This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Problems found on laptop

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings,

I've been reading through various topics in this forum this morning and decided I'd do an online scan using Eset on my laptop which I've suspected may have had problems (runs slow at times etc…). Eset found a few problems and I thought it may be wise to do a HijackThis scan and submit here to see if I can sort this out. Any help appreciated. Following is the report from Eset followed. It may be worthwhile mentioning that I was recently infected with the fake anti virus malware which I successfully removed after following instructions here via self-help.

Thanks in advance.


——

C:\Documents and Settings\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll a variant of Win32/Sefnit.AS trojan
C:\Documents and Settings\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P93G09RN\index[1].htm JS/Agent.NCX trojan
C:\Documents and Settings\Phil\AppData\Roaming\92429\bbzzkzz18.exe a variant of Win32/Kryptik.KZR trojan
C:\Documents and Settings\Phil\AppData\Roaming\92429\mscjm.exe Win32/VB.AAQC trojan
C:\Documents and Settings\Phil\AppData\Roaming\92429\pdmn2.exe a variant of Win32/Sefnit.AS trojan
C:\Documents and Settings\Phil\AppData\Roaming\92429\recf.exe Win32/VB.PPR trojan
C:\Program Files\Online Services\Dodo\Dodo.EXE probably a variant of Win32/Hupigon.MCYZRIA trojan
C:\Users\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll a variant of Win32/Sefnit.AS trojan
C:\Users\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P93G09RN\index[1].htm JS/Agent.NCX trojan
C:\Users\Phil\AppData\Roaming\92429\bbzzkzz18.exe a variant of Win32/Kryptik.KZR trojan
C:\Users\Phil\AppData\Roaming\92429\mscjm.exe Win32/VB.AAQC trojan
C:\Users\Phil\AppData\Roaming\92429\pdmn2.exe a variant of Win32/Sefnit.AS trojan
C:\Users\Phil\AppData\Roaming\92429\recf.exe Win32/VB.PPR trojan

——

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:20:04, on 19/03/2011
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.17037)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\System32\hkcmd.exe
C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\totalcmd\TOTALCMD.EXE
C:\Program Files\ESET\ESET Online Scanner\OnlineScannerApp.exe
C:\archive\Utils\Security\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.telstra.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telstra BigPond Home Internet Explorer
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe -expressboot
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\iexplore.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: HP Health Check Service - Hewlett-Packard - C:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

–
End of file - 6610 bytes
Hi,

:welcome:

My name is NoodleTech. I would be glad to take a look at your log and help you with solving any malware problems. Logs can take a while to research, so please be patient and I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clean. Absence of symptoms does not mean that everything is clean.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
===================================================

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
===================================================

Refer to the ComboFix User's Guide

  • Download ComboFix from one of these locations:

    Link 1
    Link 2

    * IMPORTANT !!! Place ComboFix.exe on your  Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.


    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: 
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.


    ———————————————————————————————
G'Day Noodletech - Thanks for helping me out :)

Below are the 2 logs requested. Also, I am located on the west coast of Australia and as such is 15 hours ahead of you, so there may be a delay or 2 - please hang in there as I'll reply as promptly as I can :)


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6105

Windows 6.0.6000
Internet Explorer 7.0.6000.17037

19/03/2011 19:47:41
mbam-log-2011-03-19 (19-47-41).txt

Scan type: Quick scan
Objects scanned: 172006
Time elapsed: 6 minute(s), 12 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 6

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\AntiVirus AntiSpyware 2011 (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
c:\Users\Phil\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus antispyware 2011 (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.

Files Infected:
c:\Users\Denise\downloads\yontooclientsetup.exe (Adware.Agent) -> Quarantined and deleted successfully.
c:\Users\Phil\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus antispyware 2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\Phil\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus antispyware 2011\help antivirus antispyware 2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\Phil\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus antispyware 2011\activate antivirus antispyware 2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\Phil\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus antispyware 2011\antivirus antispyware 2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\Phil\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus antispyware 2011\how to activate antivirus antispyware 2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.

——

ComboFix 11-03-18.03 - Phil 19/03/2011 19:53:30.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.61.1033.18.1013.430 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Phil\AppData\Roaming\AntiVirus AntiSpyware 2011
c:\users\Phil\AppData\Roaming\AntiVirus AntiSpyware 2011\IcoActivate.ico
c:\users\Phil\AppData\Roaming\AntiVirus AntiSpyware 2011\IcoHelp.ico
c:\users\Phil\AppData\Roaming\AntiVirus AntiSpyware 2011\IcoUninstall.ico
c:\windows\system32\drivers\pobasxt.sys
c:\windows\system32\midas.dll
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
——-\Service_hmfv
.
.
((((((((((((((((((((((((( Files Created from 2011-02-19 to 2011-03-19 )))))))))))))))))))))))))))))))
.
.
2011-03-19 12:03 . 2011-03-19 12:03 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-03-19 12:03 . 2011-03-19 12:03 ——– d—–w- c:\users\Denise\AppData\Local\temp
2011-03-19 12:03 . 2011-03-19 12:03 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-03-18 21:39 . 2011-03-18 21:39 ——– d—–w- c:\program files\ESET
2011-03-03 10:40 . 2011-03-09 12:41 16856 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-03-03 10:40 . 2011-03-09 12:41 719832 —-a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-02-26 08:14 . 2011-02-26 08:14 ——– d—–w- c:\users\Phil\AppData\Roaming\WinPatrol
2011-02-25 16:39 . 2011-02-25 16:39 ——– d—–w- c:\users\Phil\AppData\Local\DRMNetVdm
2011-02-25 16:38 . 2011-02-26 04:44 ——– d—–w- c:\users\Phil\AppData\Roaming\92429
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 10:09 . 2009-09-28 01:40 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 10:08 . 2009-09-28 01:40 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-02-26 126976]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-02-26 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-02-26 151552]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
"Taskman"=""
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 14:16 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2006-12-04 20:39 46704 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 07:11 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-02-17 00:15 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2006-12-03 00:32 167936 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 09:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2007-03-12 10:30 517768 —-a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\DRIVERS\cmusbnet.sys [2007-06-22 87424]
R3 cmusbser;%CMUSBSER%;c:\windows\system32\DRIVERS\cmusbser.sys [2007-06-06 87040]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2006-12-18 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2006-12-18 43904]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-26 136176]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-19 c:\windows\Tasks\User_Feed_Synchronization-{262EF333-8AD9-4D3F-BAC2-9C1A14ACD25C}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - Ext: English (Australian) Dictionary: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: FoxClocks: {d37dc5d0-431d-44e5-8c91-49419370caa1} - %profile%\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
FF - Ext: Xmarks: [removed] - %profile%\extensions\[removed]
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
- - - - ORPHANS REMOVED - - - -
.
WebBrowser-{9565115D-C7D6-46D3-BD63-B67B481A4368} - (no file)
HKLM-Run-WAWifiMessage - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
MSConfigStartUp-hpWirelessAssistant - %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
MSConfigStartUp-QlbCtrl - %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
MSConfigStartUp-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
MSConfigStartUp-swg - c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
MSConfigStartUp-YSearchProtection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
.
.
.
**************************************************************************
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files:
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1887573329-3531065527-3000446172-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65E25B5F-E841-2FFB-020C-010B023471FD}*]
"kapajeflmlmnnlofcmdihn"=hex:66,61,62,61,6d,6c,6c,6b,63,65,64,66,00,63
"kapajeflmlmnnlofcmdiin"=hex:67,61,62,62,64,65,6c,6b,70,6a,6c,63,6f,61,00,00
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
——————— DLLs Loaded Under Running Processes ———————
.
- - - - - - - > 'Explorer.exe'(2748)
c:\windows\system32\btncopy.dll
.
———————— Other Running Processes ————————
.
c:\program files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
c:\program files\Common Files\LightScribe\LSSrvc.exe
c:\windows\system32\DRIVERS\xaudio.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\HP\QuickPlay\Kernel\TV\CLSched.exe
c:\program files\Hewlett-Packard\HP Health Check\hphc_service.exe
c:\windows\system32\wbem\unsecapp.exe
c:\windows\ehome\ehmsas.exe
c:\program files\WIDCOMM\Bluetooth Software\BtStackServer.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\RacAgent.exe
c:\windows\system32\lpremove.exe
c:\windows\system32\lpksetup.exe
.
**************************************************************************
.
Completion time: 2011-03-19 20:21:24 - machine was rebooted
ComboFix-quarantined-files.txt 2011-03-19 12:20
.
Pre-Run: 11,800,752,128 bytes free
Post-Run: 11,560,681,472 bytes free
.
- - End Of File - - 226BB395BA1266FA69E277D23F54413E
Hi busdriver12,

No worries!

Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
C:\Documents and Settings\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll	
C:\Documents and Settings\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P93G09RN\index[1].htm	
C:\Documents and Settings\Phil\AppData\Roaming\92429\bbzzkzz18.exe	
C:\Documents and Settings\Phil\AppData\Roaming\92429\mscjm.exe	
C:\Documents and Settings\Phil\AppData\Roaming\92429\pdmn2.exe	
C:\Documents and Settings\Phil\AppData\Roaming\92429\recf.exe	
C:\Program Files\Online Services\Dodo\Dodo.EXE	
C:\Users\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll	
C:\Users\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P93G09RN\index[1].htm
C:\Users\Phil\AppData\Roaming\92429\bbzzkzz18.exe	
C:\Users\Phil\AppData\Roaming\92429\mscjm.exe	
C:\Users\Phil\AppData\Roaming\92429\pdmn2.exe	
C:\Users\Phil\AppData\Roaming\92429\recf.exe
Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe


Then post the results log using Copy / Paste

How is your computer running now?

How is your computer running now?


It's running fairly good now. I did a bit of research on the malware ESET found and may ask a couple of questions afterwards once we have this all sorted out :)

Out of interest, there was a message from ComboBox that it couldn't save a combobox.txt file and asked permission to upload some files to it's server for analysis which I granted. It did save a log file and here it is:


——

ComboFix 11-03-18.03 - Phil 19/03/2011 22:29:49.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.61.1033.18.1013.500 [GMT 8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\users\Phil\Desktop\CFScript.txt
.
FILE ::
"c:\documents and settings\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll"
"c:\documents and settings\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P93G09RN\index[1].htm"
"c:\documents and settings\Phil\AppData\Roaming\92429\bbzzkzz18.exe"
"c:\documents and settings\Phil\AppData\Roaming\92429\mscjm.exe"
"c:\documents and settings\Phil\AppData\Roaming\92429\pdmn2.exe"
"c:\documents and settings\Phil\AppData\Roaming\92429\recf.exe"
"c:\program files\Online Services\Dodo\Dodo.EXE"
"c:\users\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll"
"c:\users\Phil\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P93G09RN\index[1].htm"
"c:\users\Phil\AppData\Roaming\92429\bbzzkzz18.exe"
"c:\users\Phil\AppData\Roaming\92429\mscjm.exe"
"c:\users\Phil\AppData\Roaming\92429\pdmn2.exe"
"c:\users\Phil\AppData\Roaming\92429\recf.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Online Services\Dodo\Dodo.EXE
c:\users\Phil\AppData\Local\DRMNetVdm\smpWebSched.dll
c:\users\Phil\AppData\Roaming\92429\bbzzkzz18.exe
c:\users\Phil\AppData\Roaming\92429\mscjm.exe
c:\users\Phil\AppData\Roaming\92429\pdmn2.exe
c:\users\Phil\AppData\Roaming\92429\recf.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-02-19 to 2011-03-19 )))))))))))))))))))))))))))))))
.
.
2011-03-19 14:41 . 2011-03-19 14:41 ——– d—–w- c:\users\Guest\AppData\Local\temp
2011-03-19 14:41 . 2011-03-19 14:41 ——– d—–w- c:\users\Denise\AppData\Local\temp
2011-03-19 14:41 . 2011-03-19 14:41 ——– d—–w- c:\users\Default\AppData\Local\temp
2011-03-18 21:39 . 2011-03-18 21:39 ——– d—–w- c:\program files\ESET
2011-03-03 10:40 . 2011-03-09 12:41 16856 —-a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2011-03-03 10:40 . 2011-03-09 12:41 719832 —-a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2011-02-26 08:14 . 2011-02-26 08:14 ——– d—–w- c:\users\Phil\AppData\Roaming\WinPatrol
2011-02-25 16:39 . 2011-03-19 14:41 ——– d—–w- c:\users\Phil\AppData\Local\DRMNetVdm
2011-02-25 16:38 . 2011-03-19 14:41 ——– d—–w- c:\users\Phil\AppData\Roaming\92429
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-12-20 10:09 . 2009-09-28 01:40 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-12-20 10:08 . 2009-09-28 01:40 20952 —-a-w- c:\windows\system32\drivers\mbam.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2006-11-02 125440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-15 815104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-02-26 126976]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-02-26 131072]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-02-26 151552]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2009-10-10 320832]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2006-11-3 703280]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
%ProgramFiles%\Windows Defender\MSASCui.exe -hide [X]
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-01-11 14:16 39792 —-a-w- c:\program files\Adobe\Reader 8.0\Reader\reader_sl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Health Check Scheduler]
2006-12-04 20:39 46704 —-a-w- c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
2005-02-17 07:11 49152 —-a-w- c:\program files\HP\HP Software Update\hpwuSchd2.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-02-17 00:15 81920 —-a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QPService]
2006-12-03 00:32 167936 —-a-w- c:\program files\HP\QuickPlay\QPService.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-29 09:38 421888 —-a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec PIF AlertEng]
2007-03-12 10:30 517768 —-a-w- c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\DRIVERS\cmusbnet.sys [2007-06-22 87424]
R3 cmusbser;%CMUSBSER%;c:\windows\system32\DRIVERS\cmusbser.sys [2007-06-06 87040]
R3 R5U870FLx86;R5U870 UVC Lower Filter ;c:\windows\system32\Drivers\R5U870FLx86.sys [2006-12-18 73472]
R3 R5U870FUx86;R5U870 UVC Upper Filter ;c:\windows\system32\Drivers\R5U870FUx86.sys [2006-12-18 43904]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-02-26 136176]
.
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - CFCATCHME
*Deregistered* - CFcatchme
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
.
Contents of the 'Scheduled Tasks' folder
.
2011-03-19 c:\windows\Tasks\User_Feed_Synchronization-{262EF333-8AD9-4D3F-BAC2-9C1A14ACD25C}.job
- c:\windows\system32\msfeedssync.exe [2006-11-02 09:45]
.
.
——- Supplementary Scan ——-
.
uStart Page = about:blank
mStart Page = hxxp://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
IE: Send image to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth; Device… - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
FF - ProfilePath - c:\users\Phil\AppData\Roaming\Mozilla\Firefox\Profiles\ur2n5gm0.default\
FF - prefs.js: browser.startup.homepage - about:blank
FF - Ext: English (Australian) Dictionary: [removed] - %profile%\extensions\[removed]
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: FoxClocks: {d37dc5d0-431d-44e5-8c91-49419370caa1} - %profile%\extensions\{d37dc5d0-431d-44e5-8c91-49419370caa1}
FF - Ext: Xmarks: [removed] - %profile%\extensions\[removed]
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-03-19 22:41
Windows 6.0.6000 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_USERS\S-1-5-21-1887573329-3531065527-3000446172-1000\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65E25B5F-E841-2FFB-020C-010B023471FD}*]
"kapajeflmlmnnlofcmdihn"=hex:66,61,62,61,6d,6c,6c,6b,63,65,64,66,00,63
"kapajeflmlmnnlofcmdiin"=hex:67,61,62,62,64,65,6c,6b,70,6a,6c,63,6f,61,00,00
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\system\ControlSet003\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2011-03-19 22:44:10
ComboFix-quarantined-files.txt 2011-03-19 14:44
ComboFix2.txt 2011-03-19 12:21
.
Pre-Run: 11,912,515,584 bytes free
Post-Run: 11,863,994,368 bytes free
.
- - End Of File - - AB9A188D29300D07FACF589971823FA8
Hi busdriver12, Your combofix log looks good. Don't worry about the popup message. Can you give ESET another run and see if it finds anything? And what questions do you have?
G'Day NoodleTech,

The online scan had to be stopped after 40 mins (didn't take that long the first time) with just over 50% scanned with nothing found. All the threats were found a lot earlier than this so it looks like the laptop is clean.

My questions related to the trojans found. From my research they try to steal credit card info/passwords etc, but I cannot see any problems as any thing of a financial nature is always done using a secure connection (i.e. https://…). All our mail is done via web i.e. no pop mail plus I don't use any standard MS programs for everyday stuff (such as Outlook etc…). Having said this, I don't think these trojans would find anything and I don't feel overly worried about them. Does that gel with what you know of these trojans?

As I have to get to bed and get up for work in the morning, I did not have time to let ESET run it's course, so I will do so when I get home from work which should be in about 18 hours from now. I'll let you know how it goes and hopefully you can close this thread.

Many thanks for your help so far :)
Hi busdriver12, My pleasure :) A secure connection protects your information after you have typed it in and hit send. Password stealing trojans steal your information by logging keystrokes as you type. This has nothing to do with a secure connection. In addition, there's always the chance that secure connections can be compromised. In your situation, I would take preventive measures by changing your financial and banking account passwords. You can never be too safe. Post the results of the ESET scan when you can.

A secure connection protects your information after you have typed it in and hit send. Password stealing trojans steal your information by logging keystrokes as you type. This has nothing to do with a secure connection. In addition, there's always the chance that secure connections can be compromised.

In your situation, I would take preventive measures by changing your financial and banking account passwords. You can never be too safe.


Ah keyloggers, of course (slaps head!). I can confidently say that my bank accounts will be fine as it's an extra machine that we use and I haven't accessed my banking web site with that machine for a couple of years :)


Post the results of the ESET scan when you can.


I'm scanning now while I'm getting ready for work so hopefully will get it done before I head off to work.
I ran a scan after work and it found no threats and did not offer a log file. I take that as a clean bill of health?

On another note, I don't intend to delete the ESET scan as I'll run it from time to time along with Malwarebytes to make sure all is OK.

If that's it, once again thank you very much for your help. :)
Hi busdriver12,

Yes, your computer appears to be clean! Leaving Malwarebytes and ESET is a good idea, but we have to uninstall ComboFix.


Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now copy/paste Combofix /uninstall into the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

===================================================

I notice that you are not running any anti-virus software. It is important to have anti-virus software installed on your computer to actively protect you against malicious software and security threats.

Please download Microsoft Security Essentials, a free anti-malware program.
Link

Double click mseinstall.exe to start the installation.

Follow the prompts to install and update the program.

===================================================

Your version of Windows Vista is out of date. Please click here to download Service Pack 2. Double click Windows6.0-KB948465-X86.exe to install it.

===================================================

Update Adobe Reader
Earlier versions of Adobe Reader have known security flaws so it is recommended that you update your copy
  • Go to Start > Control Panel > Add/Remove Programs
  • Remove ALL instances of Adobe Reader
  • Re-boot your computer as required.
  • Once ALL versions of Adobe Reader have been uninstalled, visit: <> and download the latest version of Adobe Reader
Alternative Option: after uninstalling Adobe Reader, you could try installing Foxit Reader from >here< Foxit Reader has fewer add-ons therefore loads more quickly.

===================================================

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 23.
  • Scroll down to where it says "The Java SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • In the pull down menu next to Platform select Windows
  • Check the box that says: "I agree to the Java SE Runtime Environment 6 License Agreement"
  • Click Continue
  • Click on the link to download Windows Offline Installation and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u23-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon. [external image: Posted Image]
  • Under Temporary Internet Files, click the Settings… button
  • click the Delete Files button.
  • There are three options in the window to clear the cache - Leave all 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Temporary Files Settings
  • Click OK to leave the Java Control Panel.
===================================================

Here are some tips to reduce the potential for spyware infection in the future:

1. Make your Internet Explorer More Secure
  • Click Start > Run
  • Type Inetcpl.cpl and click OK
  • Click on the Security tab
  • Click Reset all zones to default level
  • Make sure the Internet Zone is selected and Click Custom level
  • In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to Prompt, and ("Initialize and Script ActiveX controls not marked as safe") to Disable.
  • Next Click OK, then Apply button and then OK to exit the Internet Properties page.
2. Update your Anti-Virus Software - I can not overemphasize the need for you to update your Anti-virus application on a regular basis.  With the ever increasing number of new variants of malware arriving on the scene daily, you become very susceptible to an attack without updated protection.

3. Make sure you keep your Windows OS current by visiting Windows update   regularly to download and install any critical updates and service packs. Without these you are leaving the back door open.

4. Consider a custom hosts file such as MVPS HOSTS. This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.
For information on how to download and install, please read this tutorial by WinHelp2002
Note: Be sure to follow the instructions to disable the DNS Client service before installing a custom hosts file.

5. Finally, I strongly recommend that you read TonyKlein's good advice So how did I get infected in the first place?
G'Day NoodleTech,

Thanks for the extensive reply - I've just gotten up and have to go to work soon, so will have a thorogh read of your post when I get home. I do have a couple of questions/comments but will do that then when I have more time.

Once again Thank You Very Much for all the time and effort you've put into this small problem of mine. :)
G'Day NoodleTech,

I've been through your recommendations and all have been carried out. I had to install Vista SP1 before SP2 so that added to the ongoing delays. However, all appears to be good!

As an aside, this laptop was purchased in 2007 for a road trip around Australia and since we returned home in 2008 it was in the hands of a teenager for approx a year. Once she relinquished control is sat in a corner rarely used and I assume missed out on a lot of updates etc due to it's lack of use. I'll now have to be more vigilant and manually update some stuff to make sure everything is up to date. I've discovered I had 1 unused license for Kaspersky Internet Suite which I've used to install on my laptop (I use it on my main desktop PC). Still reading up on the HOSTS file info and will get to that as time allows.

I take it the machine is now clean or is there any more scans you want me to do before marking this problem solved?

Thanks very much for your time and patience :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI