The fact that ZA tray icon stopped responding last night was a red flag for me so I went to safe mode-networking and ran MBAM, then Combofix.
Rkill found userinit.exe
MBAM found "Dont.steal.our.software" in an old, never-used Sorenson Squeeze directory.
Combofix spat out the logs pasted below.
What really freaked me out is after I changed my major passwords, I try to get on my email today and the new password doesn't work. I had to reset it by phone. Now it is possible I mistyped my new password, but you never know.
Email IP logs show normal activity.
Also, security log shows:
Failure Audit, Event ID 615, IPSEC services failed to get a complete list of network interfaces...
System event viewer log shows a lot of "DHCP Event ID 1000... lost its lease to the IP address" etc etc.
Please check my Combofix log? I am feeling especially paranoid right now.
----------------------------
ComboFix 11-09-23.03 - NAME 09/23/2011 4:49:37.10.6 - x86 NETWORK
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.3326.2967 [GMT -7:00]
Running from: C:\Documents and Settings\NAME\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: ThreatFire *Enabled/Updated* {67B2B9A1-25C8-4057-962D-807958FFC9E3}
FW: ZoneAlarm Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Documents and Settings\NAME\Local Settings\Application Data\ApplicationHistory
C:\Documents and Settings\NAME\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
C:\WINDOWS\iun6002.exe
C:\WINDOWS\system32\404Fix.exe
C:\WINDOWS\system32\CF14001.exe
C:\WINDOWS\system32\CF20100.exe
C:\WINDOWS\system32\d3d9caps.dat
C:\WINDOWS\system32\dumphive.exe
C:\WINDOWS\system32\IEDFix.C.exe
C:\WINDOWS\system32\IEDFix.exe
C:\WINDOWS\system32\o4Patch.exe
C:\WINDOWS\system32\Process.exe
C:\WINDOWS\system32\SrchSTS.exe
C:\WINDOWS\system32\tmp.reg
C:\WINDOWS\system32\VACFix.exe
C:\WINDOWS\system32\VCCLSID.exe
C:\WINDOWS\system32\WS2Fix.exe
((((((((((((((((((((((((( Files Created from 2011-08-23 to 2011-09-23 )))))))))))))))))))))))))))))))
Mod Edit: No Malware Logs In This Forum
This post has been edited by hamluis: 23 September 2011 - 04:36 PM
Reason for edit: Moved from XP to MRL forum.

Help
This topic is locked

Back to top









