This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Mal/heuri issue

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok So I created the file with the text as you said, Saved it on my desktop. Drag drop onto combofix . It started up. And then nothing happened. It didnt go through combofix. so no combofix log. here's a current HJT PC is working swimmingly now though. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:49:48 PM, on 1/19/2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16575) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Windows\RtHDVCpl.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Acer\Acer Arcade\PCMService.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\MSN Messenger\msnmsgr.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Users\Yonah France\AppData\Local\rmvunhx.exe C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE C:\Users\YONAHF~1\AppData\Local\Temp\RtkBtMnt.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Windows\system32\taskeng.exe C:\Program Files\Internet Explorer\ieuser.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil9d.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Windows\system32\SearchFilterHost.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O1 - Hosts: ::1 localhost O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - (no file) O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Acer\Acer Arcade\PCMService.exe" O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer Registration\ACE1.exe" /startup O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll" O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SHStartup.exe O4 - HKLM\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray O4 - HKCU\..\Run: [Sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe" O4 - HKCU\..\Run: [rmvunhx] c:\users\yonah france\appdata\local\rmvunhx.exe rmvunhx O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE') O4 - Global Startup: Empowering Technology Launcher.lnk = ? O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O13 - Gopher Prefix: O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\Acer\Acer Arcade\Kernel\TV\CLSched.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\Acer\Acer Arcade\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe O23 - Service: SpyHunter3 Service - Enigma Software Group, Inc. - C:\Program Files\Enigma Software Group\SpyHunter\SHService.exe O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe – End of file - 7031 bytes
When I try dragging the file you told me to make on combofix's icon it looks like it is going to run and then does nothing.
So I ran combofix by itself again.

here are the logs for combofix and for HJT .

ComboFix 08-01-28.2 - Yonah France 2008-01-31 22:55:41.3 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.441 [GMT -5:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-01-19 22:49 . 2008-01-19 22:49 d——– C:\Program Files\Trend Micro
2008-01-19 22:37 . 2008-01-22 19:08 d——– C:\Program Files\NoAdware5.0
2008-01-19 21:03 . 2008-01-22 19:09 d——– C:\Program Files\Enigma Software Group
2008-01-19 20:52 . 2008-01-19 20:52 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-01-19 20:52 . 2008-01-19 20:52 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-01-19 13:37 . 2008-01-19 13:38 d——– C:\Users\All Users\Lavasoft
2008-01-19 13:37 . 2008-01-19 13:38 d——– C:\ProgramData\Lavasoft
2008-01-19 13:37 . 2008-01-19 13:37 d——– C:\Program Files\Lavasoft
2008-01-19 13:36 . 2008-01-22 19:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-19 13:31 . 2008-01-19 13:36 d——– C:\Users\Yonah France\AppData\Roaming\mIRC
2008-01-19 13:31 . 2008-01-19 20:09 d——– C:\Program Files\mIRC
2008-01-10 21:09 . 2008-01-10 21:09 802,816 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-01-10 21:09 . 2008-01-10 21:09 216,760 –a—— C:\Windows\System32\drivers\netio.sys
2008-01-10 21:09 . 2008-01-10 21:09 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-01-10 21:09 . 2008-01-10 21:09 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-01-10 21:09 . 2008-01-10 21:09 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-01-10 21:07 . 2008-01-10 21:07 11,776 –a—— C:\Windows\System32\sbunattend.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 03:54 ——— d—–w C:\Users\Yonah France\AppData\Roaming\Skype
2008-01-29 13:21 ——— d—–w C:\Users\Yonah France\AppData\Roaming\OpenOffice.org2
2008-01-25 05:00 ——— d—–w C:\Users\Yonah France\AppData\Roaming\BitTorrent
2008-01-22 02:39 164 —-a-w C:\install.dat
2008-01-20 01:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-20 01:07 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-20 00:58 ——— d—–w C:\ProgramData\Symantec
2008-01-20 00:49 ——— d—–w C:\ProgramData\eMule
2008-01-19 02:06 ——— d—–w C:\Users\Yonah France\AppData\Roaming\dvdcss
2008-01-11 04:03 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-05 01:56 1,526,640 —-a-w C:\Windows\WRSetup.dll
2008-01-05 01:34 23,920 —-a-w C:\Windows\system32\drivers\sskbfd.sys
2008-01-05 01:34 21,872 —-a-w C:\Windows\system32\drivers\sshrmd.sys
2008-01-05 01:34 20,336 —-a-w C:\Windows\system32\drivers\SSFS0BB9.sys
2008-01-05 01:34 163,696 —-a-w C:\Windows\system32\drivers\ssidrv.sys
2007-12-14 16:32 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2007-12-13 12:36 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2007-12-13 12:35 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 12:35 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2007-12-13 12:34 824,832 —-a-w C:\Windows\System32\wininet.dll
2007-12-13 12:34 56,320 —-a-w C:\Windows\System32\iesetup.dll
2007-12-13 12:34 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-13 12:34 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-12-13 12:33 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-13 12:33 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-13 12:33 130,048 —-a-w C:\Windows\system32\drivers\srv2.sys
2007-12-13 12:33 101,888 —-a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-13 12:31 3,504,824 —-a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-13 12:31 3,470,520 —-a-w C:\Windows\System32\ntoskrnl.exe
2007-12-01 18:12 ——— d—–w C:\Program Files\KellySoftware
2007-12-01 18:09 29,696 —-a-w C:\Windows\mickey32.dll
2007-12-01 18:09 232,784 —-a-w C:\Windows\Matrix Code.scr
2007-12-01 18:09 2,285,222 —-a-w C:\Windows\Matrix Code.exe
2007-11-14 00:40 58,760 —-a-w C:\symlcsv1.exe
2006-11-02 12:48 174 –sha-w C:\Program Files\desktop.ini
2007-09-30 15:46 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-30 15:46 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-30 15:46 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 21:07 1232896]
"????r"="" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-07 18:01 43008]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 13:31 22880040]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:34 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 07:33 1004136]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-05 20:02 98304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-05 20:05 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-05 20:02 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 00:37 4186112 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-22 22:00 815104]
"PCMService"="C:\Program Files\Acer\Acer Arcade\PCMService.exe" [2007-01-09 03:55 151552]
"Acer Tour"="" []
"SetPanel"="" []
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2006-12-13 13:55 3166208]
"eRecoveryService"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-01-12 11:17:03 528384]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2007-09-07 18:01 43008 C:\Program Files\BitTorrent\bittorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra—— 2006-01-30 11:00 98304 C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
C:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2004-11-22 11:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]


R2 int15;int15;C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 17:12]
R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 15:57]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 04:39]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-05 21:29]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-10-23 22:40]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 22:58:02
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-31 22:59:25
ComboFix-quarantined-files.txt 2008-02-01 03:59:14
ComboFix2.txt 2008-01-30 04:10:40
ComboFix3.txt 2008-01-28 17:16:43
.
2008-01-30 12:25:03 — E O F —




ComboFix 08-01-28.2 - Yonah France 2008-01-31 22:55:41.3 - NTFSx86
Microsoft® Windows Vista™ Home Basic 6.0.6000.0.1252.1.1033.18.441 [GMT -5:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-01-01 to 2008-02-01 )))))))))))))))))))))))))))))))
.

2008-01-19 22:49 . 2008-01-19 22:49 d——– C:\Program Files\Trend Micro
2008-01-19 22:37 . 2008-01-22 19:08 d——– C:\Program Files\NoAdware5.0
2008-01-19 21:03 . 2008-01-22 19:09 d——– C:\Program Files\Enigma Software Group
2008-01-19 20:52 . 2008-01-19 20:52 d——– C:\Users\All Users\SUPERAntiSpyware.com
2008-01-19 20:52 . 2008-01-19 20:52 d——– C:\ProgramData\SUPERAntiSpyware.com
2008-01-19 13:37 . 2008-01-19 13:38 d——– C:\Users\All Users\Lavasoft
2008-01-19 13:37 . 2008-01-19 13:38 d——– C:\ProgramData\Lavasoft
2008-01-19 13:37 . 2008-01-19 13:37 d——– C:\Program Files\Lavasoft
2008-01-19 13:36 . 2008-01-22 19:12 d——– C:\Program Files\Common Files\Wise Installation Wizard
2008-01-19 13:31 . 2008-01-19 13:36 d——– C:\Users\Yonah France\AppData\Roaming\mIRC
2008-01-19 13:31 . 2008-01-19 20:09 d——– C:\Program Files\mIRC
2008-01-10 21:09 . 2008-01-10 21:09 802,816 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-01-10 21:09 . 2008-01-10 21:09 216,760 –a—— C:\Windows\System32\drivers\netio.sys
2008-01-10 21:09 . 2008-01-10 21:09 167,424 –a—— C:\Windows\System32\tcpipcfg.dll
2008-01-10 21:09 . 2008-01-10 21:09 24,064 –a—— C:\Windows\System32\netcfg.exe
2008-01-10 21:09 . 2008-01-10 21:09 22,016 –a—— C:\Windows\System32\netiougc.exe
2008-01-10 21:07 . 2008-01-10 21:07 11,776 –a—— C:\Windows\System32\sbunattend.exe

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-01 03:54 ——— d—–w C:\Users\Yonah France\AppData\Roaming\Skype
2008-01-29 13:21 ——— d—–w C:\Users\Yonah France\AppData\Roaming\OpenOffice.org2
2008-01-25 05:00 ——— d—–w C:\Users\Yonah France\AppData\Roaming\BitTorrent
2008-01-22 02:39 164 —-a-w C:\install.dat
2008-01-20 01:12 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-01-20 01:07 ——— d—–w C:\Program Files\Common Files\Symantec Shared
2008-01-20 00:58 ——— d—–w C:\ProgramData\Symantec
2008-01-20 00:49 ——— d—–w C:\ProgramData\eMule
2008-01-19 02:06 ——— d—–w C:\Users\Yonah France\AppData\Roaming\dvdcss
2008-01-11 04:03 ——— d—–w C:\Program Files\Windows Sidebar
2008-01-05 01:56 1,526,640 —-a-w C:\Windows\WRSetup.dll
2008-01-05 01:34 23,920 —-a-w C:\Windows\system32\drivers\sskbfd.sys
2008-01-05 01:34 21,872 —-a-w C:\Windows\system32\drivers\sshrmd.sys
2008-01-05 01:34 20,336 —-a-w C:\Windows\system32\drivers\SSFS0BB9.sys
2008-01-05 01:34 163,696 —-a-w C:\Windows\system32\drivers\ssidrv.sys
2007-12-14 16:32 12,632 —-a-w C:\Windows\System32\lsdelete.exe
2007-12-13 12:36 1,327,104 —-a-w C:\Windows\System32\quartz.dll
2007-12-13 12:35 9,728 —-a-w C:\Windows\System32\LAPRXY.DLL
2007-12-13 12:35 223,232 —-a-w C:\Windows\System32\WMASF.DLL
2007-12-13 12:34 824,832 —-a-w C:\Windows\System32\wininet.dll
2007-12-13 12:34 56,320 —-a-w C:\Windows\System32\iesetup.dll
2007-12-13 12:34 52,736 —-a-w C:\Windows\AppPatch\iebrshim.dll
2007-12-13 12:34 26,624 —-a-w C:\Windows\System32\ieUnatt.exe
2007-12-13 12:33 84,992 —-a-w C:\Windows\system32\drivers\srvnet.sys
2007-12-13 12:33 58,368 —-a-w C:\Windows\system32\drivers\mrxsmb20.sys
2007-12-13 12:33 130,048 —-a-w C:\Windows\system32\drivers\srv2.sys
2007-12-13 12:33 101,888 —-a-w C:\Windows\system32\drivers\mrxsmb.sys
2007-12-13 12:31 3,504,824 —-a-w C:\Windows\System32\ntkrnlpa.exe
2007-12-13 12:31 3,470,520 —-a-w C:\Windows\System32\ntoskrnl.exe
2007-12-01 18:12 ——— d—–w C:\Program Files\KellySoftware
2007-12-01 18:09 29,696 —-a-w C:\Windows\mickey32.dll
2007-12-01 18:09 232,784 —-a-w C:\Windows\Matrix Code.scr
2007-12-01 18:09 2,285,222 —-a-w C:\Windows\Matrix Code.exe
2007-11-14 00:40 58,760 —-a-w C:\symlcsv1.exe
2006-11-02 12:48 174 –sha-w C:\Program Files\desktop.ini
2007-09-30 15:46 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-09-30 15:46 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-09-30 15:46 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 21:07 1232896]
"????r"="" []
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.exe" [2007-01-19 11:54 5674352]
"BitTorrent"="C:\Program Files\BitTorrent\bittorrent.exe" [2007-09-07 18:01 43008]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2007-09-13 13:31 22880040]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 07:34 201728]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-02 07:33 1004136]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2006-11-05 20:02 98304]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2006-11-05 20:05 106496]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2006-11-05 20:02 81920]
"RtHDVCpl"="RtHDVCpl.exe" [2006-12-01 00:37 4186112 C:\Windows\RtHDVCpl.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-10-22 22:00 815104]
"PCMService"="C:\Program Files\Acer\Acer Arcade\PCMService.exe" [2007-01-09 03:55 151552]
"Acer Tour"="" []
"SetPanel"="" []
"Acer Product Registration"="C:\Program Files\Acer Registration\ACE1.exe" [2006-12-13 13:55 3166208]
"eRecoveryService"="" []
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11 132496]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 19:51 583048]

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Empowering Technology Launcher.lnk - C:\Acer\Empowering Technology\eAPLauncher.exe [2007-01-12 11:17:03 528384]

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=C:\Windows\pss\Adobe Reader Speed Launch.lnk.CommonStartup
backupExtension=.CommonStartup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent]
–a—— 2007-09-07 18:01 43008 C:\Program Files\BitTorrent\bittorrent.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
-ra—— 2006-01-30 11:00 98304 C:\Program Files\Hewlett-Packard\OrderReminder\OrderReminder.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\osCheck]
C:\Program Files\Norton Internet Security\osCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra—— 2004-11-22 11:18 307200 C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\?????????]


R2 int15;int15;C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 17:12]
R2 MobilityService;MobilityService;C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 15:57]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-04 04:39]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2006-11-05 21:29]
S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver;C:\Windows\system32\DRIVERS\bcmwl6.sys [2006-10-23 22:40]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceNoNetwork REG_MULTI_SZ PLA DPS BFE mpssvc

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-31 22:58:02
Windows 6.0.6000 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-01-31 22:59:25
ComboFix-quarantined-files.txt 2008-02-01 03:59:14
ComboFix2.txt 2008-01-30 04:10:40
ComboFix3.txt 2008-01-28 17:16:43
.
2008-01-30 12:25:03 — E O F —
Good job :thumbup:

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]


    Here's my usual all clean post

    Log looks good :D


    You need to create a new Clean restore point.

    Note: This will remove all previous Restore Points

    Click Start Menu > Run > copy and paste

    %SystemRoot%\System32\restore\rstrui.exe

    Press OK. Choose Create a Restore Point then click Next. Name it (something you'll remember) and click Create, when the confirmation screen shows the restore point has been created click Close.
Vista doesnt have the Run method anymore. You have to put everything in the "Start Search" So the first part worked (the combofix uninstall part) but the second didnt. putting this in start search doesnt do anyhing %SystemRoot%\System32\restore\rstrui.exe ideas?
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI