Adobe
2009-06-10 21:29 . 2009-06-10 21:34 ——– d—–w- c:\users\Neil\AppData\Roaming\Spotify
2009-06-10 21:29 . 2009-06-10 21:30 ——– d—–w- c:\users\Neil\AppData\Local\Spotify
2009-06-10 21:29 . 2009-06-10 21:29 ——– d—–w- c:\program files\Spotify
2009-05-23 13:26 . 2009-05-23 13:26 ——– d—–w- c:\users\Neil\AppData\Roaming\Sony Corporation

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 11:26 . 2007-01-25 15:19 2484 —-a-w- c:\windows\bthservsdp.dat
2009-06-15 21:23 . 2007-01-25 15:52 ——– d—–w- c:\program files\Norton Internet Security
2009-06-15 21:20 . 2007-01-25 15:51 ——– d—–w- c:\programdata\Symantec
2009-06-15 21:19 . 2007-01-25 15:51 ——– d—–w- c:\program files\Symantec
2009-06-15 21:19 . 2007-01-25 15:51 806 —-a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-06-15 21:19 . 2007-01-25 15:51 124464 —-a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-06-15 21:19 . 2007-01-25 15:51 10635 —-a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-06-15 21:18 . 2007-01-25 15:50 ——– d—–w- c:\program files\Common Files\Symantec Shared
2009-06-15 13:01 . 2007-04-15 13:43 12978 —-a-w- c:\users\Neil\AppData\Roaming\nvModes.dat
2009-05-23 13:26 . 2007-10-14 14:12 ——– d—–w- c:\program files\Sony
2009-05-21 11:40 . 2007-05-13 10:06 7484 —-a-w- c:\users\Neil\AppData\Local\d3d9caps.dat
2009-05-21 09:26 . 2007-01-25 16:12 ——– d—–w- c:\program files\Google
2009-05-18 19:36 . 2007-01-25 15:39 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-04-28 17:33 . 2009-04-28 17:33 ——– d—–w- c:\programdata\Channel4
2009-04-20 11:16 . 2009-04-20 11:15 ——– d—–w- c:\program files\SpeedFan
2009-04-12 10:58 . 2009-04-12 10:58 75048 —-a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-03-26 14:23 . 2009-03-26 14:23 36864 —-a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-26 14:23 . 2009-03-26 14:23 1900544 —-a-w- c:\windows\system32\usbaaplrc.dll
2009-03-19 15:32 . 2009-04-12 11:07 23400 —-a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 15:32 . 2009-03-19 15:32 23400 —-a-w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="c:\program files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 5674352]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
"Sidebar"="c:\program files\windows sidebar\sidebar.exe" [2008-01-09 1232896]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 115816]
"osCheck"="c:\program files\Norton Internet Security\osCheck.exe" [2006-10-27 22696]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2006-11-24 167936]
"NapsterShell"="c:\program files\Napster\napster.exe" [2006-09-06 323216]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-11-06 159744]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2008-06-16 75008]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2006-10-18 317152]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2006-10-18 472800]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0\bin\jusched.exe" [2007-01-25 77824]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-04-15 185896]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-02-27 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-02-27 7770112]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-02-27 81920]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 583048]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-11-07 111936]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"*WerKernelReporting"="c:\windows\SYSTEM32\WerFault.exe" [2006-11-02 216064]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]

c:\users\Neil\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2007-12-7 101440]

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{C44FE2CB-3481-4FBF-A5F3-B2FABE8CC8B7}"= UDP:c:\program files\HP\QuickPlay\QP.exe:QP
"{188B4E3A-3F51-4A7B-A1C0-2820E27496CA}"= TCP:c:\program files\HP\QuickPlay\QP.exe:QP
"{F28E64A0-EB3B-484F-BCBB-339D791733AA}"= c:\program files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{67E33E15-5782-4CF7-9AD1-6DDFE7FDAAEA}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{20F95EB8-8429-4859-BFA9-044A734F077D}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{20CF9182-A7F7-473D-B614-AF58BE3BB9C5}"= UDP:8223:BitComet 8223 TCP
"{DFE96A1F-DC66-4B88-A8AF-95D767A2E7FE}"= TCP:8223:BitComet 8223 UDP
"TCP Query User{5CE400A6-90A1-4D65-A695-2689A18257A6}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{5D273E7D-B597-46DE-B006-68C1C7A1C8F4}c:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:c:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{8BA9C322-64ED-4072-AD5F-0983460C8EBF}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{C6330DC0-C69F-4F40-85B7-A3AAEED3AB85}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{1ECF5D48-762E-4E86-BAC0-2061373BA78F}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{7A0911DE-46C2-4A59-BD60-0159991EE016}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{93F4162C-3057-41B1-B798-1CAC0E33E8B2}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{79FE2974-C6A2-451C-96F9-3BAC26F13890}"= UDP:c:\program files\Sierra\FEAR\FEAR.exe:FEAR
"{4BBB10EC-F96A-48AC-B6D5-9F93D1DD844A}"= TCP:c:\program files\Sierra\FEAR\FEAR.exe:FEAR
"{7E8AB2B4-9A27-479D-A0D0-9B653AC4F752}"= UDP:c:\program files\Sierra\FEAR\FEARMP.exe:FEARMP
"{15404E3E-7136-4B48-A47A-2235AB14B42D}"= TCP:c:\program files\Sierra\FEAR\FEARMP.exe:FEARMP
"{6D243499-9932-4556-A926-C1AAD57EFCAA}"= UDP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{7953AA02-97AF-4CED-81E8-4D6A1FC7FAE1}"= TCP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (CLI)
"{6D9E0E28-9F3C-4103-A3F1-56A236501DF9}"= UDP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{A0433672-2ABA-41F1-BBC0-DBC0BB1C8556}"= TCP:c:\program files\THQ\S.T.A.L.K.E.R. - Shadow of Chernobyl\bin\dedicated\XR_3DA.exe:S.T.A.L.K.E.R. - Shadow of Chernobyl (SRV)
"{716473CF-F3B6-432B-9F7B-078C4F854B01}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{3041E5AA-F26E-44FB-B68E-2CEC383B0A9D}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{C47E014E-040D-4532-8329-34E69A7C2B6D}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{341E61F3-52F9-45CA-8088-544E5BBC7DB8}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{EE6F22DB-4DAC-4215-B472-0FA15013E65A}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{73AB3761-9053-48FB-BFDB-3E351D1F524F}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{540308F1-5724-4253-98A0-1BD864D0956B}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{ADA72DB6-E7F4-4511-94C0-AD9C5D20731E}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)

R1 IDSvix86;Symantec Intrusion Prevention Driver;c:\progra~2\Symantec\DEFINI~1\SymcData\idsdefs\20070612.005\IDSvix86.sys [13/06/2007 22:47 212280]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\System32\drivers\R5U870FLx86.sys [18/12/2006 23:31 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\System32\drivers\R5U870FUx86.sys [18/12/2006 23:31 43904]
R3 SYMNDISV;SYMNDISV;c:\windows\System32\drivers\symndisv.sys [03/10/2008 14:14 37936]

— Other Services/Drivers In Memory —

*NewlyCreated* - COMHOST

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder

2009-05-08 c:\windows\Tasks\Norton Internet Security - Run Full System Scan - Neil.job
- c:\progra~1\NORTON~1\NORTON~1\Navw32.exe [2006-11-08 07:48]

2009-06-15 c:\windows\Tasks\User_Feed_Synchronization-{5AB06344-6C81-4001-8C3D-A6ADEF032017}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://uk.yahoo.com/
uLocal Page = \blank.htm
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=71&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-16 12:50
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2009-06-16 12:53
ComboFix-quarantined-files.txt 2009-06-16 11:52

Pre-Run: 17,956,864,000 bytes free
Post-Run: 21,077,667,840 bytes free

227 — E O F — 2009-06-15 15:26
Good job Neil, we're getting there. :thumbup:

1) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

2) Kaspersky
I'd like for you to run this next online scan to check for remnants or anything that might be hidden.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.


Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition
    files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
    * Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    * Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    * Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
Click on: Save Report As
Next, in the Save as prompt, Save in area, select: Desktop
In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
Text file [*.txt]
Then, click: Save
Please post the Kaspersky Online Scanner Report in
your reply.

Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

3) What You Will Need To Post:
  • MBAM Log
  • Kaspersky Log
  • How your computer is running now

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI