This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

VirtuMonde Removal

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Symptoms: Multiple popups occur when IE7 is launched

TSING Steps Taken:
CHKSDK /f /r
MS Security patches up to date
Loaded trial version of Avast AV\updated ran scans in normal and safe modes - nothing found
Loaded Spybot S&D (freeware version): Ran scan in normal and safe modes. Half way through scan system shuts down - uninstalled
Loaded Adaware 7 (freeware version): Ran scan and found virtumonde, selected remove and reran scan - virtumonde still there
Loaded Trendmicro House Call: Ran scan in normal and safe modes. Half way through scan system shuts down - uninstalled
Loaded Symantec's FxVMonde.exe: Nothing found
Loaded Microsoft's PC Safety Scan: Ran scan in normal and safe modes. Half way through scan system shuts down - uninstalled

Am at the point when I'll admit defeat. Any help would be most appreciated.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:17:52 PM, on 3/11/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O3 - Toolbar: (no name) - {84938242-5C5B-4A55-B6B9-A1507543B418} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04e\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [2caf3913] rundll32.exe "C:\WINDOWS\system32\hssxejhs.dll",b
O4 - HKLM\..\Run: [BM2f9c0a8f] Rundll32.exe "C:\WINDOWS\system32\ecasoapn.dll",s
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [A00F17C8B10.exe] C:\DOCUME~1\MARKSM~1\LOCALS~1\Temp\_A00F17C8B10.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…wlscbase370.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SysEnforce - Unknown owner - C:\PROGRA~1\TRISNA~1\SSI\SYSENF~1.EXE (file missing)

ComboFix Results


ComboFix 08-03-10.1 - Mark Smith 2008-03-11 12:46:33.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.157 [GMT -5:00]
Running from: C:\temp\ComboFix.exe

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Program Files\MW
C:\Program Files\MW\MalwareWiped 5.7\ignorelist.dat
C:\Program Files\MW\MalwareWiped 5.7\malwarewipe.ini
C:\WINDOWS\BM2f9c0a8f.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\biruuaqb.ini
C:\WINDOWS\system32\breaiyfi.ini
C:\WINDOWS\system32\cdhfdope.ini
C:\WINDOWS\system32\ecasoapn.dll
C:\WINDOWS\system32\fjnsybfa.dll
C:\WINDOWS\system32\hkugyitp.ini
C:\WINDOWS\system32\hssxejhs.dll
C:\WINDOWS\system32\kksklqrs.ini
C:\WINDOWS\system32\lochvpmv.ini
C:\WINDOWS\system32\lyojfmfx.ini
C:\WINDOWS\system32\mfuafqsu.ini
C:\WINDOWS\system32\mooqr.bak1
C:\WINDOWS\system32\mooqr.bak2
C:\WINDOWS\system32\mooqr.ini
C:\WINDOWS\system32\mooqr.ini2
C:\WINDOWS\system32\mooqr.tmp
C:\WINDOWS\system32\myvwfgie.ini
C:\WINDOWS\system32\nedjrjsb.ini
C:\WINDOWS\system32\opbrrnkk.ini
C:\WINDOWS\system32\oyaostwi.ini
C:\WINDOWS\system32\pvqmcevk.ini
C:\WINDOWS\system32\qtdikofs.dll
C:\WINDOWS\system32\shjexssh.ini
C:\WINDOWS\system32\uljkmgwx.ini
C:\WINDOWS\system32\uvuvw.ini
C:\WINDOWS\system32\uvuvw.ini2
C:\WINDOWS\system32\vvygiwah.ini
C:\WINDOWS\system32\wciqptna.ini
C:\WINDOWS\system32\wvuvu.dll
C:\WINDOWS\system32\xkpoodfa.dll
C:\WINDOWS\system32\yihgjmws.ini
C:\xcrashdump.dat

.
((((((((((((((((((((((((( Files Created from 2008-02-11 to 2008-03-11 )))))))))))))))))))))))))))))))
.

2008-03-11 12:43 . 2008-03-11 12:42 1,584,403 –a—— C:\temp\ComboFix.exe
2008-03-11 12:09 . 2008-03-11 12:09 d——– C:\Program Files\Trend Micro
2008-03-11 10:08 . 2008-03-11 10:11 d——– C:\Program Files\Windows Live Safety Center
2008-03-11 09:40 . 2008-03-11 09:40 168,592 –a—— C:\temp\FxVMonde.exe
2008-03-10 15:19 . 2008-03-10 15:22 461 –a—— C:\WINDOWS\wininit.ini
2008-03-10 09:51 . 2008-03-10 09:42 708,096 –a—— C:\WINDOWS\system32\ntdll.dll
2008-03-07 15:06 . 2006-04-13 23:05 159,744 –a—— C:\WINDOWS\system32\hasher.dll
2008-03-07 15:05 . 2008-03-07 15:05 d——– C:\Program Files\Trisnap Technologies
2008-03-07 15:05 . 2004-03-09 02:00 662,288 –a—— C:\WINDOWS\system32\mscomct2.ocx
2008-03-07 14:52 . 2008-03-10 10:30 d——– C:\VundoFix Backups
2008-03-07 14:49 . 2008-03-07 14:49 146,944 –a—— C:\temp\VundoFix.exe
2008-03-07 14:11 . 2007-03-19 13:39 270,336 –a—— C:\WINDOWS\system32\CheckDll.dll
2008-03-07 14:11 . 2008-03-06 11:25 67,024 –a—— C:\WINDOWS\system32\CloseAll.exe
2008-03-07 14:11 . 2005-02-06 10:02 104 –a—— C:\WINDOWS\system32\ProxySettings.ini
2008-03-07 12:13 . 2007-08-01 23:47 102,664 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-07 11:21 . 2008-03-07 12:30 d——– C:\Documents and Settings\Mark Smith\.housecall6.6
2008-03-07 11:06 . 2008-03-11 08:11 1,994,662 —hs—- C:\WINDOWS\system32\hnhavvmg.ini
2008-03-06 12:42 . 2008-03-06 12:43 d——– C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-06 11:31 . 2008-03-06 11:31 d——– C:\Program Files\MSXML 6.0
2008-03-05 16:54 . 2008-03-05 16:54 d——– C:\Program Files\MSBuild
2008-03-05 16:48 . 2008-03-06 11:52 d——– C:\WINDOWS\system32\XPSViewer
2008-03-05 16:45 . 2008-03-05 16:45 d——– C:\Program Files\Reference Assemblies
2008-03-05 16:42 . 2006-06-29 14:07 14,048 ——— C:\WINDOWS\system32\spmsg2.dll
2008-03-05 16:38 . 2006-10-04 09:06 1,197,294 —–c— C:\WINDOWS\system32\dllcache\sysmain.sdb
2008-03-05 16:38 . 2006-10-04 09:06 764,868 —–c— C:\WINDOWS\system32\dllcache\apph_sp.sdb
2008-03-05 16:38 . 2006-10-04 09:06 217,118 —–c— C:\WINDOWS\system32\dllcache\apphelp.sdb
2008-03-05 16:37 . 2008-03-05 16:37 23,392 –a—— C:\WINDOWS\system32\nscompat.tlb
2008-03-05 16:37 . 2008-03-05 16:37 16,832 –a—— C:\WINDOWS\system32\amcompat.tlb
2008-03-05 16:34 . 2008-03-05 16:34 d——– C:\Program Files\Windows Media Connect 2
2008-03-05 16:25 . 2008-03-07 13:04 d——– C:\WINDOWS\system32\LogFiles
2008-03-05 16:25 . 2008-03-05 16:28 d——– C:\WINDOWS\system32\drivers\UMDF
2008-03-05 15:56 . 2006-11-13 01:02 288,768 ——— C:\WINDOWS\system32\rhttpaa.dll
2008-03-05 15:56 . 2006-11-13 01:02 116,736 ——— C:\WINDOWS\system32\aaclient.dll
2008-03-05 15:56 . 2006-11-13 01:02 36,352 ——— C:\WINDOWS\system32\tsgqec.dll
2008-03-05 14:27 . 2007-12-06 21:21 6,066,176 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll
2008-03-05 14:27 . 2007-06-30 22:31 2,455,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dat
2008-03-05 14:27 . 2007-06-30 22:36 991,232 —–c— C:\WINDOWS\system32\dllcache\ieframe.dll.mui
2008-03-05 14:27 . 2007-12-06 21:21 459,264 —–c— C:\WINDOWS\system32\dllcache\msfeeds.dll
2008-03-05 14:27 . 2007-12-06 21:21 383,488 —–c— C:\WINDOWS\system32\dllcache\ieapfltr.dll
2008-03-05 14:27 . 2007-12-06 21:21 267,776 —–c— C:\WINDOWS\system32\dllcache\iertutil.dll
2008-03-05 14:27 . 2007-12-06 21:21 63,488 —–c— C:\WINDOWS\system32\dllcache\icardie.dll
2008-03-05 14:27 . 2007-12-06 21:21 52,224 —–c— C:\WINDOWS\system32\dllcache\msfeedsbs.dll
2008-03-05 14:27 . 2007-12-06 06:00 13,824 —–c— C:\WINDOWS\system32\dllcache\ieudinit.exe
2008-03-05 14:18 . 2007-08-13 19:54 33,792 –a–c— C:\WINDOWS\system32\dllcache\custsat.dll
2008-03-04 17:04 . 2008-03-04 17:04 d——– C:\Program Files\CCleaner
2008-03-04 17:01 . 2008-03-11 11:30 d——– C:\Program Files\Spybot - Search & Destroy
2008-03-04 17:01 . 2008-03-11 11:30 d——– C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-04 15:36 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-03-04 15:35 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-03-04 15:35 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-03-04 15:35 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-03-04 15:34 . 2003-03-18 16:20 1,060,864 –a—— C:\WINDOWS\system32\MFC71.dll
2008-03-04 15:34 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-03-04 15:34 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-03-04 15:34 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-03-04 15:34 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-03-04 15:33 . 2008-03-04 15:33 d——– C:\Program Files\Alwil Software
2008-03-04 15:28 . 2008-03-04 16:57 1,552 –a—— C:\WINDOWS\UninstallPestPatrol.mif
2008-03-02 19:13 . 2008-03-02 19:13 1,219,418 –a—— C:\Documents and Settings\Mark Smith\Application Data\Install.dat
2008-02-28 14:59 . 2008-02-28 15:00 1,010,104 —hs—- C:\WINDOWS\system32\69F3100c__.ini
2008-02-13 13:32 . 2008-02-13 13:32 294 —hs—- C:\WINDOWS\system32\401B100c__.ini

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-04 20:36 ——— d—–w C:\Program Files\Yahoo!
2008-02-02 20:34 ——— d—–w C:\Program Files\Full Tilt Poker
2007-09-26 14:54 6,440 –sh–w C:\WINDOWS\system32\aacdd.bak1
2007-09-25 22:36 6,440 –sh–w C:\WINDOWS\system32\aayxx.bak1
2007-09-24 23:15 6,440 –sh–w C:\WINDOWS\system32\beeeg.bak1
2007-09-29 00:38 24,294 –sh–w C:\WINDOWS\system32\beeeg.bak2
2007-09-28 12:09 15,591 –sh–w C:\WINDOWS\system32\jknnn.bak1
2007-09-29 16:37 6,440 –sh–w C:\WINDOWS\system32\knnnn.bak1
2007-10-02 04:57 7,615 –sh–w C:\WINDOWS\system32\knnnn.bak2
2007-09-26 01:57 6,440 –sh–w C:\WINDOWS\system32\tvyay.bak1
2007-09-24 04:06 6,440 –sh–w C:\WINDOWS\system32\uwvut.bak1
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATIModeChange"="Ati2mdxx.exe" [2002-08-28 19:17 28672 C:\WINDOWS\system32\Ati2mdxx.exe]
"CARPService"="carpserv.exe" [2003-03-06 18:50 4608 C:\WINDOWS\system32\carpserv.exe]
"PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2004-04-14 15:46 57393]
"SetDefPrt"="C:\Program Files\Brother\Brmfl04e\BrStDvPt.exe" [2004-05-25 10:16 49152]
"ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2004-07-20 10:34 851968]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2005-09-16 09:43 274432]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-11-05 17:52 155648]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 04:44:06 29696]
InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe [2005-02-09 10:18:13 73728]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2005-02-08 13:17:19 106560]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\__c0021423]
C:\WINDOWS\system32\__c0021423.dat 2008-03-11 07:47 22291 C:\WINDOWS\system32\__c0021423.dat

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Internet Explorer\\iexplore.exe"=

S3 brfilt;Brother MFC Filter Driver;C:\WINDOWS\system32\Drivers\Brfilt.sys [2001-08-17 14:12]
S3 BrSerWDM;Brother WDM Serial driver;C:\WINDOWS\system32\Drivers\BrSerWdm.sys [2003-03-13 19:04]
S3 BrUsbMdm;Brother MFC USB Fax Only Modem;C:\WINDOWS\system32\Drivers\BrUsbMdm.sys [2001-08-17 14:12]
S3 BrUsbScn;Brother MFC USB Scanner driver;C:\WINDOWS\system32\Drivers\BrUsbScn.sys [2001-08-17 14:12]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;C:\WINDOWS\system32\DRIVERS\wg111v2.sys [2005-04-21 00:33]

.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-03-11 12:54:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2008-03-11 12:56:08 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-11 17:55:55
.
2008-03-06 18:47:25 — E O F —
[external image: Posted Image]

Sorry about the delay in responding :(

If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread.

Also please describe how your computer behaves at the moment.
Browsed the forum and found that combofix had corrected the issue in some cases. Downloaded and ran combofix a number of times and it appears to have corrected the issue. Laptop is running correctly and the user has not mentioned any issues the past week. Still cannot run a full scan via Spybot S&D or other malware apps. Possibly due to corrupted sectors on the hard drive, but that is another issue. Thanks for the reply

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI