This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Trojan Dropper Agent GIT and maybe more?

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.


___________________________________
Search forA FILE/FOLDER FOR ME
Now I want you to search for AND LET ME KNOW IF THIS if present. If you need help finding it
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just report what you find for me BOLD

C:\WINDOWS\system32\vtsqp I am assuming this is a folder but may be a file with an unknown extension.

Just let me know what you find .
search found 3 instances of vtsqp.dll
and one instance of vtsqp.dll.vir

- one in C:\WINDOWS\system32
-one in the zip file from combofix sent to bleepingcomputer
- one in C:\Qoobox\Quarintine\catchme zip

the. dll.vir file was found in C:\Qoobox\Quarintine\C\WINDOWS\system32
Let me be certain .
The on in
C:\WINDOWS\system32 was vtsqp.dll it was a file not a folder

Did you physically look in system32 for a folder called vtsqp
Copy this to a text documnet on your desktop .

Just before you drag and drop this file to get combo to run I want you to physically disconnect from the internet.
PULL THE PLUG.

Once combo has finished and puts up the log you may reconnect to the internet to post for me.

________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

Killall::

File::
C:\WINDOWS\system32\pqstv.ini

Rootkit::
C:\WINDOWS\system32\vtsqp.dll

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{001A22EE-E54A-44B7-BBA2-043C933C8622}]



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.


_________________________
In your next reply I would like to see:
  • A new HJT log
  • The report from ComboFix
Okay, run as instructed, plug pulled from wall … still saw McAfee go off finding vtsqp.exe and 2 .tmp files at stage 3 of combofix, then after reboot again same files found by McAfee… this thing appears to fire anytime using a Windows explorer function

Here are logs

ComboFix 08-01-23.1B - acerveny 2008-01-24 21:10:20.7 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.207 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\acerveny.REALHEALTH\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\WINDOWS\system32\pqstv.ini
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\pqstv.ini2
C:\WINDOWS\system32\vtsqp.dll

.
((((((((((((((((((((((((( Files Created from 2007-12-25 to 2008-01-25 )))))))))))))))))))))))))))))))
.

2008-01-24 21:17 . 2008-01-24 21:17 318 –ahs—- C:\WINDOWS\system32\pqstv.ini
2008-01-24 21:16 . 2008-01-24 21:16 336,384 ——— C:\WINDOWS\system32\vtsqp.dll
2008-01-24 11:13 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\Nircmd.exe
2008-01-24 08:59 . 2008-01-24 08:59 0 –a—— C:\backup.reg
2008-01-24 08:57 . 2008-01-24 08:57 126,976 –a—— C:\zip.exe
2008-01-24 08:57 . 2008-01-24 08:57 292 –a—— C:\avexport.bat
2008-01-23 11:30 . 2008-01-23 11:30 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-23 11:16 . 2008-01-23 11:16 d——– C:\Program Files\CCleaner
2008-01-23 10:53 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-23 10:53 . 2007-01-11 10:34 211 –a—— C:\Boot.bak
2008-01-17 10:58 . 2008-01-17 10:58 d——– C:\Binaries
2008-01-17 10:54 . 2008-01-17 10:57 d——– C:\Program Files\ESM
2008-01-15 10:32 . 2008-01-15 10:32 593 –a—— C:\WINDOWS\system32\DWRCCMDError.ini
2008-01-15 10:19 . 2008-01-24 09:01 d——– C:\Program Files\noname
2008-01-15 09:54 . 2008-01-15 16:58 d——– C:\TEMP
2008-01-15 09:54 . 2008-01-15 09:54 d——– C:\Sun
2008-01-12 22:19 . 2008-01-24 21:16 d——– C:\QUARANTINE
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Real
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\xing shared
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-25 05:16 ——— d—–w C:\Program Files\NetWaiting
2008-01-25 05:16 ——— d—–w C:\Program Files\LivePerson
2008-01-23 18:31 ——— d—–w C:\Program Files\Apoint
2008-01-17 01:30 ——— d—–w C:\Program Files\Trillian
2008-01-16 00:04 ——— d—–w C:\Program Files\Java
2008-01-13 07:02 ——— d—–w C:\Program Files\QuickTime
2007-11-14 07:26 450,560 ——w C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-07 09:26 721,920 —-a-w C:\WINDOWS\system32\lsasrv.dll
2007-11-07 09:26 721,920 ——w C:\WINDOWS\system32\dllcache\lsasrv.dll
2007-10-30 17:20 360,064 ——w C:\WINDOWS\system32\dllcache\tcpip.sys
2007-10-30 09:55 3,065,856 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\system32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\system32\dllcache\quartz.dll
2007-10-28 01:40 222,720 —-a-w C:\WINDOWS\system32\wmasf.dll
2007-10-28 01:40 222,720 ——w C:\WINDOWS\system32\dllcache\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\system32\dllcache\shell32.dll
2007-01-19 01:08 5,971,432 —-a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-19 00:31 5,274,776 —-a-w C:\Program Files\ps2pdf995.exe
2007-01-19 00:04 6,563,928 —-a-w C:\Program Files\cuteftp.exe
.

((((((((((((((((((((((((((((( snapshot@2008-01-24_11.44.42.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-24 19:14:26 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-25 05:08:53 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-24 19:14:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-25 05:08:53 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-24 19:14:26 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-25 05:08:53 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-24 19:14:26 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-25 05:08:53 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-24 19:14:26 4,206,592 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-25 05:08:54 4,239,360 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
- 2008-01-24 19:14:26 217,088 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
+ 2008-01-25 05:08:54 217,088 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-24 19:36:52 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-25 05:03:26 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-24 19:36:52 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-25 05:03:26 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
- 2008-01-24 19:42:19 16,384 —-a-w C:\WINDOWS\TEMP\Cookies\index.dat
+ 2008-01-25 05:16:56 16,384 —-a-w C:\WINDOWS\TEMP\Cookies\index.dat
- 2008-01-24 19:42:19 16,384 —-a-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
+ 2008-01-25 05:16:56 16,384 —-a-w C:\WINDOWS\TEMP\History\History.IE5\index.dat
- 2008-01-24 19:42:22 32,768 —-a-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
+ 2008-01-25 05:16:56 32,768 —-a-w C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B919FBEF-A907-4543-99A2-05122D5E0DEA}]
2008-01-24 21:16 336384 ——— C:\WINDOWS\system32\vtsqp.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"="C:\Program Files\NetWaiting\netWaiting .exe" [ ]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [ ]
"Broadcom Wireless Manager UI"="C:\WINDOWS\system32\WLTRAY.exe" [ ]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 282624 C:\WINDOWS\stsystra.exe]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"ShStatEXE"="C:\Applications\VScan\SHSTAT.exe" [2006-11-30 08:50 112216]
"McAfeeUpdaterUI"="C:\Applications\Common Framework\UdaterUI.exe" [ ]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [ ]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [ ]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [ ]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [ ]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [ ]

C:\Documents and Settings\benito.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]

C:\Documents and Settings\acerveny.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]

[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=C:\WINDOWS\system32\vtsqp.exe

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\WINDOWS\system32\vtsqp


.
Contents of the 'Scheduled Tasks' folder
"2007-02-12 17:33:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-24 21:17:32
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\WINDOWS\Explorer.EXE [6.00.2900.3156]
-> C:\WINDOWS\system32\vtsqp.dll
.
Completion time: 2008-01-24 21:20:05 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-25 05:20:00
ComboFix2.txt 2008-01-24 19:45:23
ComboFix3.txt 2008-01-24 01:04:13
.
2008-01-10 01:28:32 — E O F —


HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 21:28, on 2008-01-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\DWRCST.exe
C:\Program Files\NetWaiting\netWaiting .exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LivePerson\hc.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\noname\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
F3 - REG:win.ini: load=C:\WINDOWS\system32\vtsqp.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Applications\VScan\scriptcl.dll
O2 - BHO: (no name) - {B919FBEF-A907-4543-99A2-05122D5E0DEA} - C:\WINDOWS\system32\vtsqp.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask .exe" -atboottime
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Applications\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting .exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: LivePerson.lnk = C:\Program Files\LivePerson\hc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Applications\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
________________________________________
Open notepad and copy/paste the text in the quotebox below into it:

KillAll::

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B919FBEF-A907-4543-99A2-05122D5E0DEA}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ModemOnHold"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"=-
"Broadcom Wireless Manager UI"=-
"DVDLauncher"=-
"QuickTime Task"=-
"McAfeeUpdaterUI"=-
"igfxtray"=-
"igfxhkcmd"=-
"igfxpers"=-
"TkBellExe"=-
"SunJavaUpdateSched"=-
[HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\windows]
"load"=-
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
"Authentication Packages"=hex(7):6d,73,76,31,5f,30,00,00

File::

C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\vtsqp.dll
C:\Program Files\NetWaiting\netWaiting.exe



NOTE: This script was done for this user specifically.
DO NOT ATTEMPT TO USE IT IF YOU ARE NOT THIS USER
YOU WILL HURT THE WORKINGS OF YOUR COMPUTER !!
.

Save this as CFScript.txt, in the same location as ComboFix.exe


[external image: Posted Image]

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:ComboFix.txt which I will need in your next reply.

_____________________________________

Post a new HJT log also.
OK! certainly feels better…., McAfee did not light up like before, probably good sign!

Here are logs:

ComboFix 08-01-23.1C - acerveny 2008-01-25 17:33:12.9 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.202 [GMT -8:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\acerveny.REALHEALTH\Desktop\CFScript.txt
* Created a new restore point

FILE
C:\Program Files\NetWaiting\netWaiting.exe
C:\WINDOWS\system32\pqstv.ini
C:\WINDOWS\system32\vtsqp.dll
.

((((((((((((((((((((((((( Files Created from 2007-12-26 to 2008-01-26 )))))))))))))))))))))))))))))))
.

2008-01-25 17:11 . 2000-08-31 08:00 51,200 –a—— C:\WINDOWS\Nircmd.exe
2008-01-25 17:09 . 2008-01-25 17:31 d——– C:\Program Files\Trend Micro
2008-01-24 08:59 . 2008-01-24 08:59 0 –a—— C:\backup.reg
2008-01-23 11:30 . 2008-01-23 11:30 d——– C:\WINDOWS\system32\Kaspersky Lab
2008-01-23 10:53 . 2004-08-03 23:00 260,272 –a—— C:\cmldr
2008-01-23 10:53 . 2007-01-11 10:34 211 –a—— C:\Boot.bak
2008-01-17 10:58 . 2008-01-17 10:58 d——– C:\Binaries
2008-01-17 10:54 . 2008-01-17 10:57 d——– C:\Program Files\ESM
2008-01-15 10:32 . 2008-01-15 10:32 593 –a—— C:\WINDOWS\system32\DWRCCMDError.ini
2008-01-15 09:54 . 2008-01-15 09:54 d——– C:\Sun
2008-01-12 22:19 . 2008-01-25 17:13 d——– C:\QUARANTINE
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Real
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\xing shared
2008-01-03 10:29 . 2008-01-03 10:29 d——– C:\Program Files\Common Files\Real

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-01-26 00:29 ——— d—–w C:\Program Files\Java
2008-01-25 23:23 ——— d—–w C:\Program Files\Palo Alto Software
2008-01-25 23:23 ——— d—–w C:\Program Files\Common Files\Palo Alto Software
2008-01-25 16:21 ——— d—–w C:\Program Files\LivePerson
2008-01-23 18:31 ——— d—–w C:\Program Files\Apoint
2007-01-19 01:08 5,971,432 —-a-w C:\Program Files\Firefox Setup 2.0.0.1.exe
2007-01-19 00:31 5,274,776 —-a-w C:\Program Files\ps2pdf995.exe
2007-01-19 00:04 6,563,928 —-a-w C:\Program Files\cuteftp.exe
.

((((((((((((((((((((((((((((( snapshot@2008-01-25_17.23.39.23 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-26 01:11:49 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
+ 2008-01-26 01:33:04 688,128 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000001\NTUSER.DAT
- 2008-01-26 01:11:49 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
+ 2008-01-26 01:33:05 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000002\UsrClass.dat
- 2008-01-26 01:11:49 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
+ 2008-01-26 01:33:05 692,224 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000003\NTUSER.DAT
- 2008-01-26 01:11:49 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
+ 2008-01-26 01:33:05 8,192 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000004\UsrClass.dat
- 2008-01-26 01:11:49 2,793,472 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-26 01:33:06 4,239,360 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000005\NTUSER.DAT
+ 2008-01-26 01:33:06 217,088 —-a-w C:\WINDOWS\erdnt\Hiv-backup\Users\00000006\UsrClass.dat
- 2008-01-26 01:22:02 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-01-26 01:23:59 64,262 —-a-w C:\WINDOWS\system32\perfc009.dat
- 2008-01-26 01:22:02 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-01-26 01:23:59 405,878 —-a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 03:00 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 14:30 282624 C:\WINDOWS\stsystra.exe]
"ShStatEXE"="C:\Applications\VScan\SHSTAT.exe" [2006-11-30 08:50 112216]

C:\Documents and Settings\benito.REALHEALTH\Start Menu\Programs\Startup\
LivePerson.lnk - C:\Program Files\LivePerson\hc.exe [2007-08-03 10:31:34 5468160]


.
Contents of the 'Scheduled Tasks' folder
"2007-02-12 17:33:16 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-25 17:37:01
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-25 17:38:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-01-26 01:38:38
ComboFix2.txt 2008-01-26 01:23:55
.
2008-01-10 01:28:32 — E O F —



HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:41, on 2008-01-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\noname\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Applications\VScan\scriptcl.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Applications\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 4958 bytes


Hope that worked!
Alright Arc369, Things look much better. :thumbup: Here's what has happened. You had a new variant of a vundo infection. One of the tools didn't see it because something ( McAfee or some other program) cleaned part of it but not all. The main culprit was Netwaitng program by the time I saw it. It does looks as if it has effected some of your other programs as well. Unfortunately these program have to be repaired / or uninstalled then reinstalled. I will give you a list of what needs to be repaired or reinstalled. Apoint"…touch pad drivers Broadcom Wireless Manager Dell Wireless WLAN Card Cyberlink PowerCinema Quicktime McAfeeUpdater McAfee Intell graphic drivers Intell graphic drivers NVidia graphics Real Player SunJavaUpdateSched Java NetWaiting ___________________________________ Please get that done and post a new HJT log. Let me know how things are running.
OK, progress on the following _

Apoint"…touch pad drivers - uninstalled and new drivers installed
Broadcom Wireless Manager Dell Wireless WLAN Card - uninstalled
Cyberlink PowerCinema- uninstalled
Quicktime - uninstalled
McAfeeUpdater McAfee- not sure how to do this, McAfee is locked to changes to me, will need to do some more work
Intell graphic drivers - removed
Intell graphic drivers- removed
NVidia graphics - removed
Real Player- removed
SunJavaUpdateSched Java - removed

NetWaiting - removed
_______________

Here is HJT LOG

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:31, on 2008-01-26
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Applications\Cisco VPN\cvpnd.exe
C:\WINDOWS\system32\DWRCS.EXE
C:\Applications\Common Framework\FrameworkService.exe
C:\Applications\VScan\Mcshield.exe
C:\Applications\VScan\VsTskMgr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\stsystra.exe
C:\WINDOWS\system32\DWRCST.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\noname\noname.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.msn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0070105
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Applications\VScan\scriptcl.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Applications\VScan\SHSTAT.EXE" /STANDALONE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Applications\Cisco VPN\vpngui.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\APPLIC~1\MSOffice\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\APPLIC~1\MSOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1168542169739
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://taurus.webex.com/client/T23L/webex/ieatgpc.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = realhealth.local
O17 - HKLM\Software\..\Telephony: DomainName = realhealth.local
O17 - HKLM\System\CCS\Services\Tcpip\..\{FCB79E8D-FA68-4BC9-8453-9BE956DC6EAA}: NameServer = 10.0.1.12,10.0.1.8
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = realhealth.local
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Applications\Cisco VPN\cvpnd.exe
O23 - Service: DameWare Mini Remote Control (DWMRCS) - DameWare Development LLC - C:\WINDOWS\system32\DWRCS.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Applications\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Applications\VScan\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Applications\VScan\VsTskMgr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 4449 bytes


some weird flashing of the desktop upon reboot, get the feeling this thing is still hiding out somewhere… many thanks for help so far!
Your doing great so far. :thumbup:


some weird flashing of the desktop upon reboot, get the feeling this thing is still hiding out somewhere… many thanks for help so far!


Your log looks good. So…I'm thinking here at this point it's a driver issue as we removed the old drivers.
So I'd like to try fixing that first.



________________________________________
You mentioned you removed all of the following, Did you replace the drivers?


Intell graphic drivers- removed
NVidia graphics - removed


If not we need to do that. It may be the funny flashing problem.
I'm thinking here you have a nividia video card (graphics).
If you have a recovery CD or any software that came with this computer your drivers may be on there.
You will be looking for something in the way of video/graphics drivers.


If you know which video card is in your computer you may try here.
http://www.nvidia.com/Download/index.aspx?lang=en-us
to aquire the correct drivers for your computer.
They also have a small app there that will run on your machine to detect which Nvidia card you have and get the correct drivers for it.
You may also try
http://support.dell.com/support/topics/glo…=gen&~ck=mn

for the drivers or to find out which video card you have.

________________________________

Let me know how this works out.
And Please answer the following questions.
  • Did the funny flash only happen 1 time after the reboot.?
    or
  • If you reboot you see it again?
  • Did you replace the drivers?

Let me know how this works out.
And Please answer the following questions.

* Did the funny flash only happen 1 time after the reboot.?
or
* If you reboot you see it again?
* Did you replace the drivers?


There were a couple of flashes after 1st reboot upon login
Since then nothing
I have reloaded the drivers from Dell, all seems to be fine.
That's awesome news arc, :thumbup:



Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.



Go to start > run and copy and paste this in the field:

ComboFix /u


Then hit enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the
system/hidden files and resets System Restore again.

______________________________





A few things to help with possible threats

These are optional . But will help protect you further.
___________________________________

SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.


Here's a site with great advise on how to AVOID malware. Much easier to do than removing it.


___________________________________
If your anything like me you should be mad these people have done this to you.
Please take the time to tell us what you would like to be done to these idiots!
We can only get something done about this if the people that we help, like you, are prepared to complain.
We have a dedicated forum for collecting these complaints Malware Complaints, you do not have to be registered to post.. just find your country room and register your complaint.

The infections you had was Vundo


Safe and Happy Surfing. :)
bob4 cannot thank you enough for guiding me through this! Thanks for your patience and guidance. Have followed the cleanup steps, and hopefully will not see this again! many thanks again. :woot:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI