Need Help 13 Posted October 26, 2009 ID:148961 Share Posted October 26, 2009 A couple days ago suddenly my computer was getting all sorts of messages in the bottom right about my computer being infected, sending credit card numbers, etc. Also those fake scans were popping up and running. When I went to run Malwarebytes it wouldn't run. Also my anti-virus and other programs wouldn't run. I tried some self-help things and eventually got my avira anti-virus to run. It picked up some things and my computer is now usable, without all those pop-ups, but I'm seeing a number of pop-up ads that I never do when I browse the internet still and Malwarebytes still won't run. HEre is the hijackthis log, thanks:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 12:18:16 PM, on 10/26/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16915)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Viewpoint\Common\ViewpointService.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\Program Files\WZCBDL Service\WZCBDLS.exeC:\WINDOWS\Explorer.EXEC:\Program Files\CheckPoint\Integrity Client\iclient.exeC:\WINDOWS\system32\ICO.EXEC:\Program Files\D-Link\AirXpert Utility\AirXCFG.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exeC:\WINDOWS\V0250Mon.exeC:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\Windows Media Player\WMPNSCFG.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\AIM6\aolsoftware.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pbs.org/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pbs.org/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>;*.localO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXEO4 - HKLM\..\Run: [AtiPTA] atiptaxx.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /minO4 - HKLM\..\Run: [V0250Mon.exe] C:\WINDOWS\V0250Mon.exeO4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [lofuzirif] Rundll32.exe "c:\windows\system32\zogovaro.dll",aO4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO4 - HKCU\..\Run: [bitComet] "C:\Program Files\BitComet\BitComet.exe" /trayO4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.comO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1121293151687O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1154431940934O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COMO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COMO20 - AppInit_DLLs: c:\windows\system32\fupuvuyu.dll c:\progra~1\ThunMail\testabd.dll c:\windows\system32\supekede.dll c:\windows\system32\zogovaro.dll,sitevahi.dllO21 - SSODL: mosukitet - {dfbe63ba-c954-4da8-b295-758795abe3e7} - c:\windows\system32\supekede.dllO22 - SharedTaskScheduler: jugezatag - {dfbe63ba-c954-4da8-b295-758795abe3e7} - c:\windows\system32\supekede.dllO23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exeO23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)O23 - Service: ISSI EZUpdate (ISSIMon) - Unknown owner - c:\sdwork\issimsvc.exe (file missing)O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exeO23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe--End of file - 8272 bytes Link to post Share on other sites More sharing options...
Staff miekiemoes Posted October 27, 2009 Staff ID:149467 Share Posted October 27, 2009 Hi,I see you have Viewpoint installed...Viewpoint Manager is considered as foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad". This will change from what we know in 2006 read this article: http://www.clickz.com/news/article.php/3561546I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present.ViewpointViewpoint ManagerViewpoint Media PlayerTo run malwarebytes when you get the error code 2 during install, or mbam.exe gets deleted, please see here:http://www.malwarebytes.org/forums/index.php?showtopic=29028Once malwarebytes opens, click the "Update" tab, click "Check for Updates" in order to download the updates.Then run the scan, let mbam quarantine/delete what it found and reboot afterwards.After reboot, post the malwarebytes log together with a new HijackThislog. Link to post Share on other sites More sharing options...
Need Help 13 Posted October 28, 2009 Author ID:150524 Share Posted October 28, 2009 Logfile of Trend Micro HijackThis v2.0.2Scan saved at 3:08:48 PM, on 10/28/2009Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16915)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Java\jre6\bin\jqs.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\ZoneLabs\vsmon.exeC:\WINDOWS\Explorer.EXEC:\Program Files\WZCBDL Service\WZCBDLS.exeC:\Program Files\CheckPoint\Integrity Client\iclient.exeC:\WINDOWS\system32\ICO.EXEC:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exeC:\Program Files\D-Link\AirXpert Utility\AirXCFG.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exeC:\WINDOWS\V0250Mon.exeC:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\Windows Media Player\WMPNSCFG.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\AIM6\aolsoftware.exeC:\Program Files\iPod\bin\iPodService.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\Program Files\Avira\AntiVir PersonalEdition Classic\avwsc.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pbs.org/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.pbs.org/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;<local>;*.localO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO4 - HKLM\..\Run: [iMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\CheckPoint\Integrity Client\iclient.exe"O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXEO4 - HKLM\..\Run: [AtiPTA] atiptaxx.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [D-Link AirXpert Utility] C:\Program Files\D-Link\AirXpert Utility\AirXCFG.exeO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /minO4 - HKLM\..\Run: [V0250Mon.exe] C:\WINDOWS\V0250Mon.exeO4 - HKLM\..\Run: [AVFX Engine] C:\Program Files\Creative\Creative Live! Cam\VideoFX\StartFX.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [calc] rundll32.exe C:\WINDOWS\system32\calc.dll,_IWMPEvents@0O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "E:\Malwarebytes' Anti-Malware\explorer.exe.exe" /runcleanupscriptO4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exeO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO4 - HKCU\..\Run: [bitComet] "C:\Program Files\BitComet\BitComet.exe" /trayO4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKCU\..\Run: [AdobeUpdater] "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"O4 - HKCU\..\Run: [calc] rundll32.exe C:\DOCUME~1\LOCALS~1\ntuser.dll,_IWMPEvents@0O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO14 - IERESET.INF: START_PAGE_URL=http://w3.ibm.comO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1121293151687O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1154431940934O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = IBM.COMO17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = IBM.COMO20 - AppInit_DLLs: sitevahi.dll O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exeO23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exeO23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: ISAM SMT Service (ISAMsmt) - Unknown owner - C:\Program Files\C4ebreg\isamsmt.exe (file missing)O23 - Service: ISSI EZUpdate (ISSIMon) - Unknown owner - c:\sdwork\issimsvc.exe (file missing)O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exeO23 - Service: WZCBDL Service (WZCBDLService) - D-Link - C:\Program Files\WZCBDL Service\WZCBDLS.exe--End of file - 8099 bytesMalwarebytes' Anti-Malware 1.41Database version: 3047Windows 5.1.2600 Service Pack 310/28/2009 3:05:39 PMmbam-log-2009-10-28 (15-05-39).txtScan type: Full Scan (A:\|C:\|D:\|E:\|)Objects scanned: 174225Time elapsed: 1 hour(s), 33 minute(s), 30 second(s)Memory Processes Infected: 0Memory Modules Infected: 3Registry Keys Infected: 1Registry Values Infected: 5Registry Data Items Infected: 2Folders Infected: 0Files Infected: 27Memory Processes Infected:(No malicious items detected)Memory Modules Infected:C:\WINDOWS\system32\calc.dll (Trojan.Agent) -> Delete on reboot.c:\WINDOWS\system32\supekede.dll (Trojan.Vundo.H) -> Delete on reboot.C:\WINDOWS\system32\wezisuve.dll (Trojan.Vundo) -> Delete on reboot.Registry Keys Infected:HKEY_CLASSES_ROOT\CLSID\{49e0d174-473c-4e87-bc8f-7a03c2d8f07c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.Registry Values Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lofuzirif (Trojan.Vundo.H) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Delete on reboot.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{49e0d174-473c-4e87-bc8f-7a03c2d8f07c} (Trojan.Vundo.H) -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\befitegud (Trojan.Vundo.H) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\calc (Trojan.Agent) -> Delete on reboot.Registry Data Items Infected:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\supekede.dll -> Quarantined and deleted successfully.HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\supekede.dll -> Quarantined and deleted successfully.Folders Infected:(No malicious items detected)Files Infected:c:\WINDOWS\system32\supekede.dll (Trojan.Vundo.H) -> Delete on reboot.C:\WINDOWS\system32\calc.dll (Trojan.Agent) -> Delete on reboot.C:\WINDOWS\system32\wezisuve.dll (Trojan.Vundo) -> Delete on reboot.C:\WINDOWS\system32\febobafi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\gipidiwu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\kegovahe.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\puzesale.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\rivuyepu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\tegareto.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\wihudiyu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\wisepale.exe (Trojan.Dropper) -> Quarantined and deleted successfully.C:\WINDOWS\system32\dedisuri.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\domohodu.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\pefasiyu.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\joyurowe.dll.tmp (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\fodudoto.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\volizita.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\WINDOWS\system32\zogovaro.dll (Trojan.Vundo) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\ntuser.dll (Trojan.Agent) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\Local Settings\temp\rundll32.dll (Trojan.Agent) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ZIC73R6G\update2[2].exe (Rogue.SecurityTool) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\scandisk.dll (Trojan.Agent) -> Quarantined and deleted successfully.C:\Documents and Settings\LocalService\ntuser.dll (Trojan.Agent) -> Quarantined and deleted successfully.C:\WINDOWS\system32\SelfDel.bat (Malware.Trace) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\Start Menu\Programs\Security Tool.LNK (Rogue.SecurityTool) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\scandisk.lnk (Trojan.Downloader) -> Quarantined and deleted successfully.C:\Documents and Settings\Administrator\Local Settings\temp\nsrbgxod.bak (Trojan.Agent) -> Delete on reboot. Link to post Share on other sites More sharing options...
Staff miekiemoes Posted October 28, 2009 Staff ID:150528 Share Posted October 28, 2009 Hi,* Please visit this webpage for instructions for downloading and running ComboFix:http://www.bleepingcomputer.com/combofix/how-to-use-combofixPost the log from ComboFix in your next reply.Please make sure you disable ALL of your Antivirus/Antispyware/Firewall before running ComboFix..This because Security Software may see some components ComboFix uses (prep.com for example) as suspicious and blocks the tool, or even deletes it. Please visit HERE if you don't know how. Link to post Share on other sites More sharing options...
Need Help 13 Posted October 28, 2009 Author ID:150566 Share Posted October 28, 2009 ComboFix 09-10-27.08 - dmullen 10/28/2009 16:22.2.1 - NTFSx86Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1023.608 [GMT -4:00]Running from: c:\documents and settings\Administrator\My Documents\Downloads\ComboFix.exeAV: Avira AntiVir PersonalEdition *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}FW: Integrity Flex Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}.((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))).c:\documents and settings\Administrator\ntuser.dllc:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.dllc:\documents and settings\Administrator\Start Menu\Programs\Startup\scandisk.lnkc:\documents and settings\NetworkService\ntuser.dllc:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}c:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}\chrome.manifestc:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}\chrome\content\overlay.xulc:\program files\Mozilla Firefox\extensions\{0A391708-8F13-4FC9-BD21-2E68EFE00381}\install.rdfc:\windows\run.logc:\windows\system32\afipupos.inic:\windows\system32\calc.dllc:\windows\system32\pcload.exec:\windows\system32\uniq.tll.((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))).-------\Legacy_AVAST!ANTIVIRUS((((((((((((((((((((((((( Files Created from 2009-09-28 to 2009-10-28 ))))))))))))))))))))))))))))))).2009-10-28 16:45 . 2009-09-10 18:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys2009-10-28 16:45 . 2009-09-10 18:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys2009-10-25 19:21 . 2009-10-25 19:32 -------- d-----w- c:\windows\Symbols2009-10-25 03:09 . 2009-10-25 23:38 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP2009-10-25 03:05 . 2009-10-25 03:05 -------- d--h--w- c:\windows\PIF2009-10-14 15:20 . 2009-10-17 13:19 -------- d-----w- c:\documents and settings\All Users\Application Data\Soulseek2009-10-14 06:00 . 2009-10-14 06:00 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\AIM2009-10-03 14:39 . 2009-10-03 14:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage.(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))).2009-10-28 17:31 . 2007-09-04 19:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Google Updater2009-10-28 16:46 . 2009-01-12 18:12 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware2009-10-28 04:02 . 2007-09-04 19:42 1744 ----a-w- c:\windows\system32\d3d9caps.dat2009-10-27 14:42 . 2009-06-29 11:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Viewpoint2009-10-27 14:42 . 2007-09-05 17:30 -------- d-----w- c:\documents and settings\Administrator\Application Data\Viewpoint2009-10-25 23:39 . 2009-01-12 05:38 -------- d-----w- c:\program files\SUPERAntiSpyware2009-10-25 14:32 . 2009-04-24 02:02 75096 ----a-w- c:\windows\system32\drivers\avipbb.sys2009-10-25 02:02 . 2007-08-25 15:48 -------- d-----w- c:\documents and settings\Administrator\Application Data\Skype2009-10-25 01:43 . 2009-04-06 08:50 -------- d-----r- c:\program files\Skype2009-10-25 01:42 . 2007-08-25 15:42 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype2009-09-21 21:41 . 2007-10-18 02:20 -------- d-----w- c:\program files\Java2009-09-11 14:18 . 2004-08-04 05:00 136192 ----a-w- c:\windows\system32\msv1_0.dll2009-09-10 07:09 . 2008-08-19 04:04 -------- d-----w- c:\program files\Microsoft Silverlight2009-09-04 21:03 . 2004-08-04 05:00 58880 ----a-w- c:\windows\system32\msasn1.dll2009-08-29 07:36 . 2004-08-04 05:00 832512 ----a-w- c:\windows\system32\wininet.dll2009-08-29 07:36 . 2009-01-05 22:41 78336 ----a-w- c:\windows\system32\ieencode.dll2009-08-29 07:36 . 2004-08-04 05:00 17408 ----a-w- c:\windows\system32\corpol.dll2009-08-26 08:00 . 2004-08-04 05:00 247326 ----a-w- c:\windows\system32\strmdll.dll2009-08-06 23:24 . 2005-04-04 17:42 327896 ----a-w- c:\windows\system32\wucltui.dll2009-08-06 23:24 . 2005-04-04 17:42 209632 ----a-w- c:\windows\system32\wuweb.dll2009-08-06 23:24 . 2005-07-13 22:19 44768 ----a-w- c:\windows\system32\wups2.dll2009-08-06 23:24 . 2005-04-04 17:57 35552 ----a-w- c:\windows\system32\wups.dll2009-08-06 23:24 . 2005-04-04 17:42 53472 ----a-w- c:\windows\system32\wuauclt.exe2009-08-06 23:24 . 2004-08-04 05:00 96480 ----a-w- c:\windows\system32\cdm.dll2009-08-06 23:23 . 2005-04-04 17:57 575704 ----a-w- c:\windows\system32\wuapi.dll2009-08-06 23:23 . 2006-08-01 11:32 274288 ----a-w- c:\windows\system32\mucltui.dll2009-08-06 23:23 . 2005-05-26 08:19 215920 ----a-w- c:\windows\system32\muweb.dll2009-08-06 23:23 . 2005-04-04 17:42 1929952 ----a-w- c:\windows\system32\wuaueng.dll2009-08-05 09:01 . 2004-08-04 05:00 204800 ----a-w- c:\windows\system32\mswebdvd.dll2009-08-05 00:44 . 2004-08-04 05:00 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe2009-08-04 14:20 . 2004-08-03 22:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe2009-08-03 19:07 . 2009-08-03 19:07 403816 ----a-w- c:\windows\system32\OGACheckControl.dll2009-08-03 19:07 . 2009-08-03 19:07 322928 ----a-w- c:\windows\system32\OGAAddin.dll2009-08-03 19:07 . 2009-08-03 19:07 230768 ----a-w- c:\windows\system32\OGAEXEC.exe.((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))..*Note* empty entries & legit default entries are not shown REGEDIT4[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"Aim6"="c:\program files\AIM6\aim6.exe" [2009-05-19 49968]"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-10-19 204288]"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2008-12-05 2356088][HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]"Zone Labs Client"="c:\program files\CheckPoint\Integrity Client\iclient.exe" [2005-10-26 931584]"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-11 39792]"D-Link AirXpert Utility"="c:\program files\D-Link\AirXpert Utility\AirXCFG.exe" [2003-07-10 2691072]"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-09-06 413696]"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]"V0250Mon.exe"="c:\windows\V0250Mon.exe" [2006-06-08 32768]"AVFX Engine"="c:\program files\Creative\Creative Live! Cam\VideoFX\StartFX.exe" [2006-06-09 24576]"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]"Mouse Suite 98 Daemon"="ICO.EXE" - c:\windows\system32\ico.exe [2002-03-14 45056]"AtiPTA"="atiptaxx.exe" - c:\windows\system32\atiptaxx.exe [2001-09-27 245760][HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]"NoDevMgrUpdate"= 1 (0x1)[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]"NoSetActiveDesktop"= 1 (0x1)"NoActiveDesktopChanges"= 1 (0x1)[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]BootExecute REG_MULTI_SZ autocheck autochk *\0bcasnative32[HKEY_LOCAL_MACHINE\software\microsoft\security center]"AntiVirusOverride"=dword:00000001"FirewallOverride"=dword:00000001"IBMconfig"=dword:00000001[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]"DisableMonitoring"=dword:00000001[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]"EnableFirewall"= 0 (0x0)[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]"%windir%\\system32\\sessmgr.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe"="c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="c:\\Program Files\\AIM6\\aim6.exe"="c:\\Program Files\\Bonjour\\mDNSResponder.exe"="c:\\Program Files\\iTunes\\iTunes.exe"="c:\\Program Files\\Avira\\AntiVir PersonalEdition Classic\\guardgui.exe"="c:\\Program Files\\Skype\\Phone\\Skype.exe"="c:\\Program Files\\iPod\\bin\\iPodService.exe"=[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]"16984:TCP"= 16984:TCP:BitComet 16984 TCP"16984:UDP"= 16984:UDP:BitComet 16984 UDPR1 pelmouse;Mouse Suite Driver;c:\windows\system32\drivers\PELMouse.SYS [7/31/2006 1:34 PM 16384]R2 NIOC;NIOC Service;c:\windows\system32\NIOC.sys [9/27/2002 6:21 PM 22912]R2 WZCBDLService;WZCBDL Service;c:\program files\WZCBDL Service\WZCBDLS.exe [3/19/2002 12:15 PM 36864]R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);c:\windows\system32\drivers\A3AB.sys [8/23/2008 12:29 AM 320320]S0 brhadby;brhadby;c:\windows\system32\drivers\kirqvkx.sys --> c:\windows\system32\drivers\kirqvkx.sys [?]S1 SABKUTIL;SABKUTIL;\??\c:\documents and settings\Administrator\My Documents\Downloads\SABKUTIL.sys --> c:\documents and settings\Administrator\My Documents\Downloads\SABKUTIL.sys [?]S1 SASKUTIL;SASKUTIL;\??\c:\program files\SUPERAntiSpyware\SASKUTIL.sys --> c:\program files\SUPERAntiSpyware\SASKUTIL.sys [?]S3 BCASPROT;SpyDefy;\??\c:\program files\ByteCrusher\SpyDefy\bcasprot32.sys --> c:\program files\ByteCrusher\SpyDefy\bcasprot32.sys [?]S3 pelps2m;PS/2 Mouse Filter Driver;c:\windows\system32\drivers\pelps2m.sys [7/31/2006 1:34 PM 18048]S3 V0250Dev;Live! Cam Notebook Pro;c:\windows\system32\drivers\V0250Dev.sys [2/1/2008 2:02 AM 185504]S3 V0250Vfx;V0250Vfx;c:\windows\system32\drivers\V0250Vfx.sys [2/1/2008 2:02 AM 6272]--- Other Services/Drivers In Memory ---*Deregistered* - mbr.Contents of the 'Scheduled Tasks' folder2009-10-21 c:\windows\Tasks\AppleSoftwareUpdate.job- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 16:34]2009-10-28 c:\windows\Tasks\Google Software Updater.job- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-09-04 22:30]..------- Supplementary Scan -------.uStart Page = hxxp://www.pbs.org/uInternet Connection Wizard,ShellNext = hxxp://www.pbs.org/uInternet Settings,ProxyOverride = ;<local>;*.localIE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cabFF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\x6rjcfib.default\FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dllFF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dllFF - HiddenExtension: XUL Cache: {114B283E-19AE-4CB3-97AD-11CC73610945} - c:\documents and settings\Administrator\Local Settings\Application Data\{114B283E-19AE-4CB3-97AD-11CC73610945}FF - HiddenExtension: XUL Cache: {6EA45995-D0DB-41F2-A913-06047118E723} - c:\windows\system32\config\systemprofile\Local Settings\Application Data\{6EA45995-D0DB-41F2-A913-06047118E723}\FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\---- FIREFOX POLICIES ----FF - user.js: yahoo.homepage.dontask - true.- - - - ORPHANS REMOVED - - - -HKCU-Run-SUPERAntiSpyware - c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exeHKCU-Run-BitComet - c:\program files\BitComet\BitComet.exeHKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exeHKLM-Run-Malwarebytes Anti-Malware (reboot) - e:\malwarebytes' anti-malware\explorer.exe.exeAddRemove-InFlac - c:\program files\Winamp\InFlac-Uninstall.exe**************************************************************************catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.netRootkit scan 2009-10-28 16:37Windows 5.1.2600 Service Pack 3 NTFSscanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfullyhidden files: 0**************************************************************************.--------------------- LOCKED REGISTRY KEYS ---------------------[HKEY_USERS\S-1-5-21-1764756388-1742547241-4250478557-500\Software\Microsoft\Internet Explorer\User Preferences]@Denied: (2) (Administrator)"659BD8E725A05FDCC64118EA787EAA2B534A94FABE"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fa,fe,1a,70,94,f6,d6,43,93,42,aa,\"3A77B377802A4B6183DDE08FDE4AD9AF647A702826"=hex:01,00,00,00,d0,8c,9d,df,01,15, d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,fa,fe,1a,70,94,f6,d6,43,93,42,aa,\[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]@DACL=(02 0000)"Installed"="1"@=""[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]@DACL=(02 0000)"Installed"="1""NoChange"="1"@=""[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]@DACL=(02 0000)"Installed"="1"@="".--------------------- DLLs Loaded Under Running Processes ---------------------- - - - - - - > 'explorer.exe'(3152)c:\windows\system32\WININET.dllc:\windows\system32\ieframe.dllc:\windows\system32\mshtml.dllc:\windows\system32\WPDShServiceObj.dllc:\windows\system32\PortableDeviceTypes.dllc:\windows\system32\PortableDeviceApi.dll.------------------------ Other Running Processes ------------------------.c:\program files\Avira\AntiVir PersonalEdition Classic\sched.exec:\program files\Avira\AntiVir PersonalEdition Classic\avguard.exec:\program files\Bonjour\mDNSResponder.exec:\program files\Java\jre6\bin\jqs.exec:\combofix\CF32472.exec:\program files\iPod\bin\iPodService.exec:\program files\AIM6\aolsoftware.exec:\windows\system32\msiexec.exec:\combofix\PEV.cfxxe.**************************************************************************.Completion time: 2009-10-28 16:46 - machine was rebootedComboFix-quarantined-files.txt 2009-10-28 20:46ComboFix2.txt 2009-01-13 02:57Pre-Run: 28,959,449,088 bytes freePost-Run: 29,334,745,088 bytes free- - End Of File - - 3F5F3B263C730345516E3EA2E7CE0936 Link to post Share on other sites More sharing options...
Staff miekiemoes Posted October 28, 2009 Staff ID:150571 Share Posted October 28, 2009 Hi,Go to start > run and copy and paste next command in the field: sc delete brhadby Hit enter.Then, * Go to start > run and copy and paste next command in the field:ComboFix /uMake sure there's a space between Combofix and /Then hit enter.This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.Let me know in your next reply how things are now. Link to post Share on other sites More sharing options...
Need Help 13 Posted October 28, 2009 Author ID:150592 Share Posted October 28, 2009 Did all that, everything seems good now. No pop ups and alerts, seems to be running a bit faster...just browsed a few websites, wasn't re-directed. Thank you. Link to post Share on other sites More sharing options...
Staff miekiemoes Posted October 28, 2009 Staff ID:150595 Share Posted October 28, 2009 Glad I could help. Please read my Prevention page with lots of info and tips how to prevent this in the future.And if you want to improve speed/system performance after malware removal, take a look here.Extra note: Make sure your programs are up to date - because older versions may contain Security Leaks. To find out what programs need to be updated, please run the Secunia Software Inspector Scan.Happy Surfing again! Link to post Share on other sites More sharing options...
Staff miekiemoes Posted October 31, 2009 Staff ID:151913 Share Posted October 31, 2009 Since this issue appears resolved ... this Topic is closed.If you need this topic reopened for continuations of existing problems, please request this by sending me a PM with the address of the thread. This applies only to the original topic starter.Everyone else please begin a New Topic. Link to post Share on other sites More sharing options...
Recommended Posts