This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Infection--

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Okay, my computer just got majorly infected with something. Basically it won't let me run any antivirus programs, and sometimes when I start the computer it shuts down instantly– hasn't happened too often though.

It's pretty much the same thing as in this topic here:
http://forums.whatthetech.com/HELP_ME_PLEA…AN_t106625.html

I would love if you guys could help me with this.

Thankyou, and this is an awesome site.

–Puglin

Hello Puglin,
Welcome to What the Tech.
My name is OCD, I will be helping you with your log today.

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.

In order for us to get started I need for you to supply me with a few logs to help evaluate your computer, and determine a course of action.

If you are running Windows Vista you will need to run these tools by right clicking on the desktop icon and selecting "Run As Administrator".

- - - - - Next - - - - -

Please run RootRepeal

  • Download RootRepeal from one of the following locations and save it to your desktop.
    Here
    Here
    or Here

  • Open [external image: Posted Image] on your desktop.

  • Click the [external image: Posted Image] tab.

  • Click the [external image: Posted Image] button.

  • In the Select Scan dialog, check

    [external image: Posted Image]

  • Push Ok
  • Check the box for your main system drive (Usually C:), and press OK.
  • Allow RootRepeal to run a scan of your system. This may take some time.
  • Once the scan completes, push the [external image: Posted Image] button. Save the log to your desktop, using a distinctive name, such as RootRepeal.txt.
- - - - - Next - - - - -

Please download DDS from one of the following links and save it to your desktop.
    • DDS.scr
    • DDS.pif
  • Disable any script blocking protection (How to Disable your Security Programs) <– Important
  • Double click DDS icon to run the tool (may take up to 3 minutes to run)
  • When done, DDS.txt will open.
  • After a few moments, attach.txt will open in a second window.
  • Save both reports to your desktop.
- - - - - Next - - - - -

On your next post please provide the following:
  • RootRepeal.txt
  • Post the contents of the DDS.txt report in your next reply
  • Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
  • Tell me how your computer is running at the moment.

Thanks for the prompt reply, hope you can help. Here's that information you wanted: Root Repeal: ROOTREPEAL © AD, 2007-2009 ================================================== Scan Start Time: 2009/09/13 15:49 Program Version: Version 1.3.5.0 Windows Version: Windows XP SP3 ================================================== Drivers ——————- Name: dump_atapi.sys Image Path: C:\WINDOWS\System32\Drivers\dump_atapi.sys Address: 0xB413B000 Size: 98304 File Visible: No Signed: - Status: - Name: dump_WMILIB.SYS Image Path: C:\WINDOWS\System32\Drivers\dump_WMILIB.SYS Address: 0xB85F4000 Size: 8192 File Visible: No Signed: - Status: - Name: rootrepeal.sys Image Path: C:\WINDOWS\system32\drivers\rootrepeal.sys Address: 0xB2529000 Size: 49152 File Visible: No Signed: - Status: - ==EOF== Here's the DDS.txt: DDS (Ver_09-07-30.01) - NTFSx86 Run by [removed] at 15:50:55.96 on Sun 13/09/2009 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.430 [GMT 8:00] AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD} ============== Running Processes =============== C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\acs.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\WINDOWS\system32\crypserv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\PnkBstrA.exe C:\WINDOWS\system32\PnkBstrB.exe C:\Program Files\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\Program Files\Sophos\AutoUpdate\ALsvc.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\TP-LINK\TWCU\TWCU.exe C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Windows Live\Messenger\msnmsgr.exe C:\Program Files\Electronic Arts\EADM\Core.exe C:\Program Files\Sophos\AutoUpdate\ALMon.exe C:\Program Files\Xfire\Xfire.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Hamachi\hamachi.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\THQ\Gas Powered Games\Supreme Commander - Forged Alliance\bin\ForgedAlliance.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\William\Desktop\RootRepeal.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\William\Desktop\dds.scr ============== Pseudo HJT Report =============== mStart Page = hxxp://www.troner.net/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Skype add-on (mastermind): {22bf413b-c6d2-4d91-82a9-a0f997ba588c} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll BHO: Sophos Web Content Scanner: {39ea7695-b3f2-4c44-a4bc-297ada8fd235} - c:\program files\sophos\sophos anti-virus\SophosBHO.dll BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background uRun: [EA Core] "c:\program files\electronic arts\eadm\Core.exe" -silent uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [RTHDCPL] RTHDCPL.EXE mRun: [SkyTel] SkyTel.EXE mRun: [GBB36X Configure] c:\windows\system32\JMRaidTool.exe boot mRun: [nwiz] nwiz.exe /install mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [TWCU] "c:\program files\tp-link\twcu\TWCU.exe" -nogui mRun: [HPDJ Taskbar Utility] c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe mRun: [NeroFilterCheck] c:\program files\common files\nero\lib\NeroCheck.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE StartupFolder: c:\docume~1\william\startm~1\programs\startup\xfire.lnk - c:\program files\xfire\Xfire.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\autoup~1.lnk - c:\program files\sophos\autoupdate\ALMon.exe IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {77BF5300-1474-4EC7-9980-D32B190E9B07} - {77BF5300-1474-4EC7-9980-D32B190E9B07} - c:\program files\skype\toolbars\internet explorer\SkypeIEPlugin.dll IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.23.0.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL ============= SERVICES / DRIVERS =============== R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [2009-6-11 110848] R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [2009-6-11 38528] R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\sophos\sophos anti-virus\SAVAdminService.exe [2009-5-7 80936] R2 Sophos AutoUpdate Service;Sophos AutoUpdate Service;c:\program files\sophos\autoupdate\ALsvc.exe [2009-6-11 172032] S2 SAVService;Sophos Anti-Virus;c:\program files\sophos\sophos anti-virus\SavService.exe [2008-8-21 98304] S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [2009-6-11 14976] =============== Created Last 30 ================ 2009-09-12 15:13 a-dshr– C:\cmdcons 2009-09-12 15:12 230,912 a——- c:\windows\PEV.exe 2009-09-12 15:12 161,792 a——- c:\windows\SWREG.exe 2009-09-12 15:12 98,816 a——- c:\windows\sed.exe 2009-09-12 15:04 –d—– c:\docume~1\william\applic~1\Malwarebytes 2009-09-12 15:03 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-12 15:03 19,160 a——- c:\windows\system32\drivers\mbam.sys 2009-09-12 15:03 –d—– c:\program files\Malwarebytes' Anti-Malware 2009-09-12 15:03 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes 2009-09-12 14:43 146,650 a——- c:\windows\system32\BuzzingBee.wav 2009-09-11 18:19 –d—– c:\program files\Savage 2 - A Tortured Soul 2009-09-09 18:24 153,088 -c—— c:\windows\system32\dllcache\triedit.dll 2009-09-07 16:12 –d—– c:\docume~1\william\applic~1\BitTorrent 2009-09-05 15:26 –d—– c:\docume~1\alluse~1\applic~1\Media Center Programs 2009-09-05 15:14 2,414,360 a——- c:\windows\system32\d3dx9_31.dll 2009-09-05 13:42 –d—– C:\found.000 2009-09-04 02:07 41,872 a——- c:\windows\system32\xfcodec.dll 2009-08-22 23:14 –d—– c:\program files\NCSoft 2009-08-22 12:37 –d—– c:\program files\bman654 2009-08-21 19:44 –d—– c:\program files\TQ Defiler.NET 2009-08-18 17:42 19 a——- c:\windows\popcinfo.dat 2009-08-18 15:44 1,089,593 -c—— c:\windows\system32\dllcache\ntprint.cat 2009-08-17 22:18 –d—– c:\windows\system32\XPSViewer 2009-08-17 22:17 597,504 -c—— c:\windows\system32\dllcache\printfilterpipelinesvc.exe 2009-08-17 22:17 89,088 -c—— c:\windows\system32\dllcache\filterpipelineprintproc.dll 2009-08-17 22:17 117,760 ——– c:\windows\system32\prntvpt.dll 2009-08-17 22:17 1,676,288 -c—— c:\windows\system32\dllcache\xpssvcs.dll 2009-08-17 22:17 575,488 -c—— c:\windows\system32\dllcache\xpsshhdr.dll 2009-08-17 22:17 –d—– C:\083e85c5d1d6c2d67c 2009-08-17 22:17 1,676,288 ——– c:\windows\system32\xpssvcs.dll 2009-08-17 22:17 575,488 ——– c:\windows\system32\xpsshhdr.dll 2009-08-15 17:36 –d—– c:\program files\Iteral 2009-08-15 11:31 21,504 ac—— c:\windows\system32\dllcache\hidserv.dll 2009-08-15 11:31 21,504 a——- c:\windows\system32\hidserv.dll 2009-08-15 11:31 60,032 ac—— c:\windows\system32\dllcache\usbaudio.sys 2009-08-15 11:31 60,032 a——- c:\windows\system32\drivers\USBAUDIO.sys ==================== Find3M ==================== 2009-09-09 22:40 138,520 a——- c:\windows\system32\drivers\PnkBstrK.sys 2009-09-09 22:40 189,640 a——- c:\windows\system32\PnkBstrB.exe 2009-08-05 17:01 204,800 a——- c:\windows\system32\mswebdvd.dll 2009-08-03 20:11 139,152 a——- c:\docume~1\william\applic~1\PnkBstrK.sys 2009-08-03 20:11 75,064 a——- c:\windows\system32\PnkBstrA.exe 2009-08-03 20:11 794,408 a——- c:\windows\system32\pbsvc.exe 2009-07-18 03:01 58,880 a——- c:\windows\system32\atl.dll 2009-07-12 12:21 233,472 a——- c:\windows\system32\wmpdxm.dll 2009-07-10 20:31 130,104 a——- c:\windows\system32\sdccoinstaller.dll 2009-07-04 01:09 915,456 ——– c:\windows\system32\wininet.dll 2009-06-25 16:25 730,112 a——- c:\windows\system32\lsasrv.dll 2009-06-25 16:25 301,568 a——- c:\windows\system32\kerberos.dll 2009-06-25 16:25 147,456 a——- c:\windows\system32\schannel.dll 2009-06-25 16:25 136,192 a——- c:\windows\system32\msv1_0.dll 2009-06-25 16:25 56,832 a——- c:\windows\system32\secur32.dll 2009-06-25 16:25 54,272 a——- c:\windows\system32\wdigest.dll 2009-06-16 22:36 119,808 a——- c:\windows\system32\t2embed.dll 2009-06-16 22:36 81,920 a——- c:\windows\system32\fontsub.dll ============= FINISH: 15:51:12.00 =============== Attach.txt should be… well… attached. Also, my computer is running just fine right now, though yesterday, when I got the actual virus, it kept shutting down immediately on startup with a text box about one of the .dll files failing to work (I'm sorry I can't be more specific, but I've forgotten the details). It wouldn't work unless I turned off power at the switch and turned it on again. But, yeah, it's running fine now, games etc. are working fine.

Attachments:

Puglin,

The logs you provided show you have run ComboFix in the past.

Was it recently? If so, please supply me with the newest log it produced.

The log can be located here:
C:\ComboFix.txt if no log is located here, then please check C:\Qoobox\ComboFix1.txt - (find the most recent date, this is the log I need to see)
Also, provide this log as well: C:\Qoobox\ComboFix-quarantined-files.txt

- - - - - Next - - - - -

Run the following scan: Eset Online Scanner
(you will need Internet Explorer to run this scan)

  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
- - - - - Next - - - - -

Reboot, on your next post please provide the following:
  • ComboFix.txt - (if found)
  • ComboFix1.txt - (most recent, if necessary)
  • ComboFix-quarantined-files.txt
  • ESET log.txt
  • Any changes in machine performance?

Yes, I did run ComboFix very recently, after the infection took hold.

Here's the log:

ComboFix 09-09-11.01 - William 12/09/2009 15:43.2.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1605 [GMT 8:00]
Running from: c:\documents and settings\[removed]\Desktop\Combo-Fix.exe
Command switches used :: c:\documents and settings\William\Desktop\CFScript.txt
AV: Sophos Anti-Virus *On-access scanning disabled* (Updated) {3F13C776-3CBE-4DE9-8BF6-09E5183CA2BD}
.

((((((((((((((((((((((((( Files Created from 2009-08-12 to 2009-09-12 )))))))))))))))))))))))))))))))
.

2009-09-12 07:04 . 2009-09-12 07:04 ——– d—–w- c:\documents and settings\William\Application Data\Malwarebytes
2009-09-12 07:03 . 2009-09-10 06:54 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-12 07:03 . 2009-09-12 07:04 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2009-09-12 07:03 . 2009-09-12 07:03 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-09-12 07:03 . 2009-09-10 06:53 19160 —-a-w- c:\windows\system32\drivers\mbam.sys
2009-09-12 05:42 . 2009-09-12 05:42 ——– d—–w- c:\documents and settings\Felicity\Local Settings\Application Data\Sophos
2009-09-11 10:19 . 2009-09-11 10:36 ——– d—–w- c:\program files\Savage 2 - A Tortured Soul
2009-09-09 10:24 . 2009-06-21 21:44 153088 -c—-w- c:\windows\system32\dllcache\triedit.dll
2009-09-07 09:51 . 2009-09-07 09:51 ——– d—–w- c:\program files\7-Zip
2009-09-07 08:12 . 2009-09-07 09:01 ——– d—–w- c:\documents and settings\William\Application Data\BitTorrent
2009-09-05 08:17 . 2009-09-07 10:24 ——– d—–w- c:\documents and settings\William\Local Settings\Application Data\Gas Powered Games
2009-09-05 07:26 . 2009-09-05 08:16 ——– d—–w- c:\documents and settings\All Users\Application Data\Media Center Programs
2009-09-05 05:42 . 2009-09-05 05:42 ——– d—–w- C:\found.000
2009-09-03 18:07 . 2009-09-03 18:07 41872 —-a-w- c:\windows\system32\xfcodec.dll
2009-08-22 15:14 . 2009-08-22 15:14 ——– d—–w- c:\program files\NCSoft
2009-08-22 15:12 . 2009-08-22 15:12 ——– d—–w- c:\documents and settings\William\Application Data\InstallShield
2009-08-22 04:37 . 2009-08-22 04:37 ——– d—–w- c:\program files\bman654
2009-08-21 11:44 . 2009-08-29 10:04 ——– d—–w- c:\program files\TQ Defiler.NET
2009-08-18 09:42 . 2009-08-18 09:42 19 —-a-w- c:\windows\popcinfo.dat
2009-08-17 14:18 . 2009-08-17 14:18 ——– d—–w- c:\windows\system32\XPSViewer
2009-08-17 14:18 . 2009-08-17 14:18 ——– d—–w- c:\program files\MSBuild
2009-08-17 14:18 . 2009-08-17 14:18 ——– d—–w- c:\program files\Reference Assemblies
2009-08-17 14:17 . 2008-07-06 12:06 89088 -c—-w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-17 14:17 . 2008-07-06 12:06 117760 ——w- c:\windows\system32\prntvpt.dll
2009-08-17 14:17 . 2008-07-06 10:50 597504 -c—-w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-17 14:17 . 2009-08-17 14:17 ——– d—–w- C:\083e85c5d1d6c2d67c
2009-08-17 14:17 . 2008-07-06 12:06 575488 -c—-w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-17 14:17 . 2008-07-06 12:06 575488 ——w- c:\windows\system32\xpsshhdr.dll
2009-08-17 14:17 . 2008-07-06 12:06 1676288 -c—-w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-17 14:17 . 2008-07-06 12:06 1676288 ——w- c:\windows\system32\xpssvcs.dll
2009-08-15 09:46 . 2009-08-15 09:46 ——– d—–w- c:\documents and settings\William\Local Settings\Application Data\Iteral_Group_Ltd
2009-08-15 09:36 . 2009-08-15 09:36 ——– d—–w- c:\program files\Iteral
2009-08-15 03:31 . 2008-04-13 21:41 21504 -c–a-w- c:\windows\system32\dllcache\hidserv.dll
2009-08-15 03:31 . 2008-04-13 21:41 21504 —-a-w- c:\windows\system32\hidserv.dll
2009-08-15 03:31 . 2008-04-13 16:15 60032 -c–a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-08-15 03:31 . 2008-04-13 16:15 60032 —-a-w- c:\windows\system32\drivers\USBAUDIO.sys

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-12 05:37 . 2009-06-21 05:36 ——– d—–w- c:\documents and settings\William\Application Data\Skype
2009-09-12 05:19 . 2009-06-13 09:30 ——– d—–w- c:\documents and settings\William\Application Data\Xfire
2009-09-12 04:57 . 2009-06-21 05:37 ——– d—–w- c:\documents and settings\William\Application Data\skypePM
2009-09-11 09:25 . 2009-06-20 07:47 ——– d—–w- c:\documents and settings\William\Application Data\Hamachi
2009-09-10 07:45 . 2009-06-13 09:30 ——– d—–w- c:\program files\Xfire
2009-09-09 14:40 . 2009-08-03 12:11 138520 —-a-w- c:\windows\system32\drivers\PnkBstrK.sys
2009-09-09 14:40 . 2009-08-03 12:11 189640 —-a-w- c:\windows\system32\PnkBstrB.exe
2009-09-05 07:47 . 2009-06-11 13:01 ——– d–h–w- c:\program files\InstallShield Installation Information
2009-09-05 07:14 . 2009-06-14 07:56 ——– d—–w- c:\program files\THQ
2009-09-02 11:16 . 2009-06-13 08:02 ——– d—–w- c:\documents and settings\William\Application Data\Apple Computer
2009-08-24 01:20 . 2009-08-10 12:34 70032 —-a-w- c:\documents and settings\James\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 15:12 . 2009-06-17 14:52 ——– d—–w- c:\documents and settings\William\Application Data\GetRightToGo
2009-08-22 04:37 . 2009-06-13 09:18 70032 —-a-w- c:\documents and settings\William\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-16 10:37 . 2009-06-13 09:23 ——– d—–w- c:\program files\Windows Live
2009-08-11 10:51 . 2009-08-11 10:50 ——– d—–w- c:\program files\NCH Software
2009-08-11 10:50 . 2009-08-11 10:50 ——– d—–w- c:\documents and settings\All Users\Application Data\NCH Software
2009-08-09 09:54 . 2009-06-11 13:51 68840 —-a-w- c:\documents and settings\Graham\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-09 09:48 . 2009-08-09 09:48 ——– d—–w- c:\program files\iTunes
2009-08-09 09:48 . 2009-08-09 09:48 ——– d—–w- c:\program files\iPod
2009-08-09 09:48 . 2009-06-11 15:29 ——– d—–w- c:\program files\Common Files\Apple
2009-08-09 09:22 . 2009-08-09 09:22 ——– d—–w- c:\documents and settings\James\Application Data\Apple Computer
2009-08-05 09:01 . 2004-08-04 12:00 204800 —-a-w- c:\windows\system32\mswebdvd.dll
2009-08-03 12:11 . 2009-08-03 12:11 139152 —-a-w- c:\documents and settings\William\Application Data\PnkBstrK.sys
2009-08-03 12:11 . 2009-08-03 12:11 75064 —-a-w- c:\windows\system32\PnkBstrA.exe
2009-08-03 12:11 . 2009-08-03 12:11 794408 —-a-w- c:\windows\system32\pbsvc.exe
2009-08-03 10:56 . 2009-06-14 05:15 ——– d—–w- c:\program files\EA GAMES
2009-08-02 05:37 . 2009-06-13 10:39 ——– d—–w- c:\documents and settings\William\Application Data\SPORE
2009-07-29 09:58 . 2009-07-29 09:58 ——– d—–w- c:\program files\Google
2009-07-17 19:01 . 2004-08-04 12:00 58880 —-a-w- c:\windows\system32\atl.dll
2009-07-12 04:21 . 2004-08-04 12:00 233472 —-a-w- c:\windows\system32\wmpdxm.dll
2009-07-10 12:31 . 2009-06-11 13:53 130104 —-a-w- c:\windows\system32\sdccoinstaller.dll
2009-07-03 17:09 . 2004-08-04 12:00 915456 ——w- c:\windows\system32\wininet.dll
2009-06-25 08:25 . 2004-08-04 12:00 730112 —-a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2004-08-04 12:00 56832 —-a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2004-08-04 12:00 54272 —-a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2004-08-04 12:00 301568 —-a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2004-08-04 12:00 147456 —-a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2004-08-04 12:00 136192 —-a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2004-08-04 12:00 92928 —-a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-21 05:37 . 2009-06-21 05:37 56 —ha-w- c:\windows\system32\ezsidmv.dat
2009-06-20 07:47 . 2009-06-20 07:47 25280 —-a-w- c:\windows\system32\drivers\hamachi.sys
2009-06-16 14:36 . 2004-08-04 12:00 81920 —-a-w- c:\windows\system32\fontsub.dll
2009-06-16 14:36 . 2004-08-04 12:00 119808 —-a-w- c:\windows\system32\t2embed.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2007-09-19 455968]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-09-03 3342336]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"GBB36X Configure"="c:\windows\system32\JMRaidTool.exe" [2006-07-12 356352]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-04-30 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-04-30 13750272]
"TWCU"="c:\program files\TP-LINK\TWCU\TWCU.exe" [2006-03-29 364544]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb04.exe" [2001-11-29 196608]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2007-03-01 153136]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.exe [2006-07-21 16261632]
"SkyTel"="SkyTel.EXE" - c:\windows\SkyTel.exe [2006-05-16 2879488]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-04-30 1657376]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-13 15360]

c:\documents and settings\William\Start Menu\Programs\Startup\
Xfire.lnk - c:\program files\Xfire\Xfire.exe [2009-9-4 3111824]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - c:\program files\Sophos\AutoUpdate\ALMon.exe [2009-6-11 245760]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService]
@="service"

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SophosAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\Defcon\\defcon.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 2 Demo\\BF2.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\BF2\\EA GAMES\\Battlefield 2\\BF2.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\BF2\\BATTLEFIELD 2 64 PLAYER\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\THQ\\Titan Quest Immortal Throne\\Tqit.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Documents and Settings\\William\\My Documents\\Game Stuff From Desktop\\Halo\\halo.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\rtcshare.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander\\bin\\SupremeCommander.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\Supreme Commander - Forged Alliance\\bin\\ForgedAlliance.exe"=
"c:\\Program Files\\THQ\\Gas Powered Games\\GPGNet\\GPG.Multiplayer.Client.exe"=
"c:\\Program Files\\Savage 2 - A Tortured Soul\\savage2.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

R1 SAVOnAccessControl;SAVOnAccessControl;c:\windows\system32\drivers\savonaccesscontrol.sys [11/06/2009 9:52 PM 110848]
R1 SAVOnAccessFilter;SAVOnAccessFilter;c:\windows\system32\drivers\savonaccessfilter.sys [11/06/2009 9:52 PM 38528]
R2 SAVAdminService;Sophos Anti-Virus status reporter;c:\program files\Sophos\Sophos Anti-Virus\SAVAdminService.exe [7/05/2009 4:12 PM 80936]
S2 SAVService;Sophos Anti-Virus;c:\program files\Sophos\Sophos Anti-Virus\SavService.exe [21/08/2008 1:04 PM 98304]
S4 SophosBootDriver;SophosBootDriver;c:\windows\system32\drivers\SophosBootDriver.sys [11/06/2009 9:52 PM 14976]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
"c:\program files\Common Files\LightScribe\LSRunOnce.exe"
.
Contents of the 'Scheduled Tasks' folder

2009-07-16 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 09:04]

2009-09-12 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 09:04]

2009-09-11 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll [2008-02-22 04:25]

2009-08-29 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe [2008-02-22 04:25]
.
.
——- Supplementary Scan ——-
.
mStart Page = hxxp://www.troner.net/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {784797A8-342D-4072-9486-03C8D0F2F0A1} - hxxps://www.battlefieldheroes.com/static/updater/BFHUpdater_4.0.23.0.cab
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-09-12 15:48
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-746137067-1214440339-725345543-1004\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:c4,38,fb,64,7e,ff,9b,e8,08,6c,08,76,69,10,5b,ce,b9,79,1e,f3,83,27,0f,
73,ae,d5,d9,5a,67,4a,f5,33,dd,60,73,45,70,7f,b6,90,da,0e,b8,a0,15,7c,ab,2b,\
"??"=hex:5e,cb,36,11,96,79,6b,f1,be,ea,9a,20,42,6f,20,95

[HKEY_USERS\S-1-5-21-746137067-1214440339-725345543-1004\Software\SecuROM\License information*]
"datasecu"=hex:17,77,ff,4d,de,24,f3,90,f4,40,3a,cb,28,84,79,e8,02,47,ee,22,15,
06,d9,c1,2f,dd,9f,58,fa,da,a6,08,ac,e6,66,22,ea,f8,8a,e5,b7,b7,80,89,8f,98,\
"rkeysecu"=hex:3e,80,9e,c4,40,b4,90,83,87,8e,33,49,64,ac,f8,d9

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10c.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(3112)
c:\windows\system32\WININET.dll
c:\program files\Xfire\xfire_toucan_39110.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
Completion time: 2009-09-12 15:49
ComboFix-quarantined-files.txt 2009-09-12 07:49
ComboFix2.txt 2009-09-12 07:27

Pre-Run: 792,313,356,288 bytes free
Post-Run: 792,283,553,792 bytes free

226 — E O F — 2009-09-09 15:42

Here's the C:\Qoobox\ComboFix-quarantined-files.txt:

2009-09-12 07:43:04 . 2009-09-12 07:43:05 228 —-a-w- C:\Qoobox\Quarantine\catchme.txt
2009-09-12 07:26:52 . 2009-09-12 07:26:52 102 —-a-w- C:\Qoobox\Quarantine\Registry_backups\HKCU-Run-PlayNC Launcher.reg.dat
2009-09-12 07:20:41 . 2009-09-12 07:20:41 1,398 —-a-w- C:\Qoobox\Quarantine\Registry_backups\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}.reg.dat
2009-09-12 07:20:35 . 2009-09-12 07:46:01 8,622 —-a-w- C:\Qoobox\Quarantine\Registry_backups\tcpip.reg
2009-09-12 07:18:28 . 2009-09-12 07:18:28 61,952 —-a-w- C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir
2009-09-12 07:12:01 . 2009-09-12 07:42:03 289 —-a-w- C:\Qoobox\Quarantine\catchme.log
2007-11-07 00:03:18 . 2007-11-07 00:03:18 562,688 —-a-w- C:\Qoobox\Quarantine\C\install.exe.vir

And I'm afraid the ESET scanner isn't downloading correctly. I'll keep trying; perhaps this is to do with the virus.

No changes with how the computer is running. Thanks.

Puglin,

Please try this Kaspersky Online Scanner since the ESET scanner gave you some trouble.
The below scan can take up to an hour or longer, please be patient.

*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.



Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner

Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.

  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.
Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif

(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%
.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419

- - - - - Next - - - - -

On your next post please provide the following:
  • Kaspersky log

Here's the Kapersky log: ——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Friday, September 18, 2009 Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Thursday, September 17, 2009 09:12:40 Records in database: 2838444 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Objects scanned: 381031 Threats found: 3 Infected objects found: 4 Suspicious objects found: 0 Scan duration: 09:24:03 File name / Threat / Threats count C:\Qoobox\Quarantine\C\WINDOWS\system32\eventlog.dll.vir Infected: Trojan.Win32.Pakes.npx 1 C:\System Volume Information\_restore{76FB0E03-E083-4C4E-AD4C-1D0E63823ED7}\RP105\A0126872.exe Infected: Trojan.Win32.FraudPack.tlr 1 C:\System Volume Information\_restore{76FB0E03-E083-4C4E-AD4C-1D0E63823ED7}\RP105\A0126876.exe Infected: Trojan.Win32.FraudPack.tlr 1 E:\OLD DRIVE\#\ Root\WINDOWS\Downloaded Program Files\gsda.dll Infected: not-a-virus:Downloader.Win32.SpyGame 1 Selected area has been scanned. Took all night to do it, but there it is =). Also, something I should have mentioned earlier, you may have noticed by now that my E:\ drive is a separate hard drive… This used to be my main one, but it got very corrupted a long time ago, so we recovered as much of it as possible, deleted the rest, and now it's just a storage hard drive. Thanks again.

Puglin,

Click HERE to download Pocket Killbox by Option^Explicit

  • Double click KillBox.exe.
  • Select the option Delete on reboot.
  • Now highlight and copy-(press Ctrl + C) for the lists below:

    E:\OLD DRIVE\#\ Root\WINDOWS\Downloaded Program Files\gsda.dll

  • Click File on the killbox menu at the top and choose Paste from Clipboard
  • The entire list should now be in the Full Path of File to Deletefield.
    Note: To check for the file paths that you paste, click on the dropdown-arrow next to that field.
  • Click "All Files" button.
  • Click the Red X, Click Yes when confirmation message appear.
  • A second message will ask to Reboot now? You will need to click Yes to allow the reboot.
Note: Killbox will let you know if a file does not exist.

- - - - - Next - - - - -

Please download ATF Cleaner by Atribune.
Download - http://www.nutnworks.com/downloads/ATF_Cleaner.exe
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

- - - - - Next - - - - -

Please download Malwarebytes' Anti-Malware from Here or Here
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
- - - - - Next - - - - -

On your next post please provide the following:
  • MBAM log
  • Tell me how your computer is running at the moment.

Huh. MBAM says that no malicious items were detected. That's odd. Here's the log: Malwarebytes' Anti-Malware 1.41 Database version: 2819 Windows 5.1.2600 Service Pack 3 18/09/2009 7:24:35 PM mbam-log-2009-09-18 (19-24-35).txt Scan type: Quick Scan Objects scanned: 116479 Time elapsed: 3 minute(s), 18 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)

Puglin,

Your log shows you have/had a P2P program installed called BitTorrent. Please see this topic for more information:
Perils of P2P File Sharing

P2P programs may themselves be safe, but the files shared within cannot be gaurantteed to be free of malware. There is a good chance this is how you
got infected in the first place.

I would recommend that you uninstall BitTorrent, however that choice is up to you.
If you wish to keep it, please do not use it until your computer is cleaned.

To remove BitTorrent please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:

  • BitTorrent
Select the program, then select remove.
(if the program is not listed don't be alarmed, just continue)
NOTE: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

- - - - - Next - - - - -

Please locate the folder in red and delete it and it's entire contents.
Be sure to delete the entire folder that is designated.
  • c:\documents and settings\william\application data\BitTorrent
Right click the file or folder, select Delete.

- - - - - Next - - - - -

On your next post please tell me how your computer is running at the moment.
Are there any remaining issues?

God yes. I've still got all those infected files. And my antivirus still won't start. MBAM just didn't find anything, which is wierd. Maybe something to do with the fact that this trojan is so good at killing antivirus's.

Puglin,

God yes. I've still got all those infected files. And my antivirus still won't start. MBAM just didn't find anything, which is wierd. Maybe something to do with the fact that this trojan is so good at killing antivirus's.

All the logs and scans we have done to this point do not show any infected files. Can you please tell me where they are located on your computer?

When you try to launch your Anti-Virus software do you recieve any error message, if so what is it?

Have you tried uninstalling your AV software and reinstalling it. Sometimes during the removal of malware files can become corrupt, reinstalling can sometimes correct this situation.

Well, on the last scan I did before MBAM, it said I had something like four or five infected files… Haven't I only deleted one of those? I JUST tried reinstalling AV, and it wouldn't even let me do that. There's GOT to be something still there, surely.

Puglin,

Well, on the last scan I did before MBAM, it said I had something like four or five infected files… Haven't I only deleted one of those? No, I haven't tried reinstalling my AV.

The files you are referring to will be removed during the clean up steps.

- - - - - Next - - - - -

It is imperative that you don't surf the Internet unprotected. You need to have a working Anti-Virus program running.
If you haven't already done so please uninstall your AV software.

Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:
  • Sophos Anti-Virus
  • Sophos AutoUpdate
Select each one of the programs, then select remove.

Exit the Control Panel when finished.

- - - - - Next - - - - -

Reboot, and try and re-install it to see if that corrects the problem.

- - - - - Next - - - - -

If you still cannot get your AV to work here are few you might like to try:

Anti - Virus:
- - - - - Next - - - - -

Your logs appear to be clean. :thumbup:

I don't see any evidence of a Firewall on your computer.
If you do not have a Firewall installed please go to one of the links below and download and install a Firewall.
This must be taken care of first.

Firewall:
- - - - - Next - - - - -

We have a little housekeeping to do before we are finished.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.

[external image: Posted Image]

The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.
- - - - - Next - - - - -

You can delete the tools we downloaded: (they should be located on your desktop)
  • DDS
  • RootRepeal
  • Pocket Killbox
- - - - - Next - - - - -

Here comes the "All Clean Speech":

You need to set a new clean System Restore Point

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points
We need to set a new system restore point:

Click Start > Run > copy and paste the following into the run box:


%SystemRoot%\System32\restore\rstrui.exe

Press OK. Choose Create a Restore Point then click Next.
Name it (something you'll remember) and click Create,
when the confirmation screen shows the restore point has been created click Close.

- - - - - Next - - - - -

Now remove all previous Restore Points:

Click Start > Run > copy and paste the following into the run box:


cleanmgr

At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.

- - - - - Next - - - - -

Here are some tips to reduce the potential for spyware infection in the future:

Automatic Updates:

The easiest way to ensure you don't miss any of the critical Windows Updates is to set your computer up to receive Automatic Updates.
To set your computer up for Automatic Updates please do the following:
  • Click Start, and then click Control Panel.
  • Depending on which Control Panel view you use, Classic or Category, do one of the following:
  • Click System, and then click the Automatic Updates tab.
  • Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
  • Select Automatic and choose a frequency and time that's convenient for you to get the updates.
  • Click Apply, then OK
  • Close the Control Panel.
- - - - - Next - - - - -

Make your Internet Explorer more secure - This can be done by following these simple instructions:

  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

You are using Sophos Anti-Virus as your anti virus software. It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Firewall I cannot stress how important it is that you keep the Firewall on your computer active at all times. Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls

Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

MVPS Hosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer, meaning it will be difficult to infect yourself in the future.

Keep a backup of your important files - Now, more than ever, it's especially important to protect your digital files and memories. This article is full of good information on alternatives for home backup solutions.

ERUNT (Emergency Recovery Utility NT) allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed.

Update all security programs regularly - Make sure you update all the programs regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.

Remember to have only one (1) Firewall and one (1) Anti-Virus program running at any one time.

I would also suggest you read "So how did I get infected in the first place"?: by Tony Klein

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.

Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI